Earlier quoted context omitted.
These recent posts about Ubiquiti have made me look again at MikroTik. Their hardware is more affordable than I had remembered. Is there any good intro to their hardware - there are certainly a lot more options than you get with Ubiquiti. Even before now there are some limitations with UniFi that have annoyed me. Setting up more complex DNS and firewall rules requires editing the JSON config. IPv6 tunnelling isn’t we…
I use the edgerouter line for firewalls, and unifi (running on a local "cloud key", with cloud login turned off) for only access-points and some switches. This news (covering up, legal overriding good security practices) is super concerning though, and I'm definitely going to start looking around as well.
Whistleblower: Ubiquiti Breach “Catastrophic”
421–430 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#422Aaannd this is why we can't have nice things. Like trust in our vendors. Or security. Or consequences.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#423> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
I wish i had gone with the Ruckus.
The lie that you can easily self host your own controller for ubiquiti is vastly exaggerated. Spent several hours of a Saturday patching extremely ancient versions of mongodb and compiling stuff. Not to mention that if you have a VM and turn the controller off, several features of the APs will stop working. and range for their Pro AP is lacking at most.
I wish ubiquiti just published the damn shell commands so i could be able to manage it without the silly troublesome "controller" which is just an annoying web ui. So condescending and inefficient just for the sake of exploiting the customer base for lock-in effect. They are just a little cisco.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#424Also, how is this a securities case? The company did not disclose the scale of the breach to shareholders.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#425Earlier quoted context omitted.
Parent’s place? Go Eero Pro. Your future time management self will thank you.
I'll take a look at it, but also note that I need in total: Router, Wifi AP (probably two to get full coverage), Powerline extender, Point-to-point extender with a switch on the other end. Stupid outbuildings. Anyway, thanks for the tip!
Eero Pro (not standard) kit comes with 3 identical boxes, each with a third radio band for backhaul mesh, each can be wired or wireless as well.
https://evanmccann.net/blog/eero-vs-eero-pro
See comparison table illustration here:
https://evanmccann.net/blog/2021/2/eero-6-vs-eero-6-pro
Not sure if still the case, but last time I dug into it, eero was also the only consumer grade software-defined-radio router/ap, allowing them to rapidly patch for various vulns that others couldn’t necessarily or took much longer for.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#426Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#427> Adam says the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies. A root user user breach, seemingly on the organiza…
This boggles me when I see this option in any password manager (and I think every single one has this 'option'). Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.
One absolutely invaluable use-case is that it lets multiple employees share access to an account with 2FA enabled.
Many systems don’t have appropriate role/permission systems to allow for 2FA otherwise.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#428Earlier quoted context omitted.
So the question for becomes: is there just not a good enthusiast market for this stuff? I have met a number of people who are "network nerds", so I'm inclined to think the market does exist. With any of the plethora of consumer devices (Linksys, Netgear, D-Link) it's a dice roll whether your gear is complete garbage or not. A lot of the time, you're coming up snake eyes. I've got some Ubiquiti gear I bought a couple…
When did link aggregation become "fancy corporate garbage"?
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#429> “The breach was massive, customer data was at risk, access to customers’ devices deployed in corporations and homes around the world was at risk.” > “They were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,” Maybe putting your network control plane in 'the cloud' isn't such a good idea after all... Edit: Just re-read…
Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…
(also sell campus controller local no cloud ... but this route is pricey)
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#430Earlier quoted context omitted.
Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…
> having a trustworthy and secured backend. Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.