Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

251–260 of 486 posts

Re: Ubiquiti Networks Breach

#251
post #231
post #101

Earlier quoted context omitted.

I'm a Mikrotik user, not a Ubiquiti user, but looks like the closest match would be Mikrotik's CRS (Cloud Router Switch) line. My home network is a CRS317-1G-16S+RM at the core and three CRS305-1G-4S+IN (one in each room), all running SwitchOS/SwOS instead of the stock RouterOS (they dual-boot, your choice), and I am very happy with them.

The Mikrotik CRS will work as a "gateway" right? That is, run a DHCP server, connect to my cable modem, provide local DNS, etc? Thanks!

Yep, that’s how they come by default, booting into RouterOS. I prefer my switches to just be switches, though, so I run SwOS and do all that service stuff jailed on a FreeBSD router PC.

Re: Ubiquiti Networks Breach

#252
I followed the instructions in their email: 1. change password, and 2. enable 2FA (confirm enabled in my case).

Password change went fine. I expected existing sessions to my controller login would be terminated upon a password change. I suppose that's not mandatory but it sure wouldn't be surprising behaviour for security software IMO. It's the conservative thing to do, no?

Nope. Already logged-in sessions (web and iOS app) remained functional when I changed the underlying password. No need to re-authenticate.

Before I received their breach email today, the past two days I have been unable to log into my controller at all. This was being reported by others through unofficial channels at the same time (Twitter, Reddit). Ubiquiti was silent until this morning. Maybe it's just a bad coincidence.

I'm a new Ubiquiti customer. My gear is < 30 days old. Their UniFi Dream Machine seemed to be my "dream" for a home network (AP, VPN, notifications, guests, pretty dashboard). It's probably better than the alternatives. But I'm forming a less than stellar first impression of them after this. Honeymoon over.

Re: Ubiquiti Networks Breach

#253

Earlier quoted context omitted.

Speaking of security... I fell for their marketing and slick Apple-like design and decided to add a UDM-Pro router and access point to my pre-existing network. I thought I was doing something wrong when the UDM-Pro ignored everything on my network that wasn't connected directly to a Unifi device. I asked about it on the Ubiquiti subreddit and basically got blackballed for "whining". Opened a support ticket with Ubiqu…

I'm not clear what you were trying to achieve? You had unmanaged switches on your network, and were trying to manage thier downstream connections? What exactly do you mean by 'breach the firewall'?

It's a basic home network. I had a simple netgear unmanaged switch and an apple airport extreme in bridged mode. The equipment works and i didn't want to add more trash to the landfill and spend money i didn't need, so I wanted to continue to use them.

There is no way to identify any clients on your network that are either behind the switch or behind the airport (even in bridged mode). I would expect at least some list of clients based on DHCP leases or the ARP table, but they are not accessible through the UI.

I have a robotic vacuum from china, and i want to stop it from calling home. There's isn't even a way to find out the IP or what traffic it's sending through the UDM pro, and no way to set blocking rules from the UI.

I understand if they want to provide wifi mesh support and other special wifi features for unifi devices only, but the supposed "enterprise grade" router and FW functionality should support standard network setups, since all traffic goes through the UDM-Pro, and it is certainly aware of the clients since it gave them DHCP leases, and they are in the ARP table (which is only accesible through the SSH command line) and are on the same subnet. It's unacceptable in my opinion.

Re: Ubiquiti Networks Breach

#254

Earlier quoted context omitted.

Speaking of security... I fell for their marketing and slick Apple-like design and decided to add a UDM-Pro router and access point to my pre-existing network. I thought I was doing something wrong when the UDM-Pro ignored everything on my network that wasn't connected directly to a Unifi device. I asked about it on the Ubiquiti subreddit and basically got blackballed for "whining". Opened a support ticket with Ubiqu…

Hi, Could you elaborate a bit more about your previous network setup? This sounds awful.

See my response above.

Re: Ubiquiti Networks Breach

#255
post #229

Earlier quoted context omitted.

Speaking of security... I fell for their marketing and slick Apple-like design and decided to add a UDM-Pro router and access point to my pre-existing network. I thought I was doing something wrong when the UDM-Pro ignored everything on my network that wasn't connected directly to a Unifi device. I asked about it on the Ubiquiti subreddit and basically got blackballed for "whining". Opened a support ticket with Ubiqu…

I am not sure I am following, can you elaborate? The way you wrote it sounds impossible.

See my response above.

Re: Ubiquiti Networks Breach

#256

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

Ubiquiti hardware and software is still amazing, and I'm willing to bet there are far more satisfied users than the few people grumbling on this forum. Cloud login is not mandatory if you choose not to enable it. No products are perfect, but for the use case of "more technical than average user" looking for better quality than your typical home-grade gear, I have not found anything better or more polished.

That’s actually not true anymore. After their latest update, my cloud key plus gen 2 requires me to sign on using their SSO. Not something you can remove anymore. Lots of people are (rightly) up in arms about this That being said, I still love my Ubiquiti products

Re: Ubiquiti Networks Breach

#257

I followed the instructions in their email: 1. change password, and 2. enable 2FA (confirm enabled in my case). Password change went fine. I expected existing sessions to my controller login would be terminated upon a password change. I suppose that's not mandatory but it sure wouldn't be surprising behaviour for security software IMO. It's the conservative thing to do, no? Nope. Already logged-in sessions (web and i…

I feel to the hype. And now I hold my friends and coworkers who hyped them in much lower steem.

Bought one Access point "PRO".

It is a hacked version of openWRT. No GPL sources anywhere on their site.

Downloaded the unifi controller to run on a debian 10 image.... a closed source java app. And it requires java8 from sun. pain to install on debian but fine.

Next, it requires an old version of mongodb. Sigh. no package available for debian 10. Compile from source, this is a nightmare on itself, but done.

A bunch more /fun/ with decades old software dependencies later, i have a unifi controller running.

Now, I learn that despite them advertising (and showing screen shots) that i can setup VLANs with that product (and the product page advertise support for N vlans) i learn it is just a dumb unmanaged AP. I write that off as a $150 lesson.

The UI says that if i buy another piece of the hype puzzle it will enable the feature i bought the "pro" AP for. But at this point, i know i will also learn i will need a something-key, and then something else. ...thanks. Fool me once, shame on you, fool me twice shame on me.

I will just save the dumb unmanaged "pro" AP to use with a setup from someone else. Probably pfsense based. Heck, the time i wasted to simply satisfy the anciently deprecated dependencies for their controller, I could have send tons of patches to pfsense so the UI looked just as good as theirs :) ...which i think is their only selling point.

Re: Ubiquiti Networks Breach

#259
post #135

Earlier quoted context omitted.

Does it support Wireguard? Also RouterOS does not seem open source.

V7 supports Wireguard and UDP OVPN, it's in beta but reasonably stable, at least for home use.

finally! been waiting for any UDP VPN from mikrotik since ... 2008?

Re: Ubiquiti Networks Breach

#260

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

My primary use case for a home router is solid set and forget qos. fq_codel and cake were recently added to routeros v7 beta, which means I will be plugging in my hEX again after a few years of happy edgerouter x usage. Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?

I'm curious as to what you are doing with qos in a home setup.
Post reply on HN