Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

471–480 of 486 posts

Re: Ubiquiti Networks Breach

#471
post #318

Earlier quoted context omitted.

This is wrong. First, the UDM is not discontinued- it's for sale right now. Second, you don't need a USG+key to do VLANs. You do need to run a Unifi controller, but you can self host that anywhere like on a RasPi or in a VM. You don't need a USG to do the tagging and routing, either... the VLANs you set in the Unifi controller will work with any router/gateway it's just not all streamlined into the controller interfa…

> you don't need a USG+key to do VLANs. You do need to run a Unifi controller Did you try? i did. The controller UI shows you a hole in the left part of the diagram and explicitly tells you "no routing control without USG"

VLANs are at layer 2 which is switching. Routing is layer 3.

I have several Unifi switches and a controller (running on an rpi) on my network but I use my own router. I can setup VLAN access ports and trunks all day on the switches no problem, but I can't control the layer 3 routing between those VLANs with the controller, which is what you're talking about. By setting up a gateway/network on each VLAN from my router I can control routing. It's just not as slick as having a USG where it's all controlled via the controller UI.

Re: Ubiquiti Networks Breach

#472
post #426
post #377

Earlier quoted context omitted.

I'm a developer from one of the cheaper engineering countries to where Ubiquiti has moved to. I'm not sure what are you implying with your comment and I hope it's not "the company is declining because the company moved talent to countries where developers are cheaper". I do personally have friends working there and they are top class developers. Living costs don't necessarily correlate with talent levels. That said I…

The whole motivation for management moving development to Brutopia is to maximize savings, they are not going for the most expensive, world-class developers of Brutopia. Bottom-of-the-barrel developers bring even greater savings, and paying peanuts has always been a great way to get monkeys.

I have heard the weather is nice in Brutopia this time of year

Re: Ubiquiti Networks Breach

#473
post #313

Earlier quoted context omitted.

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

The recommendation I've seen around is to run opnsense or pfsense for the router, then unifi APs. (I first found out about it from a YouTube channel as being a way. https://youtube.com/user/TheTecknowledge . They are PFsense resellers, which is why they talk about it. But they could go straight unifi but they don't. After running PSNs myself for the last 4 years, I like opnsense being a little more open to community…

I've been down this path before. I'd argue strongly pfSense is non-trivial and will require significant time investment for most people coming off Unifi stuff to learn the ropes, and should not be considered a serious alternative for most people. They have very different target markets and this is reflected in the software. Unifi is much closer to a "plug and play" user experience in comparison to pfSense. The customization options for pfSense are of-course fantastic.

I actually reversed this choice and am back to using the Unifi Controller again - pfSense is superb in production or more-networking-enthusiast style environments, not so nice for "average" home. I used a 5-ethernet port fan-less Intel Atom box almost identical to the one you linked for my homemade pfSense router while it was running, for that purpose it was pretty good.

Re: Ubiquiti Networks Breach

#474
post #318

Earlier quoted context omitted.

This is wrong. First, the UDM is not discontinued- it's for sale right now. Second, you don't need a USG+key to do VLANs. You do need to run a Unifi controller, but you can self host that anywhere like on a RasPi or in a VM. You don't need a USG to do the tagging and routing, either... the VLANs you set in the Unifi controller will work with any router/gateway it's just not all streamlined into the controller interfa…

> you don't need a USG+key to do VLANs. You do need to run a Unifi controller Did you try? i did. The controller UI shows you a hole in the left part of the diagram and explicitly tells you "no routing control without USG"

Yes. As I said, I do that myself with a pfSense firewall/router into Unifi switches and APs with multiple VLANs and routing between them. I've also done it with an Edgerouter + Unifi switches and APs, and a Mikrotik router too. Of course the Unifi controller doesn't control a non-Unifi router, but you can set up whatever VLAN arrangement you want in the Unifi controller and then set up your router to match and do whatever inter-VLAN routing you want separately in its own interface.

It is not all nicely integrated together if you use a separate router (obviously), but it's not like it makes it impossible. It's not even difficult... at least not any more than it would be in any other setup.

Re: Ubiquiti Networks Breach

#475

Earlier quoted context omitted.

> you don't need a USG+key to do VLANs. You do need to run a Unifi controller Did you try? i did. The controller UI shows you a hole in the left part of the diagram and explicitly tells you "no routing control without USG"

VLANs are at layer 2 which is switching. Routing is layer 3. I have several Unifi switches and a controller (running on an rpi) on my network but I use my own router. I can setup VLAN access ports and trunks all day on the switches no problem, but I can't control the layer 3 routing between those VLANs with the controller, which is what you're talking about. By setting up a gateway/network on each VLAN from my router…

A couple of their top of the line switches can actually do layer 3 switching. I haven't actually tried that, but the docs don't mention it requiring a USG so I don't think it does.

Re: Ubiquiti Networks Breach

#476
post #319
post #297

Earlier quoted context omitted.

The UDM is discontinued? I couldn't find anything on this, do you have a source?

It's not, the parent is wrong. I'm not sure if I would 100% recommend one (it depends on your needs and how nervous Ubiquiti's recent business decisions make you), but it's not discontinued nor about to be.

it's definitely not. I would still recommend the UDM, it is a very solid wifi 5 Gig device with good hackability.

Re: Ubiquiti Networks Breach

#477

Earlier quoted context omitted.

As someone who uses Ubiquiti NanoStation M2 APs very often as a part of wireless bridging solution for our own products, I was wondering what is happening with Ubiquiti. I have close colleague in Taiwan and he was so excited to inform me that he’s now working for Ubiquiti. I was sorta shocked because I thought Ubiquiti was a US based R&D team. When it first started, I remember watching the video of all the awesome en…

Innovation leads to profits, imho. "Short term profits" is the killer in most cases.

Yes of course, but there also comes a time at such companies that have experienced exponential growth (primarily attributed to innovation) that the innovation curve reaches a plateau and the focus shifts to brining in the next hot CEO to deliver profits and profits only by reducing overhead and increasing market share. At this point, any innovation and employee morale goes running out the door.

Re: Ubiquiti Networks Breach

#478

Earlier quoted context omitted.

UDM Pro can do it. But there is no standalone security gateway that can do gigabit.

UDM Pro can do it, but can't do dual NICs yet. Still.

The USG3P can do gigabit (I get very close to gigabit speeds in internet speed tests - ~950/950) but I can’t use IPS/IDS without severe performance penalties. It basically becomes a fancy router with little in the way of actual “security” besides its basic firewall functionality.

I am aware of the UDM Pro and USG Pro but those things are expensive 1U monsters. Maybe fine for SMB use but this is for home use and I’m very space constrained.

If Ubiquiti made a small footprint security gateway with some modern hardware (the USG3P is some 8 years old at this point!) I’d buy it in an instant.

Re: Ubiquiti Networks Breach

#479
post #312

Earlier quoted context omitted.

I think he's implying people in Silicon Valley are often entitled, and he's not wrong. Which is pretty hard to disagree with.

Workers should be allowed to share the fruits of the labor instead of having a rent seeker exploit them and steal it all.

it’s not the money ( actually quite underpaid) it’s the attitude

Re: Ubiquiti Networks Breach

#480
post #473
post #313

Earlier quoted context omitted.

The recommendation I've seen around is to run opnsense or pfsense for the router, then unifi APs. (I first found out about it from a YouTube channel as being a way. https://youtube.com/user/TheTecknowledge . They are PFsense resellers, which is why they talk about it. But they could go straight unifi but they don't. After running PSNs myself for the last 4 years, I like opnsense being a little more open to community…

I've been down this path before. I'd argue strongly pfSense is non-trivial and will require significant time investment for most people coming off Unifi stuff to learn the ropes, and should not be considered a serious alternative for most people. They have very different target markets and this is reflected in the software. Unifi is much closer to a "plug and play" user experience in comparison to pfSense. The custom…

Point taken. I've been running linux with iptables since 1999. I also spent a few years at Cisco doing network security stuff. So PFsense was a minimal learning curve for me.

But at the same time, I run Google WiFi points as I don't want to deal with them. :)

Post reply on HN