Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

61–70 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#61
post #50

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

That is my exact configuration, too. Would love to have alternatives.

I’m not aware of any alternatives that are designed as well, and if you switch the new option could just as easily be hacked or if so it on it could also be hacked but you may never realize. Though it’s good for all these people to pretend to threaten to leave since maybe that will get the company to be a little more forth right which is all we can really ask for these days.

Re: Ubiquiti all but confirms breach response iniquity

#62

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

I've heard good things about TP-Link's Omada series. Their controller even looks like a clone of Unifi's

Re: Ubiquiti all but confirms breach response iniquity

#63
post #43

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

[deleted]

Re: Ubiquiti all but confirms breach response iniquity

#64
post #52

Earlier quoted context omitted.

why would you not just run OpenBSD with PF.

Why should I choose OpenBSD over FreeBSD or even Linux with nftables?

If you’re really asking, and not making a point;

PF is created and primarily maintained by OpenBSD

OpenBSD’s base system (without extra packages) includes PF and has a focus on security.

PF in freebsd is several major versions old.

nftables (like iptables before it) is rule based and not bucket based. So high numbers of rules will not affect pf’s performance like it does with nftables.

But, for home users, probably not noticeable. Though I prefer the syntax of PF personally.

Re: Ubiquiti all but confirms breach response iniquity

#65
post #29

Ubiquiti has lost my business. And with the recent issues with Netgate/PfSense [1], it looks like OpnSense is the way to go. [1]: https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice...

why would you not just run OpenBSD with PF.

I switched from pfsense + Ubiquiti to OpenBSD + Ruckus and couldn't be happier. While the web UIs were cool for a day, with the command line I feel as though I understand exactly what I have setup a bit better. Ruckus UI is also much more friendly than Ubiquiti's - I had to actually install mongo db + VM/dock just to configure my Ubiquiti WAP? Seriously?

I just wish I had completely deleted my Ubiquiti account when I sold my WAP.

Re: Ubiquiti all but confirms breach response iniquity

#67

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

While I've not yet made the purchase, I'm eyeing a Synology RT2600ac (https://www.synology.com/en-us/products/RT2600ac) and an MR2200ac (https://www.synology.com/en-us/products/MR2200ac#specs). It seems like they'll be adding VLAN support in their 1.3 release (https://community.synology.com/enu/forum/2/post/130414), which should be nice for adding dedicated VPN and guest networks.

For me it's one of the few options available because my ISP forces me to use a transitional IPv6 technology called "MAP-E," which the UniFi products don't support. I switched ISPs after purchasing my equipment and ended up with $700 of dead weight.

Re: Ubiquiti all but confirms breach response iniquity

#68
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

Given they were stupid enough to spin up some VMs, I doubt it was someone that knew what they had access to. A skilled attacker would stay dormant sucking up all data accessible via the AWS API (including s3 stuff) and potentially keep access to the infrastructure for years.

[deleted]

Re: Ubiquiti all but confirms breach response iniquity

#69
post #64
post #52

Earlier quoted context omitted.

Why should I choose OpenBSD over FreeBSD or even Linux with nftables?

If you’re really asking, and not making a point; PF is created and primarily maintained by OpenBSD OpenBSD’s base system (without extra packages) includes PF and has a focus on security. PF in freebsd is several major versions old. nftables (like iptables before it) is rule based and not bucket based. So high numbers of rules will not affect pf’s performance like it does with nftables. But, for home users, probably n…

Wireguard has also been stable on OpenBSD which helped me with my throughput on my apu2d router hardware.

Re: Ubiquiti all but confirms breach response iniquity

#70

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

I've heard good things about TP-Link's Omada series. Their controller even looks like a clone of Unifi's

Isn’t TP-link a Chinese company?
Post reply on HN