Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

481–486 of 486 posts

Re: Ubiquiti Networks Breach

#481

Earlier quoted context omitted.

Ubiquiti hardware and software is still amazing, and I'm willing to bet there are far more satisfied users than the few people grumbling on this forum. Cloud login is not mandatory if you choose not to enable it. No products are perfect, but for the use case of "more technical than average user" looking for better quality than your typical home-grade gear, I have not found anything better or more polished.

That’s actually not true anymore. After their latest update, my cloud key plus gen 2 requires me to sign on using their SSO. Not something you can remove anymore. Lots of people are (rightly) up in arms about this That being said, I still love my Ubiquiti products

Interesting. My UDM has an option to disable remote sign in (although I have not used it). I guess that may still require cloud SSO but simply disable remote provisioning, in which case that seems like it would solve the vast majority of use cases people would have.

Of course, if you want a locally managed device and have a relatively simple topology there are plenty of other brands and products out there. I personally love the cloud sign in &. remote provisioning.

Re: Ubiquiti Networks Breach

#482
post #390

Earlier quoted context omitted.

Good call! This just keeps getting better, sharing the URL is such a natural thing to do but of course they need to add the tracking parameters to everything.

In this case it's both tracking and a legitimate feature: being able to place unsubscribe links in the "web version". I'd argue that this feature is not worth the privacy invasion, but for it to work, you do need a secret in the URL that is always personal.

They could easily have left the unsubscribe in the email, and linked to a UID of the mass mailout text instead for the web view.

Re: Ubiquiti Networks Breach

#483
post #368

Earlier quoted context omitted.

How does one have a valid TLS cert on a piece of software that uses a "localhost website"?

You can reverse-proxy the traffic into the Ubiquity app, and have your RP terminating the TLS connection. This is what I do and I get a correct HTTPS connection to the web site.

And how is ubnt supposed to do that, on your own domain, as you've done? I suspect you don't really know how any of this works.

Re: Ubiquiti Networks Breach

#484
post #483

Earlier quoted context omitted.

You can reverse-proxy the traffic into the Ubiquity app, and have your RP terminating the TLS connection. This is what I do and I get a correct HTTPS connection to the web site.

And how is ubnt supposed to do that, on your own domain, as you've done? I suspect you don't really know how any of this works.

Well, sorry for that. I will have to google "reverse proxy" a little bit more. And thank the god of your choice for having that setup miraculously working at home on my server.

What to say - maybe before assuming that someone "don't really know how any of this works" you may, just a second, think that the person your comment is directed to has written a security reverse proxy and presented on that on one of the largest security conferences.

Or not, maybe that I really do not know how terminating traffic on MY reverse proxy and sending it upstream to MY ubnt controller works. Who knows.

Re: Ubiquiti Networks Breach

#485
post #451
post #406

Earlier quoted context omitted.

> You can also look at the proportion of field leaders. Are more from the developed nations or the developing ones? Lower cost of living does not imply developing nation. Czhech Republic or Poland or Taiwan are developed nations, all with the cost of living a fraction of Bay Area. I see Ubiquiti dev center apparently moved to Latvia. You can argue it's a depressed region of the EU but it is not a developing country b…

I’ve spent a lot of time in Czech and Poland, and while someone could argue they’re developed countries when looking at the wider gamut, it doesn’t compare well Canada, USA, UK, etc engineering talent. A lot of the engineering talent you find there is extremely limited in quantity, but it is untapped. Overall I think it’s a step in the right direction as compared to other countries we’ve outsourced work to, but let’s…

As somebody who founded and ran R&D-heavy companies in Czech Republic and in Bay Area - this is complete bullshit. Arguably the per-capita amount engineering talent is much higher in Eastern Europe, and it is untapped because the target market is small and there's lack of entrepreneurship tradition.

Sure, if you take 300M market like US and pool all the best talent to west-coast, there is a lot of engineers. But the market is saturated, and it's nigh-impossible to hire a team of the magnitude you can get in Eastern Europe. Canada? Oh please...

Re: Ubiquiti Networks Breach

#486
post #483

Earlier quoted context omitted.

And how is ubnt supposed to do that, on your own domain, as you've done? I suspect you don't really know how any of this works.

Well, sorry for that. I will have to google "reverse proxy" a little bit more. And thank the god of your choice for having that setup miraculously working at home on my server. What to say - maybe before assuming that someone "don't really know how any of this works" you may, just a second, think that the person your comment is directed to has written a security reverse proxy and presented on that on one of the large…

In that case, you'd understand the difficulties of providing a product or piece of software out of the box with valid certificates without user setup, as you've done (without running all user data through offsite servers).

I too have a working reverse proxy setup or few. I certainly don't expect something using a "localhost site" to come with valid certificates. Unless they somehow get a valid cert for https://localhost

Edit: apologies for the assumption, I didn't realise that you weren't the guy I originally replied to. I'm new around here.

Post reply on HN