Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

201–210 of 486 posts

Re: Ubiquiti Networks Breach

#201
post #171

Earlier quoted context omitted.

Raspberry pi 4 compute module might be good for building your own router too. You can attach a pcie network extension or usb to Ethernet for local usage. All of that would cost under $70. https://www.raspberrypi.org/products/compute-module-4/?varia... https://www.zahradnik.io/raspberry-pi-as-a-home-router Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/Thoma…

It misses AES-NI though, so missing encryption hardware and would be subpar if running a VPN client for the network...

[deleted]

Re: Ubiquiti Networks Breach

#202

Earlier quoted context omitted.

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

The reason most people go with Ubiquiti for home use is the price -- that Aruba switch costs $3500 new. The ubiquiti switch costs about 1/10th that at $399. Can you get free firmware updates from Aruba or do you need a support contract?

You can get S2500-24P from eBay for 125 US or so each.

Re: Ubiquiti Networks Breach

#203
post #173
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Fitlet2 looks rather nice to me. Outfitted with an Intel J3455 CPU, and 2-4 Intel NICs, it is really power efficient for its performance class (idles at ~6 watts, for those that care). There are also some Chinese companies producing slightly cheaper boxes in this category- Qotom, Kettop, Protectli. When it comes to software, I'm conflicted. I like pfsense, but Netgate has gone a bit sour with the FLOSS community. I'd…

> I like pfsense, but Netgate has gone a bit sour with the FLOSS community

I haven't kept up with pfsense. Any chance for a tl;dr?

Re: Ubiquiti Networks Breach

#204
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Speaking of security... I fell for their marketing and slick Apple-like design and decided to add a UDM-Pro router and access point to my pre-existing network. I thought I was doing something wrong when the UDM-Pro ignored everything on my network that wasn't connected directly to a Unifi device. I asked about it on the Ubiquiti subreddit and basically got blackballed for "whining". Opened a support ticket with Ubiquiti and they confirmed that you can't work with any clients on non-Unifi hardware.

So basically all you need to do is plug a laptop into a non-Unifi switch on someone's Unifi network and are able to breach the firewall.

Needless to say I was flabbergasted at the vendor lock-in strategy worse than Apple, and asked for a refund. Thankfully they complied.

I now have a hand-rolled OPNsense router that does everything I need, and with MUCH more configurability.

Re: Ubiquiti Networks Breach

#205
post #125

Earlier quoted context omitted.

Raspberry pi 4 compute module might be good for building your own router too. You can attach a pcie network extension or usb to Ethernet for local usage. All of that would cost under $70. https://www.raspberrypi.org/products/compute-module-4/?varia... https://www.zahradnik.io/raspberry-pi-as-a-home-router Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/Thoma…

How is it great with one NIC? Ethernet adapter and USB speeds seem less than ideal.

The CM4 can hit up to ~3.4 Gbps for one interface over PCI-E, and 4.15 Gbps if you also use the onboard Gigabit interface. Use a 1, 2, or 4-port network card and you can do some interesting things at 1+ Gbps: https://pipci.jeffgeerling.com/#network-cards-nics

Re: Ubiquiti Networks Breach

#206
post #185

Earlier quoted context omitted.

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

I hear these are great little boxes for running PFSence and OPNSense https://protectli.com/

There's also Netgate hardware, which has the added benefit of supporting development of pfSense. I have the SG-3100 and have been very happy with it.

https://www.netgate.com/

Re: Ubiquiti Networks Breach

#207

Earlier quoted context omitted.

... we run it on a raspberrypi. Not sure I'd call that gigantic or bloated.

Its not a great solution. The application logs and writes to storage alot. Also it usually works fine, but when it breaks, it breaks HARD

Agree. Our DHCP pool is around 200, so we're not talking a huge amount of data. If I were running any bigger of a LAN I'd definitely ratchet the skookum factor up.

Re: Ubiquiti Networks Breach

#208

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

Something from Mikrotik, perhaps a hAP AC2? I'm a big fan of RouterOS for a home/prosumer use-case (I used a hEX myself)

Re: Ubiquiti Networks Breach

#209

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

My primary use case for a home router is solid set and forget qos. fq_codel and cake were recently added to routeros v7 beta, which means I will be plugging in my hEX again after a few years of happy edgerouter x usage. Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?

The standalone Ubiquiti access points are still great IMHO. It's just their recent prosumer gateway/router product line that's really struggling. I've had a great experience with the older UAP-HD-PRO. Their newish $100 Wifi 6 U6-Lite AP is tempting but haven't tried it.

If you just need one AP you can set it up in standalone mode and forget about it. If you want more monitoring and control you'll need to have a Ubiquiti controller running to manage things. (can run one in docker, on a rasp pi, or just buy their "Cloud Key" product.)

Re: Ubiquiti Networks Breach

#210
post #137

Earlier quoted context omitted.

How? I have been looking for this setting but haven't been able to find it.

On the landing page after you log in, click Users at the bottom. Then click Add User or Add Admin, and just set the Account Type to Local Access Only.

Oh but this doesn't actually disable remote access on the UDM side, does it? It's just a flag that the cloud host can choose to respect?
Post reply on HN