Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

161–170 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#161
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

That’s not my experience, all the way from Meraki enterprise access points to the standard consumer WRT54GL.

First problem is 5GHz is terrible at going through walls, I don’t believe it will even go through a single brick wall and maintain decent bandwidth. Even 2.4GHz is considerably slowed by 2 or 3 drywall/plywood obstructions.

Second problem is can the mobile device you’re using return that signal through all those walls to the access point. I have noticed an huge increase in quality and snappiness of FaceTime and other high up and down bandwidth activities once I added more access points so that connections are going through only 2 or 3 walls.

For another reference, I have a hotel that needed to upgrade its network to meet the brand standards for signal strength in all the rooms, and we had to end up installing 6 access points in the drop ceiling of each hallway 15 guest rooms in length (each guest room is ~15ft wide, so the corridor was ~225ft long). It resulted in the elimination of almost all guest complaints about the wireless network.

Re: Ubiquiti all but confirms breach response iniquity

#162

So, what happens now? Will Ubiquiti be held to task, by anyone?

I’m done buying ubiquiti equipment. 6 devices, and 3 family members I recommended ubiquiti to who also have multiple devices. Clearly the market exists for what they’re offering. I am surprised at the serious lack of alternatives.

HPE seems to be aiming squarely at Ubiquiti with their Aruba Instant On line (which is distinct from the Aruba Instant line because what's life without some confusing branding?). I installed some of their APs and switches in my home a few weeks ago and it's working well. It ended up a little less expensive than comparable UBNT gear would have been and there's actual availability on their Wifi6 APs.

The APs are cloud managed only, but, personally, I trust HPE not to make a complete clown show of things the way UBNT has. But that's absolutely going to be a deal-breaker for a lot of people (especially with the way UBNT's now poisoned the well to a degree).

The big hole in that lineup is a gateway device. They just don't have anything comparable to the UDM (Pro). I'd be surprised if they don't eventually introduce something, though, given how the rest of the lineup seems pointed directly at the niche Ubiquiti is currently occupying.

Re: Ubiquiti all but confirms breach response iniquity

#163
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

My house is about that size. My detached garage is 400sqft. My barn is 1600 sqft. And my travel trailer is 37" long. My network comes into the house and the wireless needs to cover all of the structures because we need into in all the places. It's all spread over about an acre and a half. I run ethernet to a PoE AP in the garage, through an overhead crawl space that covers thale span between the house and the garage, I have b2b radios between the house and barn and the trailer has an LTE router/wifi repeater that picks up wireless from the barn.

Not super complex but no single nighthawk is gonna do it and the unifi management interface does the job. I'm not cloudy though.

Re: Ubiquiti all but confirms breach response iniquity

#164
post #33
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

I mean, don't get me wrong, there absolutely _is_ somebody who's responsible for it, but I wouldn't place any money on Ubiquiti being able to figure out who it really was. They want to brush this under the rug as fast as they can, and that means using the opportunity to pin it on somebody that's been "problematic".

I remember the cloud lead they hired out of Amazon was as toxic as they come. If he's still in charge I can see him blaming his own team members.

The culture at Ubiquiti collapsed in my last year there. The company was unrecognizable because everyone was quitting so fast.

Re: Ubiquiti all but confirms breach response iniquity

#166
post #60
post #43

Earlier quoted context omitted.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Similar to the other responses, it's the fact that I can manage my network remotely from a simple app or UI. This helps me answer phone calls from my family asking why Netflix doesn't work on TV #2, when I'm not at home. Won't solve all problems, but at least I can narrow it down and troubleshoot.

And I like the fact that I can an overview of the state of my network; one of my wired links to an AP would degrade to 100 Mbps at times, and being able to see the link speeds easily was very helpful (it was a bad ethernet cable in the end).

Before I moved to Ubiquiti I had a spate of problems with my fiber broadband, which would stop working for a few minutes at random, resetting my RDP connections. I had a vendor-supplied Linksys (I think?) router, and trying to troubleshoot it was painful. If I ever have such problems again I'll have much better diagnostics.

That said, I won't buy any Ubiquiti gear that requires the cloud, and my faith in the company is eroding. But, like others, I would be at a loss what to replace my gear with at the moment. I just hope it'll function well enough until either Ubiquiti gets it act together (again?) or a viable competitor arises.

Re: Ubiquiti all but confirms breach response iniquity

#167

Earlier quoted context omitted.

This reads like a horror story, but reminds me of a guy my boss hired once against my objections.

Indeed. Even more terrifying is using an unsafe language like C rather than Rust or C++ for systems development. shudders

C++? Safe??

Re: Ubiquiti all but confirms breach response iniquity

#168
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

Probably not big by US standards, but WiFi attenuation across multiple floors is such that an AP in the living room won't provide any decent signal one floor straight up. Depends on the materials and layout of your house...

Re: Ubiquiti all but confirms breach response iniquity

#169

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

While I've not yet made the purchase, I'm eyeing a Synology RT2600ac ( https://www.synology.com/en-us/products/RT2600ac ) and an MR2200ac ( https://www.synology.com/en-us/products/MR2200ac#specs ). It seems like they'll be adding VLAN support in their 1.3 release ( https://community.synology.com/enu/forum/2/post/130414 ), which should be nice for adding dedicated VPN and guest networks. For me it's one of the few opt…

Thank you for that link, I had not realized Synology had moved into the router space, and I've been running Synology NASes for almost a decade! Generally I've been happy with them, and on the few occasions I need tech support, it was surprisingly good (going on with zero expectations based on other companies' support in the past).

Re: Ubiquiti all but confirms breach response iniquity

#170
post #55

You get great insight into the character of the leaders of a company watching how breaches are handled. Companies that put the customer first are transparent, and quickly take action (even if painful to customers) to ensure that customers’ data and systems stay intact and confidential. Companies that try to gloss over, hide or downplay things indicate that the leadership does not respect their customers and is only i…

Most of the US leadership and many of the US employees quit in recent years. The CEO wanted to focus on international offices where employees were cheaper. It was backfiring while I was there and I heard it only got worse after I left.

Sad situation. I knew a lot of good people there who cared about making good products during the UniFi glory days. Everything collapsed fast. I knew we were in trouble when the CEO's early employee friends were disappearing and their offices were being closed without warning.

Post reply on HN