Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

111–120 of 486 posts

Re: Ubiquiti Networks Breach

#111

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

I have a TP-Link Mesh network in my house. I have high speed WiFi even in my garden. 50+ devices connected. Took me 30min to install everything. Didn’t have a single issue in 3 years yet. Saved lots of money in comparison to Ubiquiti. But what do I know, I only use internet for normal activities like smart home stuff, streaming, working and so on...

Re: Ubiquiti Networks Breach

#112
post #105
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Link to the box you got? That sounds interesting.

Re: Ubiquiti Networks Breach

#114
post #74
post #50

Earlier quoted context omitted.

No one could possibly prove this kind of negative.

Why not? All you have to do is point to one particular company whose systems have not been verifiably breached after having resisted actual attempts.

most attacker groups would be unlikely to share that result

Re: Ubiquiti Networks Breach

#115

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

I use a fair amount of their equipment at home and I don't think that you need to be concerned with this. I run my controller on a server in my basement, and no part of it (besides the WAN port on my ERL) touch the internet. There is no "cloud" requirement. The "dream machine" thing I don't get. I do like their Unifi AP line, though.

Are you aware that they added telemetry a while back?

Re: Ubiquiti Networks Breach

#116
post #105
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Raspberry pi 4 compute module might be good for building your own router too. You can attach a pcie network extension or usb to Ethernet for local usage. All of that would cost under $70.

https://www.raspberrypi.org/products/compute-module-4/?varia...

https://www.zahradnik.io/raspberry-pi-as-a-home-router

Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/ThomasKaiser/sbc-bench/blob/master/Result...

Re: Ubiquiti Networks Breach

#117

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

I use a fair amount of their equipment at home and I don't think that you need to be concerned with this. I run my controller on a server in my basement, and no part of it (besides the WAN port on my ERL) touch the internet. There is no "cloud" requirement. The "dream machine" thing I don't get. I do like their Unifi AP line, though.

I agree, I don't understand the level of hate appearing in this thread. I use Ubiquiti gear at multiple sites and it is absolutely bullet proof and trivial to set up once you understand their model. As long as you aren't running remote access then losing control of your UI.com credentials is really a non-issue.

Re: Ubiquiti Networks Breach

#118

Earlier quoted context omitted.

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

They put all of their users eggs in one basket in the cloud. That makes for a very interesting target. They could have not done that. The users were probably unaware that their data was even placed on the cloud servers of some third party. Ubiquiti used to be cool. They've taken a nose dive in recent years in several ways: Firmware upgrade suddenly including telemetry by default, forcing people to use their NVR appli…

I heard rumors about the telemetry thing, but that is usually an overhyped concern - unless it is sending flow logs or something.

When did they stop allowing people to use a private server for central management? I see Unifi still has a network controller.

Re: Ubiquiti Networks Breach

#119
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Link to the box you got? That sounds interesting.

Also curious, and wondering how much that cost.

Re: Ubiquiti Networks Breach

#120

Earlier quoted context omitted.

I use a fair amount of their equipment at home and I don't think that you need to be concerned with this. I run my controller on a server in my basement, and no part of it (besides the WAN port on my ERL) touch the internet. There is no "cloud" requirement. The "dream machine" thing I don't get. I do like their Unifi AP line, though.

Are you aware that they added telemetry a while back?

You are presented with the ability to opt out of data collection in your management console.
Post reply on HN