Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

81–90 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#81

Earlier quoted context omitted.

Afaik performance will be abysmal on edge router series as the npu isn't used.

From firsthand experience: performance is in fact awesome on the edgerouters (4, 6, 8, and 12) using plain-vanilla Linux. It's a big honking MIPS chip with firehose connections to the ethernet PHYs. Precisely the kind of device you want for a router.

Then you are better off buying something with a beefier cpu that costs less since it doesn't have an npu.

Re: Ubiquiti all but confirms breach response iniquity

#82

Earlier quoted context omitted.

I've heard good things about TP-Link's Omada series. Their controller even looks like a clone of Unifi's

Isn’t TP-link a Chinese company?

Is ubiquiti a Chinese company?

Really, what a low effort idiotic post.

Re: Ubiquiti all but confirms breach response iniquity

#83
post #75
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

I have a good deal of experience with Mikrotik's offerings, and I am not looking to power networks I support with a patchwork of different systems that each have their own interface. Most of the value proposition of the Unifi lineup is I can look at a single website that I host and see the WiFi clients connected to an access point, what switch feeds that access point internet (and whether its linked at gigabit or 100…

> Most of the value proposition of the Unifi lineup is I can look at a single website ...

> The single pane of glass to view everything when I am many miles from the networks I support is essential

It's also why we're talking about this.

Re: Ubiquiti all but confirms breach response iniquity

#84
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

That would be the reverse of the usual strategy, wouldn't it? Most companies seem to try to pin breaches on sophisticated hacker groups backed by nation states. But then, they benefit from the perception of a threat that's impossible to defend from (so there wasn't anything they could do) - whereas Ubiquiti benefits from people thinking the attack was just a small actor that couldn't possibly threaten Ubiquiti's cust…

Yes, you're right. But I don't really expect them to make the "smart" or "usual" play. That would honestly surprise me. Now, pinning it on somebody that was generally disliked because they constantly blocked things that had obvious gaping security holes? Basically sicking law-enforcement on somebody out of pure spite? I can absolutely believe that.

Re: Ubiquiti all but confirms breach response iniquity

#85
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

This quote says nothing at all. Obviously the perp is someone with intricate knowledge of their network.

They might as well come out and say they have well-developed evidence that the perpetrator has an IQ over 50.

Re: Ubiquiti all but confirms breach response iniquity

#86
post #60
post #43

Earlier quoted context omitted.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

> I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment?

Crap wifi was a huge thing I dealt with. Unifi fixed that completely. The ability to run a relatively complex network (by home network standards) with multi access points is nice, but the ability to administer them without CLI interface is great. I loved my edge router but touched it with trepidation. It was rock solid except when I was sucking with it. Unifi suits/suited the enthusiastic amateur.

> I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget.

Unifi used to be too, with an interface that was a bit difficult to navigate (settings spread among about 20 tabs, but it was possible to get the job done without sshing to components).

Now it’s flakey. I just rebuilt my last week which was working fine but I couldn’t log in and the UDM-P screen said it required resetting. Dark times.

Re: Ubiquiti all but confirms breach response iniquity

#87
post #48

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

During this week I've been playing around with replacing my USG with my existing home server - it already has two NICs - my first thought was to run OPNSense in a VM but nftables on NixOS seems to work well enough - there are a few examples floating online [0,1]. OpenBSD even supports the USG [2] but I couldn't think of much reason to keep the extra hardware. The next thing I want to do is reflash my Unifi APs with O…

> replacing my USG with my existing home server

I like this idea too, but would prefer that the router was physically separated and before any hardware that was in the network.

Is this a pointless concern?

Re: Ubiquiti all but confirms breach response iniquity

#88

So, what happens now? Will Ubiquiti be held to task, by anyone?

I’m done buying ubiquiti equipment. 6 devices, and 3 family members I recommended ubiquiti to who also have multiple devices.

Clearly the market exists for what they’re offering. I am surprised at the serious lack of alternatives.

Re: Ubiquiti all but confirms breach response iniquity

#89
post #75
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

I have a good deal of experience with Mikrotik's offerings, and I am not looking to power networks I support with a patchwork of different systems that each have their own interface. Most of the value proposition of the Unifi lineup is I can look at a single website that I host and see the WiFi clients connected to an access point, what switch feeds that access point internet (and whether its linked at gigabit or 100…

It seems the hackers currently in your network must value those same features. Very convenient.

Re: Ubiquiti all but confirms breach response iniquity

#90

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

I've heard good things about TP-Link's Omada series. Their controller even looks like a clone of Unifi's

Having messed with TP-Links smart plugs, I’ve been really impressed. They integrate well into Home Assistant too.
Post reply on HN