Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

301–310 of 486 posts

Re: Ubiquiti Networks Breach

#301

Earlier quoted context omitted.

If you only need to VLAN-tag the 4 ports on that one device, you can do it with like… about literally anything? e.g. an Archer C1750 with OpenWRT does that easily. The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.

I need to set up multiple wifi SSIDs, each on a distinct VLAN, and apply firewall rules to ensure things like: hosts in the "home" vlan can open connections to hosts in the "iot" vlan, but "iot" cannot open connections to "home".

Look at Ruckus

Re: Ubiquiti Networks Breach

#302
post #91

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Do you know how ubiquiti's "edge" line compares to mikrotik?

After having worked intensely with Ubiquiti Edge devices (their routers specifically), I'd recommend them time and again. Their Debian derivative EdgeOS is great to work with, both as an enabler for advanced administration, but also an approachable web ui (plausible to offload many issues to support desk without requiring insane amounts of dedication to the Craft).

For mad scientists though, the very open software stack is a good friend to have when 11th hour Requirements® dictate you must produce a rabbit without a hat, or rewrite your own domain-specific implementation to replace the Avahi service.

No experience with Mikrotic.

_On topic_: With cloud news like this, it's nice to know about the availability of Ubiquitis' Network Management System[1] which you can host and run wherever.

[1]: https://unms.com/

Re: Ubiquiti Networks Breach

#303

Earlier quoted context omitted.

Ubiquiti had a steady exodus of engineers in the past few years. It's a very different company now compared to the glory days of UniFi.

Doesn't it seem like one of the missing measurements for directors/VPs should be "amount of disappearing expertise"?

Fun fact: very few directors or VPs at Ubiquiti. Very flat organization

Re: Ubiquiti Networks Breach

#304

Earlier quoted context omitted.

My primary use case for a home router is solid set and forget qos. fq_codel and cake were recently added to routeros v7 beta, which means I will be plugging in my hEX again after a few years of happy edgerouter x usage. Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?

I'm curious as to what you are doing with qos in a home setup.

Not have VoIP or gaming get disrupted whenever a large upload runs.

On my previous ISP latency would reach 2000+ ms when I let Dropbox sync or downloaded a huge file. Even web browsing would time out. I used Tomato to prioritize DNS, my VoIP analog telephone adapter, the first 256KB of any HTTP(S) connection, and some 27000+ ports used by games.

My current WAN connection reaches 300 ms without fq_codel enabled. With it enabled there's no jump in latency.

Re: Ubiquiti Networks Breach

#305

Earlier quoted context omitted.

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Yes, I recommend MikroTik as well. Got two of their cAP wireless access points. All the features you would expect on enterprise level kit at 1/4 the price easily. Because there are so many features the setup is not as easy as some alternatives I'm sure. But the value proposition is great. Their "RouterOS" is standardised over pretty much all of their kit. So after you have worked it out once you should be set for any…

One of the reason Uniquiti is so loved by techies is that you can recommend it to family/friends or set it and forget it for them (regular users also find the phone apps impressive and easy to use - it's an Apple like experience for network gear).

At this point there are probably 20+ home Unifi networks that i'm responsible for recommending or setting up, doing the same with MikroTik might turn me into a full time sysadmin :)

Re: Ubiquiti Networks Breach

#306
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Mikrotik phones home too

Re: Ubiquiti Networks Breach

#307
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

The HN story is a link to the Ubiquiti email sent via MailChimp. You may not be on their mailing list, but Ubiquiti is actively letting people know. I got the email at 2:31pm PST.

Re: Ubiquiti Networks Breach

#309

Earlier quoted context omitted.

I'm not clear what you were trying to achieve? You had unmanaged switches on your network, and were trying to manage thier downstream connections? What exactly do you mean by 'breach the firewall'?

It's a basic home network. I had a simple netgear unmanaged switch and an apple airport extreme in bridged mode. The equipment works and i didn't want to add more trash to the landfill and spend money i didn't need, so I wanted to continue to use them. There is no way to identify any clients on your network that are either behind the switch or behind the airport (even in bridged mode). I would expect at least some li…

This is not entirely accurate.

The default logging may not capture the individual child clients, depending on your configuration (eg double nat), sure... but those child clients are still entirely at the mercy of your configuration otherwise. Saying that the clients are completely invisible/invincible, and that the fault is the Ubiquiti product, is not true.

Re: Ubiquiti Networks Breach

#310

Earlier quoted context omitted.

If you only need to VLAN-tag the 4 ports on that one device, you can do it with like… about literally anything? e.g. an Archer C1750 with OpenWRT does that easily. The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.

I need to set up multiple wifi SSIDs, each on a distinct VLAN, and apply firewall rules to ensure things like: hosts in the "home" vlan can open connections to hosts in the "iot" vlan, but "iot" cannot open connections to "home".

OpenWRT supports that.
Post reply on HN