Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

271–280 of 486 posts

Re: Ubiquiti Networks Breach

#271

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

Have suggestions for an alternative? Most web UIs are garbage but the Ubiquiti one looks fine, even if it is cloud based.

You can run the controller software locally [0]; I use Unifi switches and APs, but use pfSense for routing/firewall. After getting a look at what Unifi offers for that with a Dream Machine, I'm pretty happy with my choice.

Re: Ubiquiti Networks Breach

#272

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

> brags about closing the San Jose office because he thought everyone there was too entitled.

He's not wrong

Re: Ubiquiti Networks Breach

#273
post #142

Earlier quoted context omitted.

RouterOS is not, but Mikrotik added wireguard support to their firmware sometime in mid-late 2020. IDK if its out of beta yet.

No, still very shitty beta sadly. In mikrotik communities routeros7 is a meme (it'll never arrive). Even though its here, its not.

A few months ago when ROS 7's first few public beta releases were out (and before then), I'd agree with you.

However, MikroTik seem to be making slow but steady progress with new features. Stability is still an issue to an extent, but for home use I could almost make the jump.

In fact, if I didn't use CAPsMAN to centrally control the multiple access points in my home, I would make the jump purely for fq_codel/cake AQM, Wireguard and WPA3.

Re: Ubiquiti Networks Breach

#274
post #197
post #143

Earlier quoted context omitted.

I still put the important part of my network behind my own router similar to yours (and in terms of security I think ubuntu server + whatever you need has likely much smaller attack surface than OpenWRT which is a piece of software just too tasty not to be exploited). Outside that, wifi part is hard to get right and smart switches are nice to have, but they are PITA if the firmware is never updated and there's no sin…

Can you expand on the security of an Ubuntu server (acting as firewall, router and vpn), versus a dedicated router hardware and software (eg pfsense or OpenWRT)?

openwrt contributor's focus is consumer hardware support.

I don't think the distro was ever security audited.

Re: Ubiquiti Networks Breach

#275
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I resisted for a long time, but after finding that there is no good home router that doesn't have major security drawbacks I decided to just build my own [1]. It's a bit of a chore to set up but works better than any off-the-shelf device I've ever owned. I run Debian, but I've heard other people using OpenBSD with great results as well; it's all about personal preference and what you're familiar with...

[1] https://nbailey.ca/post/linux-firewall-ids

Re: Ubiquiti Networks Breach

#276
post #266
post #149

Earlier quoted context omitted.

I recently invested in UniFi hardware with the UDM Pro and this isn't exactly correct. UniFi Protect (the video security line) requires remote access and Ubiquiti Cloud accounts or it will break in a million weird ways. If you disable cloud login you cannot reasonably use UniFi Protect.

As someone who uses UniFi Protect and refuses to use cloud-login: I disagree somewhat. It works fine, but the mobile apps become non-functional even on the same LAN. I haven't ran into any other problems.

> a major feature within my own infrastructure is completely broken

> can't see why disabling cloud login is a problem

:)

Re: Ubiquiti Networks Breach

#277
post #266

Earlier quoted context omitted.

As someone who uses UniFi Protect and refuses to use cloud-login: I disagree somewhat. It works fine, but the mobile apps become non-functional even on the same LAN. I haven't ran into any other problems.

> a major feature within my own infrastructure is completely broken > can't see why disabling cloud login is a problem :)

I was responding to "will break in a million weird ways" which is FUD to my eyes.

I do agree it is a big limitation, and I am looking for alternatives as Ubiquiti do not seem to be prioritizing getting their app to work without remote login which is truly unfortunate, since the predecessor, UniFi Video, supported this.

Re: Ubiquiti Networks Breach

#278
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Yes, I recommend MikroTik as well. Got two of their cAP wireless access points. All the features you would expect on enterprise level kit at 1/4 the price easily.

Because there are so many features the setup is not as easy as some alternatives I'm sure. But the value proposition is great.

Their "RouterOS" is standardised over pretty much all of their kit. So after you have worked it out once you should be set for anything else.

Re: Ubiquiti Networks Breach

#279
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

[deleted]

Re: Ubiquiti Networks Breach

#280

Earlier quoted context omitted.

I received one as well approximately an hour ago.

I still haven't received one, I'll update this comment if I do. -edit- I just received it at 2:42 pm pst

I got an email for a secondary account I had forgotten about at 4PM PST.
Post reply on HN