Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

211–220 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#211
I can believe that they do not keep logs of the database access. As brain dead as it sounds.

I have been in the position of implementing a client on a API I do not control. The owners of the servers (colleagues but in a different country) do not seem to know what logs are.

We get random failures from the server. I can pin down to the second when they occur (not closer because of network lag). I suspect that the server is failing under load, but the way I would find out is to... Read the logs.

My foreign colleagues do not respond to me, ghost me entirely, when I ask them to inspect the logs.

Perhaps it is a Windows/Azure thing?

Re: Ubiquiti all but confirms breach response iniquity

#212
post #43

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I know TP-Link is no Ubiquiti, but I run two identical small networks (VR-2100 routers with RE-200v4 extenders running in mesh mode), and it's pretty solid so far.

You can access your network from Tether app via cloud if you wish, too. When you enable Mesh, everything is controlled via the router. You don't need to manage anything on the extenders.

RE200 can work as an AP if you can get them a CAT5, or can provide wireless to Ethernet capability. I don't need home-wide VLANs and other exotic stuff (for a home network), but you can adjust QoS on the router in three levels and it has an embedded OpenVPN server if you fancy.

While not network related, you can temporarily or permanently turn off all LEDs on the devices so they don't create any light pollution, something I love to have.

All in all it's a great package, for my home network, at least.

Re: Ubiquiti all but confirms breach response iniquity

#213
Off topic but is there a good guide to middle level home network setup - something like using OpenWRT on (Rpis?) and turning that into a router and couple of access points.

I was going to press buy on the setup for some ubiquiti products till a couple of days ago :-(

Re: Ubiquiti all but confirms breach response iniquity

#216
post #102

Earlier quoted context omitted.

If I can vent for a second, this company has no leadership . None. Things may have changed in 2 years, but I doubt it. I was messaged almost daily by random employees asking wtf was going on with the company. They were afraid for their jobs. Practically no one respected the CEO, and he was the only C-suite exec. There. Was. No. Leadership. There was no company wide communication, and all communication channels were m…

> There was no company wide communication, and all communication channels were made private I couldn't understand why the ex-Amazon cloud lead was also in charge of Slack. When he made all channels private and put a Slackbot in every channel to monitor conversations, I knew it was all over. I'm worried his Slackbot logs are part of the leak. Guy had his hands in everything :( Same guy who took over GitHub and forced…

I mean, I didn't necessarily agree with all of his methods or reasonings on everything, but I've come to realize a lot of times his hands were just as tied as ours. And the draconian surveillance stuff? Yeah, he was directed to do that. One guess by whom.

He was "in charge" because he convinced Robert that he was the right guy for the job by finding a security flaw that let him log into Robert's personal UniFi Protect setup at his home. At that point Robert basically gave him carte blanche, but also started directing him to lock everything down. More than a bit of paranoia there, in my opinion.

Re: Ubiquiti all but confirms breach response iniquity

#217

Earlier quoted context omitted.

Fwiw, Ubiquiti hardware is actually quite cheap.

Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.

> Compared to your average all-in-one home router, however, these are very expensive.

Compared to your average all-in-one home router, however, these are also markedly less shitty.

Re: Ubiquiti all but confirms breach response iniquity

#219
post #132

Earlier quoted context omitted.

Did I miss something here? I run a Unifi network with a local account and don‘t recall being forced to create a cloud account.

The UDM, UDM Pro, and I think _all_ newer controller software require cloud login at some point in the process.

They do - first thing I did though was then go in and add a local account, and disable remote access (I have a wireguard tunnel that terminates on a server behind my firewall if I need remote access).

Re: Ubiquiti all but confirms breach response iniquity

#220

Earlier quoted context omitted.

The UDM, UDM Pro, and I think _all_ newer controller software require cloud login at some point in the process.

It's definitely not all the new controllers, although with the UDM line you might be right. I think there's a huge intersection between people who would buy those specific devices and people who are perfectly happy to have remote access to their control plane in the cloud.

It is also about dark patterns. I never had the cloud option enabled. One night after a long day I upgraded the controller software. I noticed a message like “do you want to login?” and wasn’t awake enough to realise that it asked for my ui.com account and that after that cloud management was enabled and my phone switched to authenticate from a direct connection with the local credentials to using the ui.com credentials.
Post reply on HN