Ubiquiti has lost my business. And with the recent issues with Netgate/PfSense [1], it looks like OpnSense is the way to go. [1]: https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...
why would you not just run OpenBSD with PF.
Ubiquiti all but confirms breach response iniquity
41–50 of 322 posts
Re: Ubiquiti all but confirms breach response iniquity
#42> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
everyone believes it
Re: Ubiquiti all but confirms breach response iniquity
#43> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.
I really just want to manage an OpenWRT based network with one central web interface and not have to deal with corporate/state entities deciding to push fun changes out in the management interfaces that power these systems.
Re: Ubiquiti all but confirms breach response iniquity
#44At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewhat pricey; but, not totally unreasonable option for the home.
Any suggestions from the HN crowd?
Re: Ubiquiti all but confirms breach response iniquity
#45Earlier quoted context omitted.
A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation. The fact that doing anything , for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had…
Meraki has captured my fancy lately. Expensive but a pretty great value prop.
It doesn't have to be network equipment in the traditional sense: any old linux server will do, it's just that it needs to have a couple dozen network ports. Traffic can be limited to a gigabit per second between all the ports combined (no need for multi-gigabit backplanes or switch fabrics or what the correct term for that is). I'd almost buy a big USB hub and connect USB–Ethernet adapters, but that feels more hacky than core infrastructure is supposed to be.
Re: Ubiquiti all but confirms breach response iniquity
#46> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
Re: Ubiquiti all but confirms breach response iniquity
#47By now we'll have to ask: Is it realistic to expect hardware-oriented companies to build secure software? (Yes, Apple exists.)
Re: Ubiquiti all but confirms breach response iniquity
#48> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.
The next thing I want to do is reflash my Unifi APs with OpenWRT [3] - the hardware is fine, but at that point I'll get all the support without the controller software.
My home environment is fairly basic so moving away isn't too hard - this would obviously be much harder for a small business...
[0] - https://francis.begyn.be/blog/nixos-home-router
[1] - http://www.willghatch.net/blog/2020/06/22/nixos-raspberry-pi...
Re: Ubiquiti all but confirms breach response iniquity
#49> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…
I hope you don't end up fulfilling your own prophecy
Re: Ubiquiti all but confirms breach response iniquity
#50It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…