Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

241–250 of 486 posts

Re: Ubiquiti Networks Breach

#241
post #138

Earlier quoted context omitted.

FWIW, I tried using OpenWRT on a box with similar specs to yours and it was a nightmare. Ended up using FreeBSD instead and it was a vastly better experience. I think OpenWRT might only be worth it on very low-spec hardware.

Hey! Could you please share what you think didn't work so well with OpenWRT? I'm currently running a Turris Omnia with their custom OpenWRT that I know how to use and it's been working quite well. What's missing is a better CPU to run Wireguard encryption full speed through our fast internet connection. I'm seriously thinking about pfSense or Opnsense, but FreeBSD still misses native Wireguard support, leaving the en…

Since Netgate (the company behind pfSense) paid for the Wireguard work, you can make a good bet that same will appear in a near-future release of pfSense.

Re: Ubiquiti Networks Breach

#242
post #185

Earlier quoted context omitted.

I hear these are great little boxes for running PFSence and OPNSense https://protectli.com/

There's also Netgate hardware, which has the added benefit of supporting development of pfSense. I have the SG-3100 and have been very happy with it. https://www.netgate.com/

Do any of these pfsense setups allow an Orbi-style network? I’ve been really unhappy with my last several router purchases.

Re: Ubiquiti Networks Breach

#243
post #175

ooooh, turn off "Remote Management" if you use Unifi products and are concerned https://help.ui.com/hc/en-us/articles/115012240067-UniFi-How...

If you use UniFi Protect you can't disable it without losing access to your video feeds in the app.

Yes, I upgraded from Unifi Video to Unifi Protect (by purchasing a Cloud Key Gen 2 Pro), and was pretty dismayed that you have to allow outside access (via the Unifi cloud) to use the cameras in the app. For the hypothetical reason that this might be cracked once. This was two weeks ago... didn't expect it would happen so soon.

Re: Ubiquiti Networks Breach

#244
post #185

Earlier quoted context omitted.

I hear these are great little boxes for running PFSence and OPNSense https://protectli.com/

There's also Netgate hardware, which has the added benefit of supporting development of pfSense. I have the SG-3100 and have been very happy with it. https://www.netgate.com/

Takes a bit of searching to find the hardware section (it's under products->appliances) https://www.netgate.com/products/appliances/

Re: Ubiquiti Networks Breach

#245
post #106
post #97

Earlier quoted context omitted.

What evidence do you have that anyone has?

When was the last time you heard of a google user data breach?

https://en.wikipedia.org/wiki/2018_Google_data_breach

https://www.express.co.uk/news/uk/1372333/Gmail-hacked-Googl...

Not unheard of at Google, either.

Re: Ubiquiti Networks Breach

#246
post #74
post #50

Earlier quoted context omitted.

No one could possibly prove this kind of negative.

Why not? All you have to do is point to one particular company whose systems have not been verifiably breached after having resisted actual attempts.

You've changed the requirement. To prove a company hasn't been breached, you'd also have to prove that there hasn't been a breach that hasn't been detected (so breached, but not verified). Any given target might already be quietly owned by some state actor or corrupt insider with allies on the outside.

Re: Ubiquiti Networks Breach

#248
post #128

Earlier quoted context omitted.

Oh, sorry! These are available from Europe, but I've heard good things from US about similar boxes, when I searched with "best pfsense computer". Not the same brand, but similar hardware. https://www.amazon.de/gp/product/B08JHKZMTN/ref=ppx_yo_dt_b_... Let's see how it works, but I expect it to be much faster than my current ARMv7 box. Of course if you have space for a rack, go with something actively cooled. In our a…

Despite the name in the Amazon listing, it has nothing to do with Mikrotik; also a 1Gbit ARM Mikrotik router/firewall can be had for considerably less.

I can't read German, but maybe it's a bare Mikrotik router board in a custom enclosure?

That said, it also says 'Pfsense', so I suppose more likely it's a typical 'Chinesium' listing.

Re: Ubiquiti Networks Breach

#249
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Speaking of security... I fell for their marketing and slick Apple-like design and decided to add a UDM-Pro router and access point to my pre-existing network. I thought I was doing something wrong when the UDM-Pro ignored everything on my network that wasn't connected directly to a Unifi device. I asked about it on the Ubiquiti subreddit and basically got blackballed for "whining". Opened a support ticket with Ubiqu…

I'm not clear what you were trying to achieve?

You had unmanaged switches on your network, and were trying to manage thier downstream connections?

What exactly do you mean by 'breach the firewall'?

Re: Ubiquiti Networks Breach

#250

Earlier quoted context omitted.

My primary use case for a home router is solid set and forget qos. fq_codel and cake were recently added to routeros v7 beta, which means I will be plugging in my hEX again after a few years of happy edgerouter x usage. Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?

For awhile I was actually using a UniFi NanoHD for my AP. Performance and stability were great but running a Docker container for a Ubiquti Controller (for a single AP) was annoying enough for me to bail on it. My old Asus router with OpenWRT has been fine for now and doesn’t require me to run a container. :) I’m still looking for a proper WiFi 6 replacement that can hook up to my 10G core, ideally via 2.5/5/10G copp…

If you just want dumb WiFi, you can provision and remove the controller. Nowadays you can even do this with the UniFi phone app (standalone mode let's you configure and update firmware).

I've had a UAP AC LR at home for a few years and we've got about 6 UAP AC HD at work. We used the phone app to provision and after that you can pretty much forget about it. Great for small startups that want great coverage and dont have someone who's supposed to mess around with it.

Post reply on HN