Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

291–300 of 486 posts

Re: Ubiquiti Networks Breach

#291
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I received an email notification before the HN article fwiw. However when I reset password for the email address they notified...crickets. I don't use UBNT for anything other than forum posts though..

Re: Ubiquiti Networks Breach

#292

Earlier quoted context omitted.

Ubiquiti hardware and software is still amazing, and I'm willing to bet there are far more satisfied users than the few people grumbling on this forum. Cloud login is not mandatory if you choose not to enable it. No products are perfect, but for the use case of "more technical than average user" looking for better quality than your typical home-grade gear, I have not found anything better or more polished.

That’s actually not true anymore. After their latest update, my cloud key plus gen 2 requires me to sign on using their SSO. Not something you can remove anymore. Lots of people are (rightly) up in arms about this That being said, I still love my Ubiquiti products

We bought their rack-mounted NVR for the office to replace our old UniFi Video system, but have yet to start using it, because we can't find a way around the SSO.

Critique about it on their forums is removed by moderators.

Re: Ubiquiti Networks Breach

#293

Earlier quoted context omitted.

Second these guys; really easy to set up (though I did have a nightmare getting a reliable USB-R232 converter for the initial bootstrap).

Not sure if you found a good one, this one has never failed me: http://amzn.com/B00425S1H8 With a male/male extension: http://amzn.com/B00QM8ZP5E

Will take a look at it!

My current one I've nicknamed a "Pirate" R232 adapter because it has an unfortunate and hilarious effect of duplicate the lowercase 'r' character for some reason (so I see Arrrrrrrrchlinux).

I mostly administer via SSH so it's all good at the moment.

Re: Ubiquiti Networks Breach

#294
post #283

Regarding authenticity, from the TechCrunch article about this: > The networking company quickly followed its email with a post on its community pages confirming that the email was authentic, after several complained that the email sent to customers included typos. Indeed: How am I supposed to know whether this email is really from Ubiquiti? * There was apparently no official press release. * All links in the email,…

The real kicker is that the sender is no-reply@ubnt.com - why is it not @ui.com?

Re: Ubiquiti Networks Breach

#295
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

MT radios are inferior to UBNT for some outdoor non-WiFi applications. 802.11ac vs the proprietary AirFiber. Agree that MT is often a better option for wired scenarios.

Re: Ubiquiti Networks Breach

#297

Earlier quoted context omitted.

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

Ironically you can do that with pretty much ANY access point. From TP-LINK, assus all the way to arruba ones (unleashed). BUT you can't do that with unifi ones alone. Go figure. You need a usg+key or the discontinued UDM you have.

The UDM is discontinued? I couldn't find anything on this, do you have a source?

Re: Ubiquiti Networks Breach

#298
post #135

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Does it support Wireguard? Also RouterOS does not seem open source.

Although it isn't OSS, it's based on Linux and therefore semantically comprehensible by someone familiar with iptables, iptraf, etc. Unlike say IOS which will explode your brain.

Re: Ubiquiti Networks Breach

#299
post #237
post #135

Earlier quoted context omitted.

Does it support Wireguard? Also RouterOS does not seem open source.

I use a Microtik hAP AC (Small little SOHO style router with an sfp and PoE). You can easily flash it with OpenWRT and use wireguard on that. All open source too. It's great hardware but I'm no personal fan of RouterOS.

Huh. What's the experience like? Eg are there any driver issues, or edge cases with unimplemented/missing bits of functionality?

Re: Ubiquiti Networks Breach

#300
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

Yeah I originally bought their hardware after being recommended it here. Really regret that now, as I realize it was just marketing doing work.

We are just as susceptible to the stuff haha.

Post reply on HN