Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

201–210 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#201
post #43

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

> Google WiFi creating loops in the network when users try to do wired backhaul

That's very surprising to hear. The decades-old spanning tree protocol can prevent that. I in fact have a friend who has done the exact same thing (Google Wifi with wired backhaul) with no problems. It switches from 802.11s to STP with no problems.

Re: Ubiquiti all but confirms breach response iniquity

#202
post #131

Can companies be held responsible for damages from data breaches? If they could, it seems like it would incentivize more caution about what data is collected, and more investment in the security of that data. I also imagine an insurance industry, where the insurers then have expectations about what kinds of security must be in place to get reasonable premiums.

Yup, this is more or less how “cyber security” policies work.

Unless it’s changed in the last two or three years cyber security insurance policies seem only to cover the cost of notifying customers of the breach and paying for credit monitoring for whatever period of time is required in each customer’s specific jurisdiction. (When last I looked, in most states it’s none.) Every time I looked into cyber security insurance it wasn’t worthwhile at all because it didn’t provide any meaningful coverage. Maybe for a small startup with a lot of PII it would make sense but I think most companies would probably come to the same conclusion.

Re: Ubiquiti all but confirms breach response iniquity

#203
post #31

> Ubiquiti also hinted it had an idea of who was behind the attack, saying it has “well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. As we are cooperating with law enforcement in an ongoing investigation, we cannot comment further.” I personally don't believe this. IMO, this is a company who is looking for a fall guy, and _most likely_ it's going to be…

That would be the reverse of the usual strategy, wouldn't it? Most companies seem to try to pin breaches on sophisticated hacker groups backed by nation states. But then, they benefit from the perception of a threat that's impossible to defend from (so there wasn't anything they could do) - whereas Ubiquiti benefits from people thinking the attack was just a small actor that couldn't possibly threaten Ubiquiti's cust…

> nation states

Nation state is not a fancy infosec way of saying country

Re: Ubiquiti all but confirms breach response iniquity

#204
post #60

Earlier quoted context omitted.

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

Frankly I wonder at how big some of these peoples' houses are. My single seven year old Nighthawk router covers an entire 2300 square foot home and penetrates the brick walls to reach halfway up the street.

I run two AP's hard wired to the PoE switch in my closet. These AP's being in the hallways on opposite sides of my home. I run them at lower power so I don't have an excessive amount of RF blasting into neighbor's homes, but I still get good signal quality to/from each AP. Because I now have two AP's running on different channels I've effectively doubled my network throughput overall.

One important thing to think about when planning your WiFi deployment is if you have things that have poor connectivity, everything on that channel suffers. I can have several devices running at several hundred megabits of quality, but a single device being really slow bogs down the channel and suddenly everything else starts getting lots of jitter and overall poor network performance despite most devices having good signal quality. Also, your device may show it has good signal strength but it might be poor quality (bad SNR) so in reality its a poor link speed. Having things physically closer usually results in better average SNR, meaning higher speeds for everything on the channel.

Also, as others have mentioned 5GHz might make it through a wall without a lot of stuff in it, but its not going to penetrate very well through several walls. Having my AP's in the hallways means there's usually only one wall with minimal stuff in it between a device and the AP, so each device usually reports at least several hundred megabits of throughput possible.

Re: Ubiquiti all but confirms breach response iniquity

#205
post #55

You get great insight into the character of the leaders of a company watching how breaches are handled. Companies that put the customer first are transparent, and quickly take action (even if painful to customers) to ensure that customers’ data and systems stay intact and confidential. Companies that try to gloss over, hide or downplay things indicate that the leadership does not respect their customers and is only i…

Most of the US leadership and many of the US employees quit in recent years. The CEO wanted to focus on international offices where employees were cheaper. It was backfiring while I was there and I heard it only got worse after I left. Sad situation. I knew a lot of good people there who cared about making good products during the UniFi glory days. Everything collapsed fast. I knew we were in trouble when the CEO's e…

Really sad to see.

I still see no realistic alternative for the "distributed decent wifi at a reasonably SMB scale" wireless product though. Miraki I guess is as close as it gets, but then you are locked in 100% cloud and it's certainly not remotely the same price point.

I am relegating Unify to manage my APs and (some) switches for ease of use - while I enjoy CLI fun, it gets old doing routine stuff the for the 100th time.

Hopefully another company really steps up in this space, because I can't imagine having to go back to the dark days of individually managed APs and all that.

Re: Ubiquiti all but confirms breach response iniquity

#206
On this subject, does anyone know what is up with the reddit sub, r/ubiquiti? Seems to be run by u/briellie. She(?) seems like a really toxic person with some kind of business relationship with Ubiquiti like a reseller or something.

The Reddit sub seems like they are actively trying to suppress discussion of this issue. There's some allegations of censorship on the sub, but I'm not seeing it... which might actually just be confirmation that they are censoring. I don't know.

Re: Ubiquiti all but confirms breach response iniquity

#207
post #150

Earlier quoted context omitted.

What Ruckus gear are you running? Last I looked it was pretty expensive.

eBay. The secondary market for high-end network switches is excellent if you’re a buyer.

Ya I did some research and it's not bad at all. And ruckus is pretty good with their firmware options.

In fact I'm buying two new R710s to replace my very old UAC AP Pros. Was going to get the new AP 6 LR but after UIs current woes (and them dropping support for my APs way too early) I'm done with them.

Re: Ubiquiti all but confirms breach response iniquity

#208
post #5

I’m still on board with Uniquiti, tons of equipment and it wouldn’t make sense to switch everything over for small operations. But this is extremely disappointing, they’re definitely moving in a little bit of a different direction then where many of us would hope. More shiny products that increase bottom line is great but many IT officials rely on UniFi as well, I wonder how they’re responding to enterprise customers…

> they’re definitely moving in a little bit of a different direction then where many of us would hope it pains me to say this because I was there for the UniFi glory days: The old Ubiquiti is dead and gone. Almost everyone I know quit. I hope they can land on their feet and return to the glory days but I don't have much hope. The company got toxic fast at the end

Based on username/comment, let me ask, what is next?

Because the platform integration and ease of administration, no one else has and it’s great for simple networks.

Re: Ubiquiti all but confirms breach response iniquity

#209
post #146

Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…

I have said this before, but would like to reiterate that I am never touching or buying anything branded as Ubiquiti or owned by Robert Pera. This hardware is far from cheap and consumers are literally paying for adware/spyware. I really hope Ubiquiti stock takes a nosedive over the next year.

Care to elaborate?

Re: Ubiquiti all but confirms breach response iniquity

#210
post #146

Earlier quoted context omitted.

I have said this before, but would like to reiterate that I am never touching or buying anything branded as Ubiquiti or owned by Robert Pera. This hardware is far from cheap and consumers are literally paying for adware/spyware. I really hope Ubiquiti stock takes a nosedive over the next year.

Fwiw, Ubiquiti hardware is actually quite cheap.

Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.
Post reply on HN