Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror. Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on differ…
Is that going to the trace service? There was a falling out between teams while I was there because the cloud team wanted to collect stats from APs even when users disabled analytics in the UI. It was so bad that some of the developers and one of the leads quit because they didn't want to be a part of it. Someone on Reddit started reverse engineering it https://www.reddit.com/r/Ubiquiti/comments/lwr4ud/update_ubi...…
Ubiquiti all but confirms breach response iniquity
311–320 of 322 posts
Re: Ubiquiti all but confirms breach response iniquity
#312Earlier quoted context omitted.
Logs are typically off by default in most Enterprise software, or goes nowhere by default which is basically the same thing. Logs cost money to both collect and store. Not everyone is cheerfully burning through VC capital. Some people have budgets. Speaking of log collection, simply dumping the logs into a central repository is the same as taking the garbage to the landfill. Collecting trash just results in a big col…
It is untrue that logs are trash. I gag at the comparison. If the would just look at logs they could answer so many questions that are costing a lot of money. I am used to a Unix world, with logs as text files. They take up very little room, and it is easy to through out old ones (keeping logs for ever is foolish for a lot of reasons). I am staggered that "I turned logging on extensively for a recent Azure project. S…
System Center Operations Manager and all derived products such as the various Azure Monitor and Azure Logs offerings have craziness going on.
For example, a typical metric is stored with a 300:1 write amplification because the database schema they use repeats the fully qualified machine name, counter name, and counter instance name per measurement. This prevents the collection of a useful set of metrics at a useful frequency.
Logs are similarly generated using suuuuuuper verbose JSON, capturing everything except the critical fields you actually wanted, and then stored uncompressed record-by-record, keeping the full field names for each and every row.
What incentive do you think they have to improve on the efficiency of the wire format or the storage format if they charge by the gigabyte?
Re: Ubiquiti all but confirms breach response iniquity
#313Hang on a minute there > Ubiquiti’s IoT gear includes things like WiFi routers I understood IoT to mean wifi toasters, TVs and other home appliances. Since when was a router an IoT device? Are we going to call all nework devices IoT now. This strikes me as taking rather too much journalistic license. In fact wtf is a WiFi Router . I use Unifi to deploy Wireless Acess Points on a LAN with centralized control. It is po…
Wi-Fi router I would take to mean one of those consumer all-in-one boxes, which is what the UDM fits the description of.
I agree that this distinction is unnecessary. When we consider who wrote the article and who it's for, we should expect a bit more granularity than foggy acronyms.
Re: Ubiquiti all but confirms breach response iniquity
#314Earlier quoted context omitted.
Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.
> Compared to your average all-in-one home router, however, these are very expensive. Compared to your average all-in-one home router, however, these are also markedly less shitty.
Don't get me wrong, I see why you would spend money on Ubiquiti gear; in fact, I run a similar setup. But for your average non-technical user, it's going to be a harder sell. It's the same reason you (probably) don't run a several thousand euro enterprise WiFi at home.
Re: Ubiquiti all but confirms breach response iniquity
#315Earlier quoted context omitted.
It is untrue that logs are trash. I gag at the comparison. If the would just look at logs they could answer so many questions that are costing a lot of money. I am used to a Unix world, with logs as text files. They take up very little room, and it is easy to through out old ones (keeping logs for ever is foolish for a lot of reasons). I am staggered that "I turned logging on extensively for a recent Azure project. S…
> There is no way that this can be true unless there is some very very bad craziness going on. A real mindfuck System Center Operations Manager and all derived products such as the various Azure Monitor and Azure Logs offerings have craziness going on. For example, a typical metric is stored with a 300:1 write amplification because the database schema they use repeats the fully qualified machine name, counter name, a…
If it is too much for production, turn it on for development servers.
My foreign friends seem to know not what that means
Re: Ubiquiti all but confirms breach response iniquity
#316Earlier quoted context omitted.
Meraki go is their direct unifi competitor.
Trouble is the firewall in the Meraki Go Gateway only does 250Mbps - bit crap if you've got gigabit fibre to the house https://www.meraki-go.com/products/security-gateway/
Re: Ubiquiti all but confirms breach response iniquity
#317Earlier quoted context omitted.
Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.
> Compared to your average all-in-one home router, however, these are very expensive. Compared to your average all-in-one home router, however, these are also markedly less shitty.
Unless, of course, you find spyware shitty... Which one would think most reasonable people do.
Re: Ubiquiti all but confirms breach response iniquity
#318Earlier quoted context omitted.
> Compared to your average all-in-one home router, however, these are very expensive. Compared to your average all-in-one home router, however, these are also markedly less shitty.
Are they, though? The only difference my parents (for example) would recognize between their ISP router and Ubiquiti would (might) be that the WiFi is "a bit better". And talking about security is a bit moot, given the topic of this thread. Don't get me wrong, I see why you would spend money on Ubiquiti gear; in fact, I run a similar setup. But for your average non-technical user, it's going to be a harder sell. It's…
And yes, Ubiquiti most definitely isn't for non-technicals (Except for the AmpliFi stuff). It's more prosumer grade stuff. More features than the "gaming wifi" crap but still easier to configure than official Cisco stuff.
Re: Ubiquiti all but confirms breach response iniquity
#319Earlier quoted context omitted.
Ubiquiti does not lock their bootloaders like phone manufacturers do. It is very, very easy to run vanilla Linux (or even OpenBSD) on their hardware. I do exactly this: https://news.ycombinator.com/item?id=26645062 Octeons (not Octeon-TX) are amazing processors. Ubiquiti makes killer hardware. I hear their software is junk but wouldn't really know since I always erase it immediately after unboxing.
Do you run Debian on Ubiquiti's access points too?
Re: Ubiquiti all but confirms breach response iniquity
#320Earlier quoted context omitted.
I feel the same way - my Nighthawk is going strong with custom firmware, but my friends with Ubiquiti gear try to get me to replace it with a bunch of Unifi stuff every time I talk to them.
What firmware? I need new APs soon.