Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

351–360 of 486 posts

Re: Ubiquiti Networks Breach

#351
post #348

Earlier quoted context omitted.

I would go with MikroTik. Or just one if the cheaper Ubiquiti devices, like the EdgeRouter series.

MikroTik feels like rolling your own linux router box, a bit overkill and high maintenance.

It's definitely overkill, but what is a homelab if not overkill? It's not really high maintenance, though. Once it's in and running you'll never have to touch it.

Re: Ubiquiti Networks Breach

#352
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

I'm sure it's also the case that your call is important to them. Isn't that what companies always say while making you wait on hold for 45 minutes?

Re: Ubiquiti Networks Breach

#353
post #283

Regarding authenticity, from the TechCrunch article about this: > The networking company quickly followed its email with a post on its community pages confirming that the email was authentic, after several complained that the email sent to customers included typos. Indeed: How am I supposed to know whether this email is really from Ubiquiti? * There was apparently no official press release. * All links in the email,…

The real kicker is that the sender is no-reply@ubnt.com - why is it not @ui.com?

ubnt.com is another one of their domains.

Re: Ubiquiti Networks Breach

#354

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

I bought a UDM Pro so I could run Unifi Protect. I got three cameras deep and their SSO went down the other day. It was impossible to access from my phone, as their app only supports SSO login.

WHAT? I bought this stuff so I could self-host and _not_ rely on other services. I guess I didn't do enough research when investing in new hardware. I didn't see anything in their spec. sheets or descriptions about needing cloud for Protect access.

Re: Ubiquiti Networks Breach

#355
post #18

Ubiquiti is slowly becoming Sonos. The difference is, their potential for bad behavior, risks and attack surface is far, far greater.

What’s wrong with Sonos? I’m about to drop a bunch on a full home setup, should I consider an alternative?

Ironically, Sonos wreaks absolute havoc on my Unifi network when I hardwire the Sonos speakers (I have 12). When I remove the ethernet cables, it comes so unreliable, it frequently loses connectivity while playing music or speakers straight up disappear.

I do have over 100 devices on the Dream machine + 4 AP-HDs network, but Unifi promised to make my network rock solid, and it's been anything but.

Re: Ubiquiti Networks Breach

#356
post #314

Earlier quoted context omitted.

Though you'll probably end up with Atheros wifi chipset on modern hardware... and I've found the OpenWRT drivers to be extremely unreliable when providing multiple SSIDs--- crashing every few days instead of weeks of uptime. I keep hoping that one of the OpenWRT snapshots will fix it, but this is something I've been fighting with for years on multiple pieces of hardware.

I bought a Linksys WRT3200ACM specifically for use with OpenWRT after a bunch of research. It's modern hardware and based on Marvell, not Atheros. I don't have lots of SSIDs, but I do have separate 5G and 2.4G SSIDs, and they're working well enough.

The Velop series, from my own inspection, seems to be based on a custom (neutered) version of OpenWRT

Re: Ubiquiti Networks Breach

#357
post #348

Earlier quoted context omitted.

MikroTik feels like rolling your own linux router box, a bit overkill and high maintenance.

It's definitely overkill, but what is a homelab if not overkill? It's not really high maintenance, though. Once it's in and running you'll never have to touch it.

Until you do and then you’ve forgotten how and what to do.

Re: Ubiquiti Networks Breach

#358

Earlier quoted context omitted.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

Mikrotik? Easier? Do not get me wrong, I love Mikrotik, but easier would not the word I would be using. This image ( https://www.reddit.com/r/mikrotik/comments/jyjgnc/mikrotik_v... ) sums it up neatly. Also, Mikrotik is not directly comparable, you cannot replace Unifi Controller with Capsman.

MikroTik is great, but hard to configure compared to UniFi AND capsman NEVER worked reliably for me.

Re: Ubiquiti Networks Breach

#359

Earlier quoted context omitted.

The real kicker is that the sender is no-reply@ubnt.com - why is it not @ui.com?

ubnt.com is another one of their domains.

My point is that it's very confusing when their main domain is ui.com and auth server is account.ui.com - there's seemingly no customer-facing reference to that domain.

Re: Ubiquiti Networks Breach

#360
post #40

I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time. I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote…

Not only have they engaged in multiple interface redesigns with loss of features with no apparent gains, the last firmware update removed the ability for me to use the Protect app locally on my network without needing cloud access enabled. This breach has only confirmed my belief that my home cameras must stay off their cloud. Extremely dissatisfied.

>engaged in multiple interface redesigns with loss of features with no apparent gains

Yeah, this has been really baffling. Their settings UI has been in a transition state between "Classic Settings" and "New Settings" for years. Neither is complete. Some settings are only in New Settings (e.g. WiFi AI), while many more are only in the Classic Settings (e.g. allow multicast from Ethernet to WiFi).

Post reply on HN