Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

171–180 of 486 posts

Re: Ubiquiti Networks Breach

#171
post #105

Earlier quoted context omitted.

Just ordered a Chinese box with 8th gen U-series i5, 8 GB of RAM and 120 GB of SSD. Has six ethernet connections, HDMI and COM. Planning to install OpenWRT to it, and with AES-NI the system should be easily able to push the full 1 Gbps of traffic through Wireguard. I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CP…

Raspberry pi 4 compute module might be good for building your own router too. You can attach a pcie network extension or usb to Ethernet for local usage. All of that would cost under $70. https://www.raspberrypi.org/products/compute-module-4/?varia... https://www.zahradnik.io/raspberry-pi-as-a-home-router Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/Thoma…

It misses AES-NI though, so missing encryption hardware and would be subpar if running a VPN client for the network...

Re: Ubiquiti Networks Breach

#173
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Fitlet2 looks rather nice to me. Outfitted with an Intel J3455 CPU, and 2-4 Intel NICs, it is really power efficient for its performance class (idles at ~6 watts, for those that care). There are also some Chinese companies producing slightly cheaper boxes in this category- Qotom, Kettop, Protectli.

When it comes to software, I'm conflicted. I like pfsense, but Netgate has gone a bit sour with the FLOSS community. I'd also consider OpenWRT, FreeBSD, OpenBSD.

Re: Ubiquiti Networks Breach

#174
post #147

Earlier quoted context omitted.

I run a Netgate SG-5100 (PF-Sense) as the main router, the Unifi controller and Access points are al behind the Firewall. The AP and switches are really good, not the DPI/IPS/IDS solution (those suck)

Great router! The only issue I have with Netgate is pricing!

Protectli is a pretty common alternative.

Re: Ubiquiti Networks Breach

#175

ooooh, turn off "Remote Management" if you use Unifi products and are concerned https://help.ui.com/hc/en-us/articles/115012240067-UniFi-How...

If you use UniFi Protect you can't disable it without losing access to your video feeds in the app.

Re: Ubiquiti Networks Breach

#176
post #137

Earlier quoted context omitted.

Ubiquiti let users disable the cloud logins with UDM Pro, after a pretty big backlash on their forums. You do need a Ubiquiti account to setup the hardware in the first place, but you can turn off cloud access and login locally after that. And you should.

How? I have been looking for this setting but haven't been able to find it.

On the landing page after you log in, click Users at the bottom. Then click Add User or Add Admin, and just set the Account Type to Local Access Only.

Re: Ubiquiti Networks Breach

#178
post #168

Earlier quoted context omitted.

Despite the name in the Amazon listing, it has nothing to do with Mikrotik; also a 1Gbit ARM Mikrotik router/firewall can be had for considerably less.

How fast are the ARM CPU they have in their routers, do they support AES-NI and how much data you can push with VPN encryption through their boxes? The current ARMv7 I have goes to about 100 degrees Celsius and loads in the level of 4 to 6 when downloading a bunch of data full speed.

I'm not sure if they support AES-NI on ARM. I found some changelogs indicating that they do support it on x86 and x64, and most ARM routers list "hardware IPsec" encryption, so maybe?

Re: Ubiquiti Networks Breach

#179
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

My primary use case for a home router is solid set and forget qos. fq_codel and cake were recently added to routeros v7 beta, which means I will be plugging in my hEX again after a few years of happy edgerouter x usage.

Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?

Re: Ubiquiti Networks Breach

#180

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

Have suggestions for an alternative? Most web UIs are garbage but the Ubiquiti one looks fine, even if it is cloud based.
Post reply on HN