Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

411–420 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#411
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

>Seems like there is nothing good out there

Check out Ruckus. I've found their 'unleashed' stuff quite nice (no affiliation, just a customer).

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#412
post #399
post #75

I am extremely relieved none of our Ubiquiti devices are set up for this cloud shit. (We use the PtP stuff, not the APs, the cloud bits are optional there.) Then again we have a "clear skies" policy & wouldn't have bought anything that requires cloud blah. (Which covers a whole bunch of other vendors too, looking at you Cisco "SmartLicense")

What is a "clear skies" policy?

I'm guessing clear sky as in no clouds, meaning stuff should like AP/network management must remain on premise.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#413

Earlier quoted context omitted.

No, TP-Link's Omada controller can be run locally, I do that at home and at my parents' house. It is not cloud-connected unless you turn that on. Runs surprisingly well on a Raspberry Pi 2, actually. I've got a setup similar to what you're asking for. The TP-Link APs (AC1750, AC1350 and AC1200) support PoE, they're in a wireless mesh, support roaming, and all configuration is handled with one interface, no cloud invo…

Are you concerned that TP-Link is a Chinese company? Could your data be exfiltrated back to China?

What data would they even want? My WiFi password? My PPPoE password? All my https packets?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#414

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

> having a trustworthy and secured backend.

Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#415
I'll change my forum password and continue to avoid UBNT's cloud features like always.

I'm still happy with the value, stability, and security updates (!!) of my UBNT hardware.

I still won't buy gear from another vendor that wants $$$/device-year in support contracts and have unavoidable cloud controllers.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#416

Earlier quoted context omitted.

Look into Mikrotik hardware and OpenWRT. Of the Mikrotik-based hardware I'm familiar with, they support PoE. OpenWRT supports roaming and mesh networks, and is a local solution, as opposed to a cloud-based one. There are no licenses you need to pay for, either.

Mikrotik is amazing, for what you get. But of a learning curve but worth the effort, I've seen large scale wireless networks crossing mountains with their kit.

I setup a small wisp using mikrotik kit for a few neighbours, it worked well in the end, but the learning curve was immense unless you have a strong networking background. I'd setup and used openwrt before for a domestic router and this was another level of complexity to get basically functional compared to that. Thst said the level of customizabilty and scripting (albeit in a weird language) you can do is immense, so for a true power user with a lot of time on their hands, it's a good option

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#417
post #375

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Get Linux boards and USB-3 WiFi dongles with well-supported chipsets and roll your own? The other alternative is to go way up-market and buy industrial gear. Consumer gear is shit due to a race to the bottom mentality. 90% of consumers buy the cheapest. This is also what turned every TV and appliance into a feature-encrusted shitbox full of spyware.

I think you can do it with Pi-Zero and BATMAN? I gotta find my notes.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#418

Earlier quoted context omitted.

Eero is amazing. It Just Works. Apple style. Plug it in. Never fuck with it. Rock solid.

They are amazon-owned. I'd be shocked if they weren't collecting and reporting telemetry.

Yeah, but they’re still the best user-experience I’ve found, and they seem to care about code quality and doing right by their customers.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#419

Earlier quoted context omitted.

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

My personal experience with Meraki has been the very definition of vendor lock-in. The security appliance was relatively cheap, then we saw the fine print that the total bandwidth was artificially limited and increased only adaquetly two product levels up. Sorry Mr BubbleTime, you need to buy a new applicance and a new license. Your old one is worth nothing and non-transferable, watch it rot. The switches seem absurd…

Is there a community for this kind of discussion at this point? When I was an admin, and then later working in networking in the 2000s, there were tons of very active mailing lists, not just for hardcore networking but for IT-oriented stuff, mostly all faded to a shadow of their former selves.

I'd be particularly interested in comparisons of Meraki/Mist/etc. for small enterprise and campus.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#420
post #7

> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Have a look into Ruckus with their local zone director offering.
Post reply on HN