Shit, I had plans to refresh the network infrastructure in my parent's place with a full ubiquiti setup to replace the years of added on junk.
Parent’s place? Go Eero Pro. Your future time management self will thank you.
Whistleblower: Ubiquiti Breach “Catastrophic”
61–70 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#62Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?
I use Mikrotik (or OpenWRT) for routers, but Mikrotik is not that good on WiFi. Peeople recommend Ruckus, but it's pretty expensive (and not that easy to get second hand in Europe, or Spain at least). Is there any (good) brand with pricing between Mikrotik and a Ruckus that doesn't need a cloud connection?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#63Earlier quoted context omitted.
If i were you I’d take heart in the knowledge that the others aren’t any better, it’s just a matter of “when” they’ll get cracked in the same way
Not every network hardware provider ties everything to a "Cloud" for reasons. They may have breaches but they won't be this widespread.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#64Earlier quoted context omitted.
Same, my setup is 100% Unifi from back before they started going downhill. At least I was self-hosting the software so I wasn't bitten by this breach.
They forced cloud authentication on self hosted software too.[1] [1] https://www.reddit.com/r/Ubiquiti/comments/kslyh9/cloud_key_...
I have a few Ubiquiti devices I haven't updated in months, that don't use any cloud accounts, and I used to run their controller software in a container that I only started when I needed to administer something. But now I guess I'm never updating and will be looking to get rid of all their equipment.
What an incredibly consumer hostile and incompetent company. Shame, because the hardware pretty much works reliably.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#65> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#66> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…
What is the right way store credentials to something like this? Hardware keys?
Generate a long random password, print it out and then lock it in a safe without allowing anyone to see it.
Turn on 2FA and then lock the second factor in a different safe.
There’s virtually never a need for the root account and it’s impossible to attenuate (by design).
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#67Earlier quoted context omitted.
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
Technically, Ubiquiti does have a local option. You can run the controller locally and disable cloud login.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#68Was days away from refitting my home out with £2,000 of gear. Any other recommendations for routers, wifi and security cameras?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#69But less academically it's depressing as hell too, because the grapevine liked them for good reason and there still isn't any drop in replacement. Their p2p/p2mp gear is still solid. And UniFi was a wonderful concept solidly executed. It also eschewed the subscription/cloud bullshit so many other players are chasing, which indeed is something of a saving grace here. While there is a cloud option, lots (if not most) people can and do run their UniFi networks completely self-hosted even for remote sites. The single pane of glass, ease of provisioning and recovery, etc made sense and saved time. And they had an incredibly enthusiastic and supportive community, like when they asked about moving L3 switching way back on the old forums (back when the rot was in its earliest stages and not clear yet) they got huge amounts of feedback, their beta testing had many people putting in a lot of good work.
Such a damn stupid waste. And the nature of the beast for tech infrastructure is that market signals are always behind the curve and thus muted until things are already getting to be too late. Robert Pera also owns the majority of their stock IIRC so there isn't any way to effect an outside management change there either. It is odd to me that nobody has sought to go after them directly and aggressively, though I heard rumblings late last year that Cisco was giving a go at something clearly aimed right at the UniFi market (no subscriptions like Meraki)?
At any rate, final straw for me on routing was the flop their "UXG" has been, I finally gave up at long last and began migrating everything to OPNsense a month back. And once the single pane of glass is broken, the barrier to start moving more drops in turn and network effects (harhar) begin to go into reverse. I'd still be happy if they somehow recovered, but if they do I think it'll be a long time. Problems that build for years tend to take years to reverse too, if they can be. I hope we get some stories someday internally on how it all went down.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#70Earlier quoted context omitted.
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
It's a shame that Mikrotik doesn't have a easy to use global GUI. It's the right hardware, and great firmware and wonderful flexibility - but it needs an easy to use GUI controller to make the simple stuff easy to take over from Ubiquiti.