Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

141–150 of 486 posts

Re: Ubiquiti Networks Breach

#141
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on:

Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet).

Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras.

Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment my Google WiFi. I'm happy with the Google WiFi, and in particular it has good tools for managing kids access to WiFi. But the Ruckus APs are quite good and so I may move parent and IoT access over to Ruckus, separate out IoT devices to their own network.

This is the end of phase 1. Then I plan to go on to:

Add an OPN-Sense router. Currently not using Ubiquiti for routing, the Google WiFi is our main router. Would like to gain additional capabilities like insight into what the kids are doing.

Replace the Ubiquiti Dome G3 with one of the less expensive 4K cameras if they seem to provide similar or better functionality. Also trying out the Wyse Cam v3, which seems ok and the price sure is right, but is more of an augment camera than a main camera, I prefer wired and PoE.

I've been doing some research and those are the options that seem attractive. In particular, going with old enterprise gear looks to be a huge win. You do lose that handy "single pane of glass" management. But considering the problems I'm having with Ubiquiti, and the upgrades I've already done to try to get past them, with only some success, I can't bring myself to go further in on Ubiquiti.

Re: Ubiquiti Networks Breach

#142
post #135

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Does it support Wireguard? Also RouterOS does not seem open source.

RouterOS is not, but Mikrotik added wireguard support to their firmware sometime in mid-late 2020. IDK if its out of beta yet.

Re: Ubiquiti Networks Breach

#143
post #105
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

I still put the important part of my network behind my own router similar to yours (and in terms of security I think ubuntu server + whatever you need has likely much smaller attack surface than OpenWRT which is a piece of software just too tasty not to be exploited).

Outside that, wifi part is hard to get right and smart switches are nice to have, but they are PITA if the firmware is never updated and there's no single place to nicely manage it all.

Re: Ubiquiti Networks Breach

#144
post #91

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Do you know how ubiquiti's "edge" line compares to mikrotik?

Having owned several products from both, Mikrotik equivalents are generally way more feature packed but I find them hard to use. EdgeMax stuff is more polished, but has fewer features. Performance is comparable for the most part.

Re: Ubiquiti Networks Breach

#145
post #105
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

i've got this on my todo list of projects. looks super interesting. there seem to be a lot of flavors of these boxes and i'm having a difficult time figuring which one will work best. i don't know anything about the manufacturers.

Re: Ubiquiti Networks Breach

#146
post #135

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Does it support Wireguard? Also RouterOS does not seem open source.

V7 supports Wireguard and UDP OVPN, it's in beta but reasonably stable, at least for home use.

Re: Ubiquiti Networks Breach

#147
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I run a Netgate SG-5100 (PF-Sense) as the main router, the Unifi controller and Access points are al behind the Firewall. The AP and switches are really good, not the DPI/IPS/IDS solution (those suck)

Great router!

The only issue I have with Netgate is pricing!

Re: Ubiquiti Networks Breach

#148
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

The reason most people go with Ubiquiti for home use is the price -- that Aruba switch costs $3500 new. The ubiquiti switch costs about 1/10th that at $399.

Can you get free firmware updates from Aruba or do you need a support contract?

Re: Ubiquiti Networks Breach

#149

Earlier quoted context omitted.

I turned off cloud login a while back. There’s a toggle in the settings for this.

I was confused by the parent comment too. Aside from the remote management features, if you turn off cloud login you still get everything else. Maybe it's something specific to the USG Pro? I've only used the smaller USG.

I recently invested in UniFi hardware with the UDM Pro and this isn't exactly correct. UniFi Protect (the video security line) requires remote access and Ubiquiti Cloud accounts or it will break in a million weird ways. If you disable cloud login you cannot reasonably use UniFi Protect.
Post reply on HN