Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

151–160 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#151

So ubiquiti can't be trusted. What are the suggestions for running a ssries if home and small office networks in rented buildings (no cabling?). A UDM + nano ap / flex HD as wireless bridges & mesh wifi gave VLANS, performance monitoring, and an ease of use that let even a junior UI dev implement use it easily and correctlywhile complying with all lease req's. With the world of work at home exploding there seems to b…

OpenWRT does mesh networking and OpenWISP allow centralized management of networking appliances. The latter is compatible with the former.

Re: Ubiquiti all but confirms breach response iniquity

#152
post #30

Earlier quoted context omitted.

A friend of my boss recommended Ubiquity semi-recently. We're a small IT company, plenty of theoretical expertise but no dedicated network admins, so it made sense to go on a recommendation. The fact that doing anything , for example assigning a VLAN to a switch port, requires you to first setup a mongodb server on your machine before you can install the controller software tipped me off to the quality of what we had…

It's not a massive ask to install MongoDB. Unifi stuff is quite cheap for what you get for a simple reason: Each one does not need to run a webserver and all that stuff. This means that the pretty stuff has to run elsewhere. For a single site you can use a phone app and for multi site setups and MSPs you have the controllers. The controller can be run on a Windows PC with a next next install or a Linux box with prett…

Whatever one may thing of the quality of MongoDB, they are asking you to install a defunct version.

Re: Ubiquiti all but confirms breach response iniquity

#153
post #32

By now we'll have to ask: Is it realistic to expect hardware-oriented companies to build secure software? (Yes, Apple exists.)

iOS exploits are cheaper than Android exploits because iOS exploits are so plentiful in comparison[1].

[1] https://www.cyberscoop.com/ios-zero-day-zerodium-high-supply...

Re: Ubiquiti all but confirms breach response iniquity

#154
post #43

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

Check out OpenWISP. It works with OpenWRT.

Re: Ubiquiti all but confirms breach response iniquity

#155

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

While I've not yet made the purchase, I'm eyeing a Synology RT2600ac ( https://www.synology.com/en-us/products/RT2600ac ) and an MR2200ac ( https://www.synology.com/en-us/products/MR2200ac#specs ). It seems like they'll be adding VLAN support in their 1.3 release ( https://community.synology.com/enu/forum/2/post/130414 ), which should be nice for adding dedicated VPN and guest networks. For me it's one of the few opt…

I’ve deployed several syno routers and extenders and have had 0 calls for support, they seem to just work.

The lack of mounting options and Poe power are obviously a downside for a lot of implementations but overall they appear to be solid.

Re: Ubiquiti all but confirms breach response iniquity

#156
post #148
post #101

Earlier quoted context omitted.

https://www.amazon.com/gp/customer-reviews/R3GCUBZSITZCYS/

I can at least verify a portion of the second claim of this reviewer's post. A section of the EULA does dictate that Synology grants itself the right to conduct an audit to protect their intellectual property. "Section 7. Audit.Synology will have the right to audit your compliance with the terms of this EULA. You agree to grant Synology a right to access to your facilities, equipment, books, records and documents and…

Given synology is owned and operated out of Taiwan, it’s rather silly to make claims about the prc.

As far as I know that clause was created years ago when people were using key generators to make keys for surveillance station licenses. I don’t know of anyone who has ever actually been audited.

Re: Ubiquiti all but confirms breach response iniquity

#157
I keep one 6p behind isp router to manage home network, they have good hardware but i didnt like the idea exposing to cloud, only allowed local dns, ntp. And removed all port listeners from ubi in sbin then touched a new file with same name. Latest firmware complained a lot but worked at some point. I am not sure i am fully secure but quite happy with performance

Re: Ubiquiti all but confirms breach response iniquity

#158
post #137
post #48

Earlier quoted context omitted.

During this week I've been playing around with replacing my USG with my existing home server - it already has two NICs - my first thought was to run OPNSense in a VM but nftables on NixOS seems to work well enough - there are a few examples floating online [0,1]. OpenBSD even supports the USG [2] but I couldn't think of much reason to keep the extra hardware. The next thing I want to do is reflash my Unifi APs with O…

> The next thing I want to do is reflash my Unifi APs with OpenWRT My understanding is that this doesn't work anymore because Ubiquiti started signing firmware. Your link also goes to a blank page.

Depends on the hardware, I guess? I bought an AC AP Pro last fall and had no problem flashing OpenWRT on it.

Re: Ubiquiti all but confirms breach response iniquity

#159
post #132

Earlier quoted context omitted.

Did I miss something here? I run a Unifi network with a local account and don‘t recall being forced to create a cloud account.

The UDM, UDM Pro, and I think _all_ newer controller software require cloud login at some point in the process.

It's definitely not all the new controllers, although with the UDM line you might be right. I think there's a huge intersection between people who would buy those specific devices and people who are perfectly happy to have remote access to their control plane in the cloud.

Re: Ubiquiti all but confirms breach response iniquity

#160
post #75

Earlier quoted context omitted.

I have a good deal of experience with Mikrotik's offerings, and I am not looking to power networks I support with a patchwork of different systems that each have their own interface. Most of the value proposition of the Unifi lineup is I can look at a single website that I host and see the WiFi clients connected to an access point, what switch feeds that access point internet (and whether its linked at gigabit or 100…

> Most of the value proposition of the Unifi lineup is I can look at a single website ... > The single pane of glass to view everything when I am many miles from the networks I support is essential It's also why we're talking about this.

[deleted]
Post reply on HN