Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

181–190 of 486 posts

Re: Ubiquiti Networks Breach

#181
"We recently became aware of unauthorized access to certain of our information technology systems hosted by a third party cloud provider."

Is this an attempt to shift blame? Using wording that implies it was someone else's fault is not confidence inspiring.

Re: Ubiquiti Networks Breach

#182

Earlier quoted context omitted.

They put all of their users eggs in one basket in the cloud. That makes for a very interesting target. They could have not done that. The users were probably unaware that their data was even placed on the cloud servers of some third party. Ubiquiti used to be cool. They've taken a nose dive in recent years in several ways: Firmware upgrade suddenly including telemetry by default, forcing people to use their NVR appli…

I heard rumors about the telemetry thing, but that is usually an overhyped concern - unless it is sending flow logs or something. When did they stop allowing people to use a private server for central management? I see Unifi still has a network controller.

[deleted]

Re: Ubiquiti Networks Breach

#183
post #101

Earlier quoted context omitted.

I'm a Mikrotik user, not a Ubiquiti user, but looks like the closest match would be Mikrotik's CRS (Cloud Router Switch) line. My home network is a CRS317-1G-16S+RM at the core and three CRS305-1G-4S+IN (one in each room), all running SwitchOS/SwOS instead of the stock RouterOS (they dual-boot, your choice), and I am very happy with them.

What APs do you use with a MicroTik setup?

I like Aruba Instant APs, the kind that don't require cloud management or a separate controller, though it seems they've folded the IAP line into the regular AP line or something with their new Wi-Fi 6 gear.

I'm still using Wi-Fi 5 because it's fast enough and cheaper. My central AP is a IAP-315, an IAP-305 in the garage, and another IAP-305 at the wall by the back yard. They're all PoE and linked with wired backbone to form a single big coverage area using a single elected IAP leader as controller for the rest.

You shouldn't have trouble buying grey-market ones as long as you are careful to stick to the same regulatory domain for all of them. Aruba gear is available as USA/FCC, Japan, Israel, and RW (Rest of World) versions. I have operated RW units in FCC territory (proooobably legally but probably not worth the risk) by setting them to "US Virgin Islands" so they match FCC-allowed frequencies and power limits, but linking more than one AP still requires the hardware to be same regulatory domain.

Re: Ubiquiti Networks Breach

#184
post #107

Earlier quoted context omitted.

I was confused by the parent comment too. Aside from the remote management features, if you turn off cloud login you still get everything else. Maybe it's something specific to the USG Pro? I've only used the smaller USG.

Not USG but UDM-PRO. It was the first device from them that required me to make an ubiquiti account to set it up.

Well this is a disappointing development. I'm currently using EdgeRouter hardware, but was considering moving to their Unifi line for my next upgrade. Guess that's off the table till I can use these without cloud access.

Re: Ubiquiti Networks Breach

#185
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

I hear these are great little boxes for running PFSence and OPNSense

https://protectli.com/

Re: Ubiquiti Networks Breach

#186

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

Have suggestions for an alternative? Most web UIs are garbage but the Ubiquiti one looks fine, even if it is cloud based.

Second this. I'm no great expert in this area but have greatly enjoyed using Ubiquiti gear for my home the past few years. If there is something else that offers a comparable experience at similar price point would be great to know. The Unifi Controller software has been some of the nicest I've used in a domestic setting.

Re: Ubiquiti Networks Breach

#187

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

Any idea what it would cost to develop a completely open source router?

Re: Ubiquiti Networks Breach

#188

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

My primary use case for a home router is solid set and forget qos. fq_codel and cake were recently added to routeros v7 beta, which means I will be plugging in my hEX again after a few years of happy edgerouter x usage. Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?

For awhile I was actually using a UniFi NanoHD for my AP. Performance and stability were great but running a Docker container for a Ubiquti Controller (for a single AP) was annoying enough for me to bail on it. My old Asus router with OpenWRT has been fine for now and doesn’t require me to run a container. :)

I’m still looking for a proper WiFi 6 replacement that can hook up to my 10G core, ideally via 2.5/5/10G copper or preferably SFP+ DAC. Nothing’s jumped out at me yet though.

Re: Ubiquiti Networks Breach

#189
post #185

Earlier quoted context omitted.

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

I hear these are great little boxes for running PFSence and OPNSense https://protectli.com/

I've never used those ones but I can recommend these ones (originally from the US, moved to Switzerland): https://pcengines.ch

Re: Ubiquiti Networks Breach

#190
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

> Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard.

They’re still sending out the email. Mail chip will be rate-limiting the send rate to prevent email providers from block listing them.

Give it a couple of hours and no doubt you’ll have an email as well.

Post reply on HN