Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

101–110 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#101

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

While I've not yet made the purchase, I'm eyeing a Synology RT2600ac ( https://www.synology.com/en-us/products/RT2600ac ) and an MR2200ac ( https://www.synology.com/en-us/products/MR2200ac#specs ). It seems like they'll be adding VLAN support in their 1.3 release ( https://community.synology.com/enu/forum/2/post/130414 ), which should be nice for adding dedicated VPN and guest networks. For me it's one of the few opt…

https://www.amazon.com/gp/customer-reviews/R3GCUBZSITZCYS/

Re: Ubiquiti all but confirms breach response iniquity

#102
post #55

You get great insight into the character of the leaders of a company watching how breaches are handled. Companies that put the customer first are transparent, and quickly take action (even if painful to customers) to ensure that customers’ data and systems stay intact and confidential. Companies that try to gloss over, hide or downplay things indicate that the leadership does not respect their customers and is only i…

If I can vent for a second, this company has no leadership. None. Things may have changed in 2 years, but I doubt it. I was messaged almost daily by random employees asking wtf was going on with the company. They were afraid for their jobs. Practically no one respected the CEO, and he was the only C-suite exec. There. Was. No. Leadership.

There was no company wide communication, and all communication channels were made private, and if you sent an email to more than a couple people you were directly rebuked by the CEO. Nobody felt like they were trusted, and the norm was for most engineers to have absolutely zero idea of what was happening in the company outside of their direct project.

Teams were constantly at odds and pitted against each other, and the CEO never resolved any conflicts between teams or employees. The company (at least the software side) was treated like Thunderdome. Some team leads and office managers took care of their people, but most people were just beaten down. I don't think I'd ever seen a less motivated, more dejected group of software developers than I did during my time there.

IMO, this kind of bullshit clown show starts from the top. And as long as the top doesn't want to fix it, it won't get fixed. And since software almost invariable ends up reflecting the structure of the organization that produced it, you get this kind of security shit show.

I hope this is the last one and they get their act together. But realistically I can't believe that'll happen.

Re: Ubiquiti all but confirms breach response iniquity

#103
post #30

Earlier quoted context omitted.

Ditto and they have also lost my recommendations. If I hear any friends thinking of Ubiquiti, I will be pointing them towards articles like the one we are discussing. I had been a bit wary of then since their push for cloud SSO etc, but these recent events have put the final nail in the coffin for me. Personally I am migrating my family's network to MicroTik gear.

A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation. The fact that doing anything , for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had…

It's not a massive ask to install MongoDB.

Unifi stuff is quite cheap for what you get for a simple reason: Each one does not need to run a webserver and all that stuff. This means that the pretty stuff has to run elsewhere. For a single site you can use a phone app and for multi site setups and MSPs you have the controllers.

The controller can be run on a Windows PC with a next next install or a Linux box with pretty minimal setup requirements.

It sounds like you might want to go the app route otherwise if you are an IT company (I own a 20 person one - so also small) then find the one screen doc with around 10 copy and paste instructions once you have say a small Debian or Ubuntu minimal installed. You could also run up a Win10 VM and install the Windows distro quite easily.

Re: Ubiquiti all but confirms breach response iniquity

#104

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

I've heard good things about TP-Link's Omada series. Their controller even looks like a clone of Unifi's

Last time I looked into this (admittedly several years ago), TP-Link had a really poor reputation for not patching known security issues in their firmware.

Not sure how much I’d trust their products unless they’ve really done a 180 in terms of security in the last year or two.

Re: Ubiquiti all but confirms breach response iniquity

#105

Earlier quoted context omitted.

Isn’t TP-link a Chinese company?

Is ubiquiti a Chinese company? Really, what a low effort idiotic post.

We can assume what they were implying, but it seems like a legitimate question.

Also, Ubiquiti is an American company, right?

Re: Ubiquiti all but confirms breach response iniquity

#106
post #60
post #43

Earlier quoted context omitted.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Re: Ubiquiti all but confirms breach response iniquity

#107

Earlier quoted context omitted.

Afaik performance will be abysmal on edge router series as the npu isn't used.

From firsthand experience: performance is in fact awesome on the edgerouters (4, 6, 8, and 12) using plain-vanilla Linux. It's a big honking MIPS chip with firehose connections to the ethernet PHYs. Precisely the kind of device you want for a router.

Awesome at what level?

Are we talking DPI at 1Gbps symmetric?

Re: Ubiquiti all but confirms breach response iniquity

#108

So, what happens now? Will Ubiquiti be held to task, by anyone?

They’ve lost my business.

I was pretty sure I’d never buy any more hardware from them after the UniFi 6.x releases, but after this I’m totally sure.

Re: Ubiquiti all but confirms breach response iniquity

#109

Earlier quoted context omitted.

Isn’t TP-link a Chinese company?

Is ubiquiti a Chinese company? Really, what a low effort idiotic post.

It's pretty hard to deny that Chinese US relations are heating up. Supporting your own supply chain is becoming a matter of national security, both in terms of potential attacks (what if they load state software on Chinese devices, especially as a response to military action), and in terms of supporting your own industry.

Re: Ubiquiti all but confirms breach response iniquity

#110
post #75

Earlier quoted context omitted.

I have a good deal of experience with Mikrotik's offerings, and I am not looking to power networks I support with a patchwork of different systems that each have their own interface. Most of the value proposition of the Unifi lineup is I can look at a single website that I host and see the WiFi clients connected to an access point, what switch feeds that access point internet (and whether its linked at gigabit or 100…

> Most of the value proposition of the Unifi lineup is I can look at a single website ... > The single pane of glass to view everything when I am many miles from the networks I support is essential It's also why we're talking about this.

[deleted]
Post reply on HN