Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

311–320 of 486 posts

Re: Ubiquiti Networks Breach

#311
post #40

I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time. I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote…

Not only have they engaged in multiple interface redesigns with loss of features with no apparent gains, the last firmware update removed the ability for me to use the Protect app locally on my network without needing cloud access enabled. This breach has only confirmed my belief that my home cameras must stay off their cloud. Extremely dissatisfied.

Re: Ubiquiti Networks Breach

#312

Earlier quoted context omitted.

> brags about closing the San Jose office because he thought everyone there was too entitled. He's not wrong

What do you mean? What was going on at Ubiquity?

I think he's implying people in Silicon Valley are often entitled, and he's not wrong.

Which is pretty hard to disagree with.

Re: Ubiquiti Networks Breach

#313

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

The recommendation I've seen around is to run opnsense or pfsense for the router, then unifi APs. (I first found out about it from a YouTube channel as being a way. https://youtube.com/user/TheTecknowledge . They are PFsense resellers, which is why they talk about it. But they could go straight unifi but they don't. After running PSNs myself for the last 4 years, I like opnsense being a little more open to community involvement, versus the control that PFsense has.).

Opnsense forums have lots of recommendation for hardware, which is the path I went recently. I went with https://protectli.com/, which are just some rebranded hardware sold on Alibaba, but they provide support ontop of the hardware.

Re: Ubiquiti Networks Breach

#314

Earlier quoted context omitted.

I need to set up multiple wifi SSIDs, each on a distinct VLAN, and apply firewall rules to ensure things like: hosts in the "home" vlan can open connections to hosts in the "iot" vlan, but "iot" cannot open connections to "home".

OpenWRT supports that.

Though you'll probably end up with Atheros wifi chipset on modern hardware... and I've found the OpenWRT drivers to be extremely unreliable when providing multiple SSIDs--- crashing every few days instead of weeks of uptime.

I keep hoping that one of the OpenWRT snapshots will fix it, but this is something I've been fighting with for years on multiple pieces of hardware.

Re: Ubiquiti Networks Breach

#315

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

Any idea what it would cost to develop a completely open source router?

The Turris Omnia is an OpenWRT based open source option.

Re: Ubiquiti Networks Breach

#316

Earlier quoted context omitted.

Italian franchise[0] restaurant in Sacramento has this huge neon sign in their window: "health inspected". Neon . It's just that one instance of the store. Not that I've seen them all, but never seen that signage in their other stores. [0] Maybe not technically a franchise. Not sure. There are a bunch in California.

Reminds me of a restaurant in Goa, India, which proudly advertises: "Vegetables are cleaned with clean water before use!"

In India and many other less developed countries, proper culinary hygiene is very far from universal, and contaminated water is common. It's less absurd of a statement than it would be in the US.

Re: Ubiquiti Networks Breach

#317
post #288

Earlier quoted context omitted.

I'm in the process of replacing my home Ubiquiti infrastructure. Here's what I've decided on: Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet). Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras. Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment…

This sounds good, but are there any good alternatives to BlueIris that would run on a Linux server?

I'm not aware of one, but would be interested if there was. I'd prefer to run it on Linux. Zoneminder seems to be the common recommendation, but most discussions I've seen of it have not been very positive.

There's Xeoma and Blue Cherry, neither of which I know very much about. Never heard anyone mention either of them. So I figured BlueIris was what I'd try. Seems to be what everyone on YouTube is using...

Re: Ubiquiti Networks Breach

#318

Earlier quoted context omitted.

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

Ironically you can do that with pretty much ANY access point. From TP-LINK, assus all the way to arruba ones (unleashed). BUT you can't do that with unifi ones alone. Go figure. You need a usg+key or the discontinued UDM you have.

This is wrong. First, the UDM is not discontinued- it's for sale right now. Second, you don't need a USG+key to do VLANs. You do need to run a Unifi controller, but you can self host that anywhere like on a RasPi or in a VM. You don't need a USG to do the tagging and routing, either... the VLANs you set in the Unifi controller will work with any router/gateway it's just not all streamlined into the controller interface if you use a separate gateway. I know this because I do exactly that, I have a pfSense gateway and Unifi switches/APs.

Re: Ubiquiti Networks Breach

#319
post #297

Earlier quoted context omitted.

Ironically you can do that with pretty much ANY access point. From TP-LINK, assus all the way to arruba ones (unleashed). BUT you can't do that with unifi ones alone. Go figure. You need a usg+key or the discontinued UDM you have.

The UDM is discontinued? I couldn't find anything on this, do you have a source?

It's not, the parent is wrong. I'm not sure if I would 100% recommend one (it depends on your needs and how nervous Ubiquiti's recent business decisions make you), but it's not discontinued nor about to be.

Re: Ubiquiti Networks Breach

#320

Earlier quoted context omitted.

Italian franchise[0] restaurant in Sacramento has this huge neon sign in their window: "health inspected". Neon . It's just that one instance of the store. Not that I've seen them all, but never seen that signage in their other stores. [0] Maybe not technically a franchise. Not sure. There are a bunch in California.

Reminds me of a restaurant in Goa, India, which proudly advertises: "Vegetables are cleaned with clean water before use!"

Well, it's not like Sacramento has a Ganges River...
Post reply on HN