Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

131–140 of 486 posts

Re: Ubiquiti Networks Breach

#131
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Link to the box you got? That sounds interesting.

similar boxes are on amazon, with worse(ish) specs under the brand "Protectli "

Re: Ubiquiti Networks Breach

#132
Did they email everyone with an account this information? I.e., if I didn't get that email, I don't have an account?

You can't check via a login page whether you have an account...

Re: Ubiquiti Networks Breach

#133
post #56

Earlier quoted context omitted.

I don't think my post argues, or even attempts to argue, against your point. It was a light-hearted jest at the fact that this exact line is in every single breach notification I have read for the past few years. The more serious point I was alluding at was not "just don't get breached", it was that the "we care" line rings hollow after the 250th time reading it.

My misread, apologies. I think the "we care" is a dodge around the reality that most are uncomfortable with, which is, "we make your data safe as possible but we will likely be hacked and you should compartmentalize your personal data accordingly with that expectation". But I am no good with marketing.

Most companies choose to collect data they don't have to.

Re: Ubiquiti Networks Breach

#134
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Another endorsement for mikrotik here...spent a lot of time in the WISP space and doing CPE installations. Mikrotik all the way down - text config files (version control), ssh-like remote terminals on all endpoints, full feature-set on even the most basic hardware. I've taken them into other jobs and other engineers have been happy with them.

The cons are that everything has one or more "mikrotik" way of doing things, and it may not be intuitive to the new user. Also, although everything is included, you have to set it all up yourself.

Re: Ubiquiti Networks Breach

#135
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Does it support Wireguard?

Also RouterOS does not seem open source.

Re: Ubiquiti Networks Breach

#136

Earlier quoted context omitted.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

You can also just run a docker container for it [0]. This has the added benefit of separating your data from the runtime so you can move it around as if you had a physical cloud key. [0] https://hub.docker.com/r/linuxserver/unifi-controller

I shouldn't have to run a docker appliance for my network appliances to function. Are you kidding me?

Re: Ubiquiti Networks Breach

#137
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Ubiquiti let users disable the cloud logins with UDM Pro, after a pretty big backlash on their forums. You do need a Ubiquiti account to setup the hardware in the first place, but you can turn off cloud access and login locally after that. And you should.

How? I have been looking for this setting but haven't been able to find it.

Re: Ubiquiti Networks Breach

#138
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

FWIW, I tried using OpenWRT on a box with similar specs to yours and it was a nightmare. Ended up using FreeBSD instead and it was a vastly better experience. I think OpenWRT might only be worth it on very low-spec hardware.

Hey! Could you please share what you think didn't work so well with OpenWRT? I'm currently running a Turris Omnia with their custom OpenWRT that I know how to use and it's been working quite well. What's missing is a better CPU to run Wireguard encryption full speed through our fast internet connection.

I'm seriously thinking about pfSense or Opnsense, but FreeBSD still misses native Wireguard support, leaving the encryption to the go implementation, which is subpar for our use cases. But, I'd be happy to run Opnsense, with jails and all those goodies from FreeBSD.

Re: Ubiquiti Networks Breach

#140
post #74
post #50

Earlier quoted context omitted.

No one could possibly prove this kind of negative.

Why not? All you have to do is point to one particular company whose systems have not been verifiably breached after having resisted actual attempts.

> one particular company whose systems have not been verifiably breached

The unknown unknown. How can you be sure all the "resisted actual attempts" been even detected?

Post reply on HN