Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

331–340 of 486 posts

Re: Ubiquiti Networks Breach

#331
post #40

I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time. I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote…

Can’t you still access a Unifi video server locally? What’s so hard about setting up a reverse proxy or VPN?

Re: Ubiquiti Networks Breach

#332
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I received an email notification before the HN article fwiw. However when I reset password for the email address they notified...crickets. I don't use UBNT for anything other than forum posts though..

Second miracle: less than 1h after posting on HN I received the reset email.

Re: Ubiquiti Networks Breach

#333
post #318

Earlier quoted context omitted.

Ironically you can do that with pretty much ANY access point. From TP-LINK, assus all the way to arruba ones (unleashed). BUT you can't do that with unifi ones alone. Go figure. You need a usg+key or the discontinued UDM you have.

This is wrong. First, the UDM is not discontinued- it's for sale right now. Second, you don't need a USG+key to do VLANs. You do need to run a Unifi controller, but you can self host that anywhere like on a RasPi or in a VM. You don't need a USG to do the tagging and routing, either... the VLANs you set in the Unifi controller will work with any router/gateway it's just not all streamlined into the controller interfa…

Same here but with opnsense instead of pfsense. It would be great to have all of the info in the controller's dashboard, but I wasn't thrilled with what ui had available over the last year and figured I'd punt buying a usg or similar down the road a few years.

Re: Ubiquiti Networks Breach

#334
post #186

Earlier quoted context omitted.

Have suggestions for an alternative? Most web UIs are garbage but the Ubiquiti one looks fine, even if it is cloud based.

Second this. I'm no great expert in this area but have greatly enjoyed using Ubiquiti gear for my home the past few years. If there is something else that offers a comparable experience at similar price point would be great to know. The Unifi Controller software has been some of the nicest I've used in a domestic setting.

Strange, I found the Unifi Controller web UI to be really poorly architected.

1) You start a .app that sits for a few seconds then requires you to launch the browser by clicking a button. While using the browser, you can't close the extra window for the controller.

2) On the browser, you go to a localhost website that has an invalid TLS certificate (you can a "Not Secure" warning) and have to click through to the unsafe website (and it's still like that in my current Unifi version).

3) The login page doesn't let you use the Chrome password manager, so you have to type it all in each time to access a local program.

4) In the web UI, the icons are not intuitive, and some combination of circles and rounded rectangles.

5) The new UI makes it seem like you can configure things that can't actually be configured outside your router.

6) Speaking of your router, Ubiquity's own EdgeRouter routers aren't supported in the Controller UI. They require a completely different interface.

In case anyone thinks the problem with the certificate is something to do with my own setup, it's not. It's a universal problem [https://help.ui.com/hc/en-us/articles/212500127-UniFi-SSL-Ce...]

Re: Ubiquiti Networks Breach

#335
post #203
post #173

Earlier quoted context omitted.

Fitlet2 looks rather nice to me. Outfitted with an Intel J3455 CPU, and 2-4 Intel NICs, it is really power efficient for its performance class (idles at ~6 watts, for those that care). There are also some Chinese companies producing slightly cheaper boxes in this category- Qotom, Kettop, Protectli. When it comes to software, I'm conflicted. I like pfsense, but Netgate has gone a bit sour with the FLOSS community. I'd…

> I like pfsense, but Netgate has gone a bit sour with the FLOSS community I haven't kept up with pfsense. Any chance for a tl;dr?

Okay this seems like a compelling reason to switch to OPNsense https://docs.opnsense.org/history/thefork.html#transparency

Re: Ubiquiti Networks Breach

#336

Earlier quoted context omitted.

It's a basic home network. I had a simple netgear unmanaged switch and an apple airport extreme in bridged mode. The equipment works and i didn't want to add more trash to the landfill and spend money i didn't need, so I wanted to continue to use them. There is no way to identify any clients on your network that are either behind the switch or behind the airport (even in bridged mode). I would expect at least some li…

This is not entirely accurate. The default logging may not capture the individual child clients, depending on your configuration (eg double nat), sure... but those child clients are still entirely at the mercy of your configuration otherwise. Saying that the clients are completely invisible/invincible, and that the fault is the Ubiquiti product, is not true.

You need to read my comment again. The clients are behind either a bridged AP or a switch, i.e. all on the same subnet, all getting their DHCP addresses from the UDM-Pro, all in the UDM-Pro's ARP table. There is NO double NAT happening here.

Furthermore I didn't say they were invincible. I just said they were invisible to the UDM-Pro's UI. Unless you have a blanket ban on outgoing LAN traffic, which would be absurd, there's no way to block access for a particular client or a particular destination address for that client.

In the case I gave, a Chinese robot vacuum with no on-device interface, please tell me how to find the IP of this robot, then block outgoing traffic from it, without SSH'ing into the UDM and running scripts. That's right, you can't, because the UDM-Pro doesn't support it.

Re: Ubiquiti Networks Breach

#337

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

Mikrotik is much better and cheaper, but you actually have to know the basics of networking to use it

Re: Ubiquiti Networks Breach

#338
post #40

I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time. I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote…

Deploying a 6 AP network some years back, I ran across this gem in some Release Notes. I can hear someone screaming JUST SHIP IT!

"Do not choose the skip option when running the Migrate Site wizard. If you do your devices may end up in a weird state."

https://unifi-forum.nl/index.php?threads/unifi-sdn-controlle...

Re: Ubiquiti Networks Breach

#339

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

I would go with MikroTik. Or just one if the cheaper Ubiquiti devices, like the EdgeRouter series.

Re: Ubiquiti Networks Breach

#340
post #135

Earlier quoted context omitted.

Does it support Wireguard? Also RouterOS does not seem open source.

Sadly RouterOS isn’t open source. They’ve received a bit of flak for their “available on request” stance on getting GPL sources too. The fact that their GPL patches aren’t readily available is pretty uncool. WireGuard isn’t supported on RouterOS 6, which is the current stable version, afaik. RouterOS 7 (currently available in beta) did support for WG in August though, as part of 7.1beta2 [1]. [1] https://mikrotik.com…

If you have any more details about the GPL issues with Mikrotik RouterOS, I recommend reporting them to the Linux developers via Software Freedom Conservancy, who have copyleft compliance projects:

https://sfconservancy.org/copyleft-compliance/#reporting

Post reply on HN