Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

281–290 of 486 posts

Re: Ubiquiti Networks Breach

#281

Earlier quoted context omitted.

There's also Netgate hardware, which has the added benefit of supporting development of pfSense. I have the SG-3100 and have been very happy with it. https://www.netgate.com/

Do any of these pfsense setups allow an Orbi-style network? I’ve been really unhappy with my last several router purchases.

No, you'd still need a 3rd party like Orbi or Ubiquiti. I'm running a few Ubiquiti FlexHD's in mesh and have yet to have any issues.

Re: Ubiquiti Networks Breach

#282

Earlier quoted context omitted.

I use a fair amount of their equipment at home and I don't think that you need to be concerned with this. I run my controller on a server in my basement, and no part of it (besides the WAN port on my ERL) touch the internet. There is no "cloud" requirement. The "dream machine" thing I don't get. I do like their Unifi AP line, though.

I agree, I don't understand the level of hate appearing in this thread. I use Ubiquiti gear at multiple sites and it is absolutely bullet proof and trivial to set up once you understand their model. As long as you aren't running remote access then losing control of your UI.com credentials is really a non-issue.

The problem is that their equipment is great and they would grow naturally by just keeping their hardware and software high quality. Apparently they've got new management, and they are intentionally hobbling functionality to lock users into their ecosystem.

I purchased several pieces and was planning to purchase more until I found out about their vendor lock-in aspects, and returned it all. It's really stupid because they don't have to compensate for anything with lock-in considering their high quality at their price point.

Re: Ubiquiti Networks Breach

#283
Regarding authenticity, from the TechCrunch article about this:

> The networking company quickly followed its email with a post on its community pages confirming that the email was authentic, after several complained that the email sent to customers included typos.

Indeed: How am I supposed to know whether this email is really from Ubiquiti?

* There was apparently no official press release.

* All links in the email, including the "Change password" button, are to e.g. `https://ui.us8.list-manage.com/track/click?u=somehexnumber&i...`.

* The delivering server is `mail42.atl11.rsgsv.net`, which the TLD of which doesn't seem to resolve in my browser to provide hints.

* Various news sites that reported this either just referred to "emails people got", screenshots random people got via Twitter, or link to the Mailchimp site, for which I'm not sure how to verify whether the "ubnt" account actually belongs to Ubiquiti.

Given this, how shall the normal affected user figure out that this isn't well-executed phishing?

It seems companies could do a much better job making it obvious that their emails are legit. Especially if they were just breached, and "Change password" buttons are involved.

Re: Ubiquiti Networks Breach

#284

Earlier quoted context omitted.

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

If you only need to VLAN-tag the 4 ports on that one device, you can do it with like… about literally anything? e.g. an Archer C1750 with OpenWRT does that easily. The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.

I need to set up multiple wifi SSIDs, each on a distinct VLAN, and apply firewall rules to ensure things like: hosts in the "home" vlan can open connections to hosts in the "iot" vlan, but "iot" cannot open connections to "home".

Re: Ubiquiti Networks Breach

#285
post #261

Earlier quoted context omitted.

Blue Iris is a great piece of software and Ken the developer has constantly improved it. I think there's a way to get the RTSP stream from your existing cameras.

I'm trying to recall, but maybe someone else can answer: do the UniFi cameras stream RTSP directly still, or do you still have to run their controller and re-stream it?

Log into the WebUI, set it to whatever the non-Unifi Video mode is, update the firmware, repeat, set your RTSP config, good to go.

Re: Ubiquiti Networks Breach

#286

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

> brags about closing the San Jose office because he thought everyone there was too entitled. He's not wrong

What do you mean? What was going on at Ubiquity?

Re: Ubiquiti Networks Breach

#287
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I resisted for a long time, but after finding that there is no good home router that doesn't have major security drawbacks I decided to just build my own [1]. It's a bit of a chore to set up but works better than any off-the-shelf device I've ever owned. I run Debian, but I've heard other people using OpenBSD with great results as well; it's all about personal preference and what you're familiar with... [1] https://n…

What about mikrotik? I've got the RB4011 and found it to be the perfect home/small business router

Re: Ubiquiti Networks Breach

#288
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

This sounds good, but are there any good alternatives to BlueIris that would run on a Linux server?

Re: Ubiquiti Networks Breach

#289

Earlier quoted context omitted.

I resisted for a long time, but after finding that there is no good home router that doesn't have major security drawbacks I decided to just build my own [1]. It's a bit of a chore to set up but works better than any off-the-shelf device I've ever owned. I run Debian, but I've heard other people using OpenBSD with great results as well; it's all about personal preference and what you're familiar with... [1] https://n…

What about mikrotik? I've got the RB4011 and found it to be the perfect home/small business router

I used a RB750Gr3/hEX router for nearly a year, and I wasn't terribly impressed by the software. The hardware seemed neat, but even as somebody very familiar with routing & switching I found the UI to be rather obtuse.

The other reason I decided to 'roll my own' was an in-line IDS. There seem to be 'hacky' ways to get Snort installed on the RouterOS platform, but the CPUs aren't really powerful enough to run DPI with a sufficiently large ruleset.

I also like the ability to use Ansible to manage my router/firewall. There are modules available to do this with RouterOS, but they don't seem nearly as robust and mature as the built-in Linux utilities.

Re: Ubiquiti Networks Breach

#290

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

Ironically you can do that with pretty much ANY access point. From TP-LINK, assus all the way to arruba ones (unleashed). BUT you can't do that with unifi ones alone. Go figure. You need a usg+key or the discontinued UDM you have.
Post reply on HN