Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

221–230 of 486 posts

Re: Ubiquiti Networks Breach

#221
post #173
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Fitlet2 looks rather nice to me. Outfitted with an Intel J3455 CPU, and 2-4 Intel NICs, it is really power efficient for its performance class (idles at ~6 watts, for those that care). There are also some Chinese companies producing slightly cheaper boxes in this category- Qotom, Kettop, Protectli. When it comes to software, I'm conflicted. I like pfsense, but Netgate has gone a bit sour with the FLOSS community. I'd…

Protectli seems to be a US company rebadging these Chinese devices. But apparently also putting coreboot on them now, which is nice. I wonder if their coreboot board configs are open source.

Re: Ubiquiti Networks Breach

#222

Earlier quoted context omitted.

The reason most people go with Ubiquiti for home use is the price -- that Aruba switch costs $3500 new. The ubiquiti switch costs about 1/10th that at $399. Can you get free firmware updates from Aruba or do you need a support contract?

I guess I could have pointed it out more clearly: I'm going "used enterprise" as the route for replacement. As you say, yes, this switch was $2500 new (that's what I saw when I looked), but I bought one for under $100 on ebay. Similarly for the Ruckus R610 AP I mentioned: Those APs were a grand new, but you can get them for a bit over $100 on ebay. Linus Tech Tips did a comparison of it with other consumer units, doi…

That is a good price for the hardware, but what about the firmware? Do Aruba and Ruckus give free firmware updates?

Have you looked at the power consumption of the switch? I've run some enterprise gear at home in the past (my favorite was the E-450 Sun server which an ex-employer gave me for free), but when I started paying for my own power, I found that even if the hardware is free, the power consumption makes it expensive.

Re: Ubiquiti Networks Breach

#223
post #185

Earlier quoted context omitted.

I hear these are great little boxes for running PFSence and OPNSense https://protectli.com/

I've never used those ones but I can recommend these ones (originally from the US, moved to Switzerland): https://pcengines.ch

Second these guys; really easy to set up (though I did have a nightmare getting a reliable USB-R232 converter for the initial bootstrap).

Re: Ubiquiti Networks Breach

#224
post #138

Earlier quoted context omitted.

Hey! Could you please share what you think didn't work so well with OpenWRT? I'm currently running a Turris Omnia with their custom OpenWRT that I know how to use and it's been working quite well. What's missing is a better CPU to run Wireguard encryption full speed through our fast internet connection. I'm seriously thinking about pfSense or Opnsense, but FreeBSD still misses native Wireguard support, leaving the en…

Wireguard has been merged into upstream FreeBSD almost a couple months ago.

FreeBSD 13 is out in March 2021 and opnSense with that system much later. Might be a bit complex to go that route right now, but it might be a great choice one year from now...

Re: Ubiquiti Networks Breach

#225
post #185

Earlier quoted context omitted.

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

I hear these are great little boxes for running PFSence and OPNSense https://protectli.com/

Thanks for the pointer. I was planning on running under a VM. A dedicated box would be nice from just a reboot standpoint. I was looking at getting one or two of those HP COMPAQ ELITE 8300 boxes off ebay for $200, but they probably only have one Network interface, so I might want to add another.

Re: Ubiquiti Networks Breach

#226

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

If you only need to VLAN-tag the 4 ports on that one device, you can do it with like… about literally anything? e.g. an Archer C1750 with OpenWRT does that easily.

The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.

Re: Ubiquiti Networks Breach

#227

Earlier quoted context omitted.

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

Blue Iris is a great piece of software and Ken the developer has constantly improved it. I think there's a way to get the RTSP stream from your existing cameras.

One of the slick things you can do is add machine learning to it and have motion alerts based on what is detected in the video (person, car, bear, those are some of the built-in options). That looks pretty slick.

Re: Ubiquiti Networks Breach

#228
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Speaking of security... I fell for their marketing and slick Apple-like design and decided to add a UDM-Pro router and access point to my pre-existing network. I thought I was doing something wrong when the UDM-Pro ignored everything on my network that wasn't connected directly to a Unifi device. I asked about it on the Ubiquiti subreddit and basically got blackballed for "whining". Opened a support ticket with Ubiqu…

Hi,

Could you elaborate a bit more about your previous network setup? This sounds awful.

Re: Ubiquiti Networks Breach

#229
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Speaking of security... I fell for their marketing and slick Apple-like design and decided to add a UDM-Pro router and access point to my pre-existing network. I thought I was doing something wrong when the UDM-Pro ignored everything on my network that wasn't connected directly to a Unifi device. I asked about it on the Ubiquiti subreddit and basically got blackballed for "whining". Opened a support ticket with Ubiqu…

I am not sure I am following, can you elaborate? The way you wrote it sounds impossible.

Re: Ubiquiti Networks Breach

#230
post #38

Earlier quoted context omitted.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

They have a little device (IIRC they call it "cloud key" or something like that) that runs that interface pretty well. Much better than setting that UI up on a device yourself.

The CloudKey is actually pretty decent -- the CK2 Plus Gen2 if you're running UniFi Protect.
Post reply on HN