Earlier quoted context omitted.
I'm not sure what you're calling conspiracy theories since it looks like the GP edited his content, but if you think China is not exfiltrating data from hardware, let me know. I'll provide you with copious references from the recent past. Sure, the US is doing it, too.
I certainly think they do for businesses, but worrying about state actors attacking your home network is kind of pretentious until they actually do it. Are you that special? The comment was something about how if you get the FBI mad they'll fabricate a drug case against you which somehow involves hacking into your home router or possibly subpoenaing your ISP.
Whistleblower: Ubiquiti Breach “Catastrophic”
531–540 of 815 posts
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#532It really doesn't get worse than this. But isn't Ubiquiti more of a prosumer company, like MikroTik? MikroTik does get a lot of heat when they have a security vulnerability and get downranked for it as if it were far, far away from Ubiquiti's security profile (something like "US vs. some east EU country"), but this event tells a lot about Ubiquiti's upper management and their internal security practices.
Have MikroTik had any security vulnerabilities anywhere close to what has now been revealed about Ubiquiti? MikroTik's firmware seems very solid and I get the impression that they care about security and routines.
An individual vulnerability in a device is an issue but it gets patched. Hopefully it can't be exploited remotely. My biggest annoyance is when "infrastructure" ends up with outside connections in place (to the cloud or elsewhere), that breaks this model down (trusting the provider to mediate remote access, for example).
They're a big single point of failure, and this incident really proves that.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#533Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#534Earlier quoted context omitted.
Is there a community for this kind of discussion at this point? When I was an admin, and then later working in networking in the 2000s, there were tons of very active mailing lists, not just for hardcore networking but for IT-oriented stuff, mostly all faded to a shadow of their former selves. I'd be particularly interested in comparisons of Meraki/Mist/etc. for small enterprise and campus.
Some of the relevant subreddits have decent discussions from time to time. The grandfather is /r/networking, but if you look at its sidebar, there's a long list of other subreddits for more specific subjects and individual brands. Stick to the subs for professionals rather than minor home network issues and you'll find quite a few knowledgeable people and plenty of anecdotes both good and bad about different brands e…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#535Earlier quoted context omitted.
People have reported cloud login can't be disabled now.
It can still be disabled from the controller: New UI: Settings > System Settings > Administration > Enable Remote Access "Classic" UI: Settings > Remote Access > Enable Remote Access
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#536Earlier quoted context omitted.
"Cloud-based" is the implementation; the killer feature is the single pane of glass. It's just hard to implement that without putting a bunch of logic in the cloud. Hard in what way? As long as the control traffic has paths between all relevant devices over the management LAN, why does the cloud need to be used at all?
1. Putting the management UI on a local system requires some custom networking setup, and is full of security footguns. 2. Most customers who want this have multi-site setups; in that case, you need paths across the public internet too. Again security footguns, and also reliability ones. 3. Remote work is very very common for IT people. 4. Recovery from configuration mess-ups is harder if your control plane has to ru…
In the prosumer to small business segment, I would argue that there is still enormous potential value in being able to configure all of the network gear from a single GUI, not least because it doesn't then require a lot of in-house networking expertise to get something going that works and is reasonably secure.
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#537By the way, reporting to krebsonsecurity is a giant waste of potential income. This is what the SEC whistleblower program is for. You get paid for submissions there that lead to successful enforcement actions, and the payouts can be very substantial. Furthermore because payouts exist, there's an industry of competent lawyers that will happily take cases with compensation coming exclusively from your payout. Also, how…
It's already started.
'SHAREHOLDER ALERT: Ubiquiti, Inc. Investigated for Possible Securities Laws Violations by Block & Leviton LLP; Investors Should Contact the Firm'
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#538Earlier quoted context omitted.
That's awfully convenient for the company offering those products, but I want to control what happens on my network, even if that's inconvenient for some hardware vendor. Case studies, focus groups, surveys and interviews are great ways to find the unknown unknowns. Of course, you need to pay people to participate in them, and then you need to pay expensive employees to conduct, collect and analyze the results. It's…
I was thinking of those as thing you do before product release (so they're "known"). But it's not a good way to find out about reliability issues, because those only happen in especially weird situations, or over time like running out of disk space. Telemetry that tells you which features are popular is useful but does need filtering to avoid identifying individual users. But sending back errors and crashes is what's…
Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#539Re: Whistleblower: Ubiquiti Breach “Catastrophic”
#540Earlier quoted context omitted.
Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…
> Note, however, that roaming between APs is a feature of the 802.11 standard; In theory yes, but man do a lot of devices have terrible roaming heuristics. "I can still see beacons so id better stay here even though i havent received a packet in the last minute. Wouldnt want to pay the time cost of associating with that other BSS that has 5X the signal"