Can companies be held responsible for damages from data breaches? If they could, it seems like it would incentivize more caution about what data is collected, and more investment in the security of that data. I also imagine an insurance industry, where the insurers then have expectations about what kinds of security must be in place to get reasonable premiums.
Ubiquiti all but confirms breach response iniquity
131–140 of 322 posts
Re: Ubiquiti all but confirms breach response iniquity
#132Earlier quoted context omitted.
> Most of the value proposition of the Unifi lineup is I can look at a single website ... > The single pane of glass to view everything when I am many miles from the networks I support is essential It's also why we're talking about this.
Only because they made it cloud based. If they never forced people to create a cloud account - and instead allowed people to choose - this would be wildly different.
Re: Ubiquiti all but confirms breach response iniquity
#133Re: Ubiquiti all but confirms breach response iniquity
#134Earlier quoted context omitted.
I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…
Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.
Re: Ubiquiti all but confirms breach response iniquity
#135Earlier quoted context omitted.
Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.
Depends a lot on the house. My house is It wasn’t a problem until covid when multiple meeting or other streams just performed poorly on a marginal network. The Ubiquiti gear made it easier to run antennas for optimal signal. The hot thing to do is to shit on them, but I’ll be sticking with it. They’ll emerge better from this crisis and if you think that any competitor in this price point is better, you’re delusional.
Works amazingly on heating and cooling bills, but it's a pretty solid wall to radio waves.
[0] https://www.ibhs.co.uk/foil-backed-mineral-wool-50mm-thick-x...
Re: Ubiquiti all but confirms breach response iniquity
#136Earlier quoted context omitted.
These blanket statements don’t apply to everyone. It depends which Ubiquiti hardware you own and how you’ve configured it. For example, I run the UniFi controller on my FreeNAS server. There are no forced updates to it. It doesn’t update unless I update it. The firmware on my APs doesn’t update unless I update them from my controller.
Unless you're manually verifying the content of your AP firmware updates (which is a bit hard since they're closedsource), I don't understand what you're trying to say. The firmware could be compromised at the source so your FreeNAS doesn't help at all when you download and apply a compromised firmware update. Unless you're not updating your APs and keeping them vulnerable in that way :)
In my case, no, they cannot push anything to my devices. Obviously, I could pull down compromised firmware. But that's always a risk with software that I don't personally verify, which is like 99.9% of software.
As a side note: obviously this security incident doesn't give me a whole lot of confidence in how they run their systems, but at no point has it been alleged that Ubquiti's firmware updates have been tampered with.
Re: Ubiquiti all but confirms breach response iniquity
#137Earlier quoted context omitted.
Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.
During this week I've been playing around with replacing my USG with my existing home server - it already has two NICs - my first thought was to run OPNSense in a VM but nftables on NixOS seems to work well enough - there are a few examples floating online [0,1]. OpenBSD even supports the USG [2] but I couldn't think of much reason to keep the extra hardware. The next thing I want to do is reflash my Unifi APs with O…
My understanding is that this doesn't work anymore because Ubiquiti started signing firmware. Your link also goes to a blank page.
Re: Ubiquiti all but confirms breach response iniquity
#138Earlier quoted context omitted.
I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…
Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.
Make no mistake, it still "works" with just one, only slower.
Re: Ubiquiti all but confirms breach response iniquity
#139> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…