Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

121–130 of 486 posts

Re: Ubiquiti Networks Breach

#121
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Raspberry pi 4 compute module might be good for building your own router too. You can attach a pcie network extension or usb to Ethernet for local usage. All of that would cost under $70. https://www.raspberrypi.org/products/compute-module-4/?varia... https://www.zahradnik.io/raspberry-pi-as-a-home-router Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/Thoma…

It's worth noting that the Unifi gateways have hardware offload for traffic routing.

While a Raspberry Pi might work for some folks, it's worth noting that these are two very different performance classes.

Re: Ubiquiti Networks Breach

#122
post #105
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

FWIW, I tried using OpenWRT on a box with similar specs to yours and it was a nightmare. Ended up using FreeBSD instead and it was a vastly better experience. I think OpenWRT might only be worth it on very low-spec hardware.

Re: Ubiquiti Networks Breach

#124

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

Ubiquiti hardware and software is still amazing, and I'm willing to bet there are far more satisfied users than the few people grumbling on this forum. Cloud login is not mandatory if you choose not to enable it.

No products are perfect, but for the use case of "more technical than average user" looking for better quality than your typical home-grade gear, I have not found anything better or more polished.

Re: Ubiquiti Networks Breach

#125
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Raspberry pi 4 compute module might be good for building your own router too. You can attach a pcie network extension or usb to Ethernet for local usage. All of that would cost under $70. https://www.raspberrypi.org/products/compute-module-4/?varia... https://www.zahradnik.io/raspberry-pi-as-a-home-router Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/Thoma…

How is it great with one NIC?

Ethernet adapter and USB speeds seem less than ideal.

Re: Ubiquiti Networks Breach

#126
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Did you happen to write up the results of your router tests? I'd be really interested in reading up on them! I recently picked up an old Apple Airport Extreme so I could easily set up Time Machine backups on my network, but obviously Airports have their own host of issues so I'd be really interested in upgrading soon.

I don't, but it was a narrow case. Part of my home-made home automation runs on wifi so I was focusing on low latency and no packets lost when using wifi in my specific building. Top of the shelf routers all had some occasional hiccups. I think the good old WRT54GL did much better than them. Plus it was done with the set of wifi receivers available to me at the time (mostly cheapos connected to rpis & esp8266).

This is not a common use case, I was not interested in high bandwidth. I did try to disable beamforming and all other fireworks when testing though (but did tests with default settings too)

Re: Ubiquiti Networks Breach

#127
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Link to the box you got? That sounds interesting.

$350-$400ish search AliExpress for "i5 7200U firewall"

Re: Ubiquiti Networks Breach

#128
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Link to the box you got? That sounds interesting.

Oh, sorry!

These are available from Europe, but I've heard good things from US about similar boxes, when I searched with "best pfsense computer". Not the same brand, but similar hardware.

https://www.amazon.de/gp/product/B08JHKZMTN/ref=ppx_yo_dt_b_...

Let's see how it works, but I expect it to be much faster than my current ARMv7 box. Of course if you have space for a rack, go with something actively cooled. In our apartment, we expect the router to not make any noise.

Re: Ubiquiti Networks Breach

#130

Earlier quoted context omitted.

I use a fair amount of their equipment at home and I don't think that you need to be concerned with this. I run my controller on a server in my basement, and no part of it (besides the WAN port on my ERL) touch the internet. There is no "cloud" requirement. The "dream machine" thing I don't get. I do like their Unifi AP line, though.

Are you aware that they added telemetry a while back?

Yes, I have disabled it. You can also drop outbound traffic for the uid running the controller with iptables if you're paranoid about it.
Post reply on HN