As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…
Have suggestions for an alternative? Most web UIs are garbage but the Ubiquiti one looks fine, even if it is cloud based.
Ubiquiti Networks Breach
271–280 of 486 posts
Re: Ubiquiti Networks Breach
#272As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…
He's not wrong
Re: Ubiquiti Networks Breach
#273Earlier quoted context omitted.
RouterOS is not, but Mikrotik added wireguard support to their firmware sometime in mid-late 2020. IDK if its out of beta yet.
No, still very shitty beta sadly. In mikrotik communities routeros7 is a meme (it'll never arrive). Even though its here, its not.
However, MikroTik seem to be making slow but steady progress with new features. Stability is still an issue to an extent, but for home use I could almost make the jump.
In fact, if I didn't use CAPsMAN to centrally control the multiple access points in my home, I would make the jump purely for fq_codel/cake AQM, Wireguard and WPA3.
Re: Ubiquiti Networks Breach
#274Earlier quoted context omitted.
I still put the important part of my network behind my own router similar to yours (and in terms of security I think ubuntu server + whatever you need has likely much smaller attack surface than OpenWRT which is a piece of software just too tasty not to be exploited). Outside that, wifi part is hard to get right and smart switches are nice to have, but they are PITA if the firmware is never updated and there's no sin…
Can you expand on the security of an Ubuntu server (acting as firewall, router and vpn), versus a dedicated router hardware and software (eg pfsense or OpenWRT)?
I don't think the distro was ever security audited.
Re: Ubiquiti Networks Breach
#275Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
Re: Ubiquiti Networks Breach
#276Earlier quoted context omitted.
I recently invested in UniFi hardware with the UDM Pro and this isn't exactly correct. UniFi Protect (the video security line) requires remote access and Ubiquiti Cloud accounts or it will break in a million weird ways. If you disable cloud login you cannot reasonably use UniFi Protect.
As someone who uses UniFi Protect and refuses to use cloud-login: I disagree somewhat. It works fine, but the mobile apps become non-functional even on the same LAN. I haven't ran into any other problems.
> can't see why disabling cloud login is a problem
:)
Re: Ubiquiti Networks Breach
#277Earlier quoted context omitted.
As someone who uses UniFi Protect and refuses to use cloud-login: I disagree somewhat. It works fine, but the mobile apps become non-functional even on the same LAN. I haven't ran into any other problems.
> a major feature within my own infrastructure is completely broken > can't see why disabling cloud login is a problem :)
I do agree it is a big limitation, and I am looking for alternatives as Ubiquiti do not seem to be prioritizing getting their app to work without remote login which is truly unfortunate, since the predecessor, UniFi Video, supported this.
Re: Ubiquiti Networks Breach
#278Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…
Because there are so many features the setup is not as easy as some alternatives I'm sure. But the value proposition is great.
Their "RouterOS" is standardised over pretty much all of their kit. So after you have worked it out once you should be set for anything else.
Re: Ubiquiti Networks Breach
#279Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…