Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

341–350 of 486 posts

Re: Ubiquiti Networks Breach

#341
post #318

Earlier quoted context omitted.

This is wrong. First, the UDM is not discontinued- it's for sale right now. Second, you don't need a USG+key to do VLANs. You do need to run a Unifi controller, but you can self host that anywhere like on a RasPi or in a VM. You don't need a USG to do the tagging and routing, either... the VLANs you set in the Unifi controller will work with any router/gateway it's just not all streamlined into the controller interfa…

Same here but with opnsense instead of pfsense. It would be great to have all of the info in the controller's dashboard, but I wasn't thrilled with what ui had available over the last year and figured I'd punt buying a usg or similar down the road a few years.

I personally wouldn't recommend it, the USG and their other Unifi gateways are actually kinda limited feature wise. You get all the stuff in the dashboard, but I'd say it's fairly primitive compared to what you'd be used to in ***sense. It's a good solution for people who want something turnkey, but if you're a prosumer/homelabber type you're better off leaving switching and APs in Unifi but using something else for the gateway. I do quite like the EdgeMax routers like the ER-4 paired with Unifi, however. Just my own perspective having tried all of the above.

Re: Ubiquiti Networks Breach

#342

Earlier quoted context omitted.

Ubiquiti had a steady exodus of engineers in the past few years. It's a very different company now compared to the glory days of UniFi.

Doesn't it seem like one of the missing measurements for directors/VPs should be "amount of disappearing expertise"?

you would think, but then you'd have to actually do something to retain talent instead of hiring whoever you can whos cheaper and has no idea how any part of the software or or company works. But of course the comp/hr team never see it that way.

More the old guard leaves, the more of the old guard that leaves. Then who is left to train the new people?

Re: Ubiquiti Networks Breach

#343

Earlier quoted context omitted.

> That phenomenon is called counter-signaling, which I first ran into listening to Dan Jurafsky making the point that if a menu uses the word "fresh", its a low-brow restaurant. A high-brow restaurant would never use the word "fresh" -- the freshness is implicit in the other signals. https://kelley.iu.edu/riharbau/cs-randfinal.pdf source: https://news.ycombinator.com/item?id=25713050

Italian franchise[0] restaurant in Sacramento has this huge neon sign in their window: "health inspected". Neon . It's just that one instance of the store. Not that I've seen them all, but never seen that signage in their other stores. [0] Maybe not technically a franchise. Not sure. There are a bunch in California.

There's a bar near Union Square, SF, which has a sign including the words

> .. never had any safety issue so far

It's the 'so far' which really tickles me.

Re: Ubiquiti Networks Breach

#344
post #203
post #173

Earlier quoted context omitted.

Fitlet2 looks rather nice to me. Outfitted with an Intel J3455 CPU, and 2-4 Intel NICs, it is really power efficient for its performance class (idles at ~6 watts, for those that care). There are also some Chinese companies producing slightly cheaper boxes in this category- Qotom, Kettop, Protectli. When it comes to software, I'm conflicted. I like pfsense, but Netgate has gone a bit sour with the FLOSS community. I'd…

> I like pfsense, but Netgate has gone a bit sour with the FLOSS community I haven't kept up with pfsense. Any chance for a tl;dr?

Ok TBH I'm unprepared to back up my statement. I only vaguely recall second hand heresay in regards to their exchanges with OpenBSD developers.

Re: Ubiquiti Networks Breach

#345

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

As someone who uses Ubiquiti NanoStation M2 APs very often as a part of wireless bridging solution for our own products, I was wondering what is happening with Ubiquiti. I have close colleague in Taiwan and he was so excited to inform me that he’s now working for Ubiquiti. I was sorta shocked because I thought Ubiquiti was a US based R&D team. When it first started, I remember watching the video of all the awesome engineers that left Cisco to start this new revolution. It’s sad to hear how the company is now being driven into the ground (merely for profits over innovation). I always thought that Ubiquiti would champion something in the 5G realm that would give US an edge over everyone else.

Re: Ubiquiti Networks Breach

#346

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

I’m not sure how it is that they still don’t have a hardware update to the USG3P that can enable both IPS and DPI without throttling network speeds to sub-80Mbps speeds. It’s been years now. I’m a big fan of the ecosystem and I’ve recommended it to many people but I’m constantly astonished by the slow pace of hardware updates.

UDM Pro can do it. But there is no standalone security gateway that can do gigabit.

Re: Ubiquiti Networks Breach

#347

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

> If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.

Robert Pera (the CEO) got his start in the industry in San Jose.

Re: Ubiquiti Networks Breach

#348

Earlier quoted context omitted.

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

I would go with MikroTik. Or just one if the cheaper Ubiquiti devices, like the EdgeRouter series.

MikroTik feels like rolling your own linux router box, a bit overkill and high maintenance.

Re: Ubiquiti Networks Breach

#349
post #186

Earlier quoted context omitted.

Second this. I'm no great expert in this area but have greatly enjoyed using Ubiquiti gear for my home the past few years. If there is something else that offers a comparable experience at similar price point would be great to know. The Unifi Controller software has been some of the nicest I've used in a domestic setting.

Strange, I found the Unifi Controller web UI to be really poorly architected. 1) You start a .app that sits for a few seconds then requires you to launch the browser by clicking a button. While using the browser, you can't close the extra window for the controller. 2) On the browser, you go to a localhost website that has an invalid TLS certificate (you can a "Not Secure" warning) and have to click through to the uns…

I'm not sure it's fair to fault the Unifi software for using a self-signed SSL certificate. I think the only theoretical security risk here would be that Ubiquiti could decrypt the traffic between you and your Unifi controller, if they could somehow obtain it. (Someone please correct me if I'm wrong.) Ultimately, if you don't trust the certificate it comes with, it's not too difficult to replace it with one of your own (in fact, the page you linked explains how).

I haven't had the password manager issue you describe. KeepassXC in Chrome and Firefox both fill out my credentials successfully on the login page. I totally agree about the UX of the web application though. It feels like over time, options have become more and more hidden and the icons more cryptic.

Re: Ubiquiti Networks Breach

#350

Earlier quoted context omitted.

If you only need to VLAN-tag the 4 ports on that one device, you can do it with like… about literally anything? e.g. an Archer C1750 with OpenWRT does that easily. The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.

I need to set up multiple wifi SSIDs, each on a distinct VLAN, and apply firewall rules to ensure things like: hosts in the "home" vlan can open connections to hosts in the "iot" vlan, but "iot" cannot open connections to "home".

Meraki does multiple wifi SSIDs. Probably does the firewalling too.
Post reply on HN