Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

101–110 of 486 posts

Re: Ubiquiti Networks Breach

#101
post #91

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Do you know how ubiquiti's "edge" line compares to mikrotik?

I'm a Mikrotik user, not a Ubiquiti user, but looks like the closest match would be Mikrotik's CRS (Cloud Router Switch) line. My home network is a CRS317-1G-16S+RM at the core and three CRS305-1G-4S+IN (one in each room), all running SwitchOS/SwOS instead of the stock RouterOS (they dual-boot, your choice), and I am very happy with them.

Re: Ubiquiti Networks Breach

#102
post #74
post #50

Earlier quoted context omitted.

No one could possibly prove this kind of negative.

Why not? All you have to do is point to one particular company whose systems have not been verifiably breached after having resisted actual attempts.

Challenge accepted?

Just because known attempts have failed doesn’t mean the unknown ones have too.

Re: Ubiquiti Networks Breach

#103
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Ubiquiti let users disable the cloud logins with UDM Pro, after a pretty big backlash on their forums.

You do need a Ubiquiti account to setup the hardware in the first place, but you can turn off cloud access and login locally after that. And you should.

Re: Ubiquiti Networks Breach

#105
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard.

I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CPU is a must.

Re: Ubiquiti Networks Breach

#106
post #97
post #45

Earlier quoted context omitted.

I think it is possible to secure yourself against a devoted, persistent threat group. I think it's expensive, but possible. Do you have data to back up your claim that no one, ever has ever successfully remained secure?

What evidence do you have that anyone has?

When was the last time you heard of a google user data breach?

Re: Ubiquiti Networks Breach

#107

Earlier quoted context omitted.

I turned off cloud login a while back. There’s a toggle in the settings for this.

I was confused by the parent comment too. Aside from the remote management features, if you turn off cloud login you still get everything else. Maybe it's something specific to the USG Pro? I've only used the smaller USG.

Not USG but UDM-PRO. It was the first device from them that required me to make an ubiquiti account to set it up.

Re: Ubiquiti Networks Breach

#108
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

It rolls off the tongue better than "We now wish to begin taking your security seriously"

Re: Ubiquiti Networks Breach

#109
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

They opted to TELL people about it which is a good indicator. I’m sure there’s many companies who choose not to (which may be against the law). It’s also HR spin on the topic, but iirc ubiquity offer bug bounties on a range of devices they sell so there’s at least some truth to the spin. ‘We know they breached but don’t know what they did’ is an interesting statement. One POV is that they didn’t have sufficient loggi…

> They opted to TELL people about it which is a good indicator.

Aren't they based in California which, if I remember correctly, as a law requiring them to notify the victims of a data breach?

Would they still have chosen to in the absence of such a law? We'll never know, I guess.

Re: Ubiquiti Networks Breach

#110
My goodness. How stupid does everyone involve need to be to put out a statement like this with a "mailchi.mp" URL, WITH PASSWORD RESET BUTTONS?

What the hell is wrong with these people?

Post reply on HN