Live data from Hacker News

Ubiquiti all but confirms breach response iniquity

krebsonsecurity.com

301–310 of 322 posts

Re: Ubiquiti all but confirms breach response iniquity

#301
post #60
post #43

Earlier quoted context omitted.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

I keep seeing the requests for central management interface, which leave me somewhat puzzled. Why do you need in a home environment? I run a small network with one big router and several access points, and at least with Mikrotik's gear, it's pretty much fire and forget. It has CAPsMAN[1] to centrally manage wireless networks, but I've found it to introduce unneeded complexity. Auto-updates[2] don't need any central m…

People want a power-user Meraki for the home that isn't tied to a cloud service. It's really as simple as that. Ubiquiti gave them that until they didn't. And now the inevitable breach has occurred and users are looking for a replacement.

Its pretty simple, having each device individually managed is archaic, a pain in the ass and there is no technical reason why it has to be that way.

Re: Ubiquiti all but confirms breach response iniquity

#302

It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response. At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewh…

context: former pfsense, unifi dream machine, unifi ap user

I'm running openwrt on a rpi4-2gb (usb ethernet dongle for WAN, onboard ethernet for LAN) and and a TP-LINK EAP245 access point and have been extremely happy. For reference, my connection to my ISP is 940 down / 840 up, and the pi4 handles SQM/QoS on this line without breaking a sweat

I do plan to flash openwrt on to the eap245 as soon as the 5ghz drivers become usable, I like the hardware and the stock firmware isn't bad, but just not nearly as good as openwrt. there's a port of openwrt to the eap right now but 5ghz speed is limited to 2.4ghz speed for some reason at the moment.

Re: Ubiquiti all but confirms breach response iniquity

#303
post #235

Earlier quoted context omitted.

The key is “for each packet”, because it’s bucket based it will entirely skip evaluation for packets that do not match. This is due to how the rule set is compiled, but I can see how it could be confusing if you’re used to iptables and only think in those terms. I posted the architectural diagrams of both in another comment on this thread yesterday, I think you missed that.

>The key is “for each packet”, because it’s bucket based it will entirely skip evaluation for packets that do not match. That is how it works in nftables. >but I can see how it could be confusing if you’re used to iptables and only think in those terms. Considering you're misunderstanding some basics about nftables and iptables here, I think you need to look in the mirror. >I posted the architectural diagrams of both…

Here is an article that covers performance between Linux and FreeBSD, and it leaves BSD in the dust: https://matteocroce.medium.com/linux-and-freebsd-networking-...

Also, it specifically outlined how more rules slow down of on FreeBSD, and how poor multicore support is on pf.

Re: Ubiquiti all but confirms breach response iniquity

#304
post #176

Earlier quoted context omitted.

I don't use a UI.com account to connect to the Unifi controller I host (as I don't need their inconsistently working NAT traversal to get to my controller), hopefully the networks I support are safe due to not being entangled with Ubiquiti's cloud infrastructure. Anyone who is forced to get a UI.com account (eg: UniFi Dream Machine and UDM-Pro owners) should change their credentials and do a factory reset on their ro…

> do a factory reset on their routers and Access Points ASAP This is a miserable user experience. If you do a reset and don’t know the SSH password on APs or cameras you get to spend a hellish few hours crawling though ceiling insulation, climbing ladders and physically resetting devices. It’s so shit. I’ve just done it, but not due to security concerns, but instead because of a UDM-P crapping out randomly.

>If you do a reset and don’t know the SSH password on APs or cameras

Who's fault is that if you don't have it? First thing I do when I set a new site up is record all the vital information like that for when I will inevitably need to recover stuff.

It should be standard backup/disaster recovery practices - for ANY system. Making sure you have critical information BEFORE you really need it is preparedness 101.

Re: Ubiquiti all but confirms breach response iniquity

#305

Hang on a minute there > Ubiquiti’s IoT gear includes things like WiFi routers I understood IoT to mean wifi toasters, TVs and other home appliances. Since when was a router an IoT device? Are we going to call all nework devices IoT now. This strikes me as taking rather too much journalistic license. In fact wtf is a WiFi Router . I use Unifi to deploy Wireless Acess Points on a LAN with centralized control. It is po…

Indeed - throwing around the IoT buzzword is just an unnecessary (and irrelevant) distraction.

Re: Ubiquiti all but confirms breach response iniquity

#306

Ubiquiti should really stop making cloud logins mandatory. The latest stuff (UDM/UDM Pro, Cloud Key G2) must be connected to their cloud at installation time. Remote access can be turned off but an admin account connected to their cloud remains. Without those ties to their infrastructure, this breach would not be as severe. It would just cause an attacker to see what I've bought from them, nothing else. I'm glad I ca…

I worked there and I didn't even understand why we had to force cloud logins on Dream Machine. In the early days we were all about letting people run their own controller hardware and not requiring cloud logins. No one could ever tell us why we had to force everyone to the cloud. It was a mandate from above

They utterly flushed away their biggest selling point - the only vendor in that space that didn't require a cloud login.

Beyond stupid.

Re: Ubiquiti all but confirms breach response iniquity

#307
post #66

I was about to buy Ubiquiti products and it is disappointing. Are there good alternatives other than DIYs like PfSense/BSD?

Cisco small business line is shaping up nicely. You can get used kit on ebay pretty reasonably, update firmware without needing an account or support contract (yes, I am still talking about Cisco!) and their management console is maturing. For new installs I'm likely to go in that direction since UBNT seems lost and directionless, plus regressing on their former major selling points like no cloud required.

At this point it wouldn't shock me if they announced subscription required for firmware updates and at that point screw it - might as well go Meraki or Ruckus and get actual support as well as a lot better performance.

Re: Ubiquiti all but confirms breach response iniquity

#308

Off topic but is there a good guide to middle level home network setup - something like using OpenWRT on (Rpis?) and turning that into a router and couple of access points. I was going to press buy on the setup for some ubiquiti products till a couple of days ago :-(

Unifi is still great for APs or switches. Their routers are OK if you just want the basics. If you set the controller up in a VM or raspberry pi you can stay 100% local all the time. Leave auto updates OFF, only upgrade the firmware/controller until you have a real reason to - something important gets fixed, a new feature is released you want to use - that sort of stuff.

I have sites that firmware hasn't been updated in years and doesn't need to. It always amuses me in one thread people bitch about MS, Windows 10 and forced updates then in threads like this I read people fessing to having auto updates enabled voluntarily. Ugh.

As for alternatives, Cisco's small business line is looking pretty reasonable. You can find used gear on ebay easily, you can upgrade firmware without a subscription or even needing an account (yes, I'm still talking about Cisco!) and while their management console is a bit weak, it's maturing. I think it will mature faster than UBNT who was strong out the gate but delivered nothing new or significant for almost 7 years now in routing, switching has never delivered layer 3 - especially useful for larger switches. APs seem to take longer to get bugs resolved in their firmware - but like I said if you only upgrade when you really need to that won't even effect you.

Re: Ubiquiti all but confirms breach response iniquity

#309
post #43

Earlier quoted context omitted.

Damn, that's pretty depressing. I really wouldn't like to migrate away but I can't say all the info that's been coming back has been making me want to have them as a part of my network infrastructure.

I want to fire Ubiquiti, but where can I go to get my router, wireless access points and switches in one management interface? There are plenty of poorly performing consumer grade options out there which hide all complexity, but they break in fun ways (eg: Google WiFi creating loops in the network when users try to do wired backhaul) and only tackle part of the stack. I really just want to manage an OpenWRT based net…

Keep an eye on the Cisco Small Business line - no subscription, firmware updates without an account (yes, I am still talking about Cisco) and while the management console is a bit weak, I'd wager Cisco will mature faster than UBNT can get their crap together at this point :p

Re: Ubiquiti all but confirms breach response iniquity

#310
post #102
post #55

You get great insight into the character of the leaders of a company watching how breaches are handled. Companies that put the customer first are transparent, and quickly take action (even if painful to customers) to ensure that customers’ data and systems stay intact and confidential. Companies that try to gloss over, hide or downplay things indicate that the leadership does not respect their customers and is only i…

If I can vent for a second, this company has no leadership . None. Things may have changed in 2 years, but I doubt it. I was messaged almost daily by random employees asking wtf was going on with the company. They were afraid for their jobs. Practically no one respected the CEO, and he was the only C-suite exec. There. Was. No. Leadership. There was no company wide communication, and all communication channels were m…

Even as an outsider it's beyond obvious there is no leadership or vision other than cut costs.

After Brandon left, Unifi went to shit. There hasn't been one significant feature or major function added to Unifi since then. Routing hasn't move at all in 7 years. Well, in a recent beta you can now have multiple WAN IP addresses. Whooppee. Switching hasn't gained anything - layer 3 is utter missing. QoS? Good luck.

Unifi is fine for networks with simple needs, good for prosumer use or small businesses - but if you start to scale requirements it falls over pretty quick.

It was very promising when routing/switching was added to Unifi - but it's never been fully realized :(

Post reply on HN