Live data from Hacker News

Final thoughts on Ubiquiti

krebsonsecurity.com

201–210 of 238 posts

Re: Final thoughts on Ubiquiti

#201

Ubiquiti is so worried about suing Krebs meanwhile their brand reputation has turned to mud due to the quality of their products, both from my own experience and the general consensus I've heard online. If this incident had never occurred I still would have stopped recommending and using their equipment.

I've used Ubiquiti in my home for roughly 7 years now, with 2 UAP-PROs, 8 Port PoE Switch and the USG.

Apart from the USG getting a little old and struggling to cope with the latest features added (A positive in itself). I really can't think of many other solutions that tie everything together so well. Yes I've had the odd problem, or I've needed to change the config of something. But apart from that, it works fantastically and solved WiFi woes I had many years ago.

They release regular software updates to all devices, including the controller. My only issue is I think the design of the landing page on the controller has gone downhill.

Re: Final thoughts on Ubiquiti

#203

It's great that he retracted his story but the way he did it isn't so great. In particular he's removed his older incorrect stories and replaced them with a redirect to the retraction. Thankfully the Wayback Machine has archives https://web.archive.org/web/20220223015405/https://krebsonse... https://web.archive.org/web/20220711220855/https://krebsonse...

Both are also available on archive.today, which I believe is less publisher-friendly for removal requests, should that situation arise.

"All but confirms": https://archive.ph/QycQv

"Charged with extortion": https://archive.ph/V4dUu

Re: Final thoughts on Ubiquiti

#204
post #125

Earlier quoted context omitted.

Maybe part of an informal settlement ;)

The lawsuit was close to being settled ... my guess is this is part of the formal settlement.

Which also explains the delay. You don't post something like this mid-lawsuit unless it's putting issues to rest.

Re: Final thoughts on Ubiquiti

#205
post #89

Earlier quoted context omitted.

Nobody competes with them as 'Apple for networking', but MikroTik is if anything a bit cheaper and better on the actual specs etc. - just without the snazzy UI and easy GUI (highly-G) config. There's probably a lot of people who'd love Ubiquiti gear ('gadget nerds', Linus Tech Tips viewers, gamers, etc.) to whom I wouldn't recommend MikroTik, but to anyone who's.. idk, heard of iptables, I would. All the gamer-market…

> "just without the snazzy UI and easy GUI" That UI is really fucking good imo, and good UX around this stuff is massively undervalued. Apple took over the world for a reason. As far as I know nobody comes close to Ubiquiti in this space.

While I can't speak for a less technical user, I'm throwing away a nearly brand-new Ubiquiti access point on the basis that it took me like five times as long to set up client isolation as it did to manually set up PPPoE and VLAN tagging for my fiber connection on the Mikrotik I bought at the same time. Also the Mikrotik didn't install an nginx server on my laptop. I'm replacing the Ubiquiti with another Mikrotik box even though they're apparently not that great for wifi purely on the basis of the UX.

Re: Final thoughts on Ubiquiti

#206

Earlier quoted context omitted.

This is about of straightforward as a "I screwed up, I own it, I apologize" Everyone makes mistakes. Some of the good work Krebs has done seems to be completely overshadowed by a mistake here. Granted, this is probably in response to some legal action either in progress or already settled, but what more do you want from the guy?

> what more do you want from the guy? "This has taught me that my platform can be weaponized by any bad actor who can fool or manipulate me. One column from me could get a CISO fired or move a Fortune 500 company's stock price. That's a heavy responsibility that I wasn't really accounting for, but now that I understand it, I've put some thought in to it and I have made some changes that I hope will harden me and my p…

I'd like to see this, like a tech corps security incident explaination. Though I don't expect such statements from journalists.

Re: Final thoughts on Ubiquiti

#207
post #6

An accurate but pretty lacklustre "mea culpa" and retraction. I don't mind people making mistakes, everyone does, but seeing how Krebs has handled this whole episode has not inspired optimism in how he'll handle future mistakes. He was essentially used as an unwitting party in a cyber blackmail scheme, and he doesn't touch on that at all. There will continue to be nefarious parties trying to misuse his reputation, so…

It does read, to me, much like it’s something that was workshopped between Krebs, his lawyers and Ubiquiti’s.

This apology should be about Ubiquiti, not Krebs, and maybe the terseness is just a reflection of that.

Frankly I was on the fence about buying new Ubiquiti gear because of what I’d heard, and seeing this lets me reevaluate my position - which I think is the point.

Re: Final thoughts on Ubiquiti

#208

It's great that he retracted his story but the way he did it isn't so great. In particular he's removed his older incorrect stories and replaced them with a redirect to the retraction. Thankfully the Wayback Machine has archives https://web.archive.org/web/20220223015405/https://krebsonse... https://web.archive.org/web/20220711220855/https://krebsonse...

Speaking from experience with these things (although in my case, the articles we were forced to remove were absolutely and completely 100% accurate -- but the company that acquired us wanted to settle all outstanding lawsuits and ended up caving so that the transaction could close), this might have been terms of the settlement or whatever it was he came to with Ubiquiti. In our case, because our articles were in fact…

Just because you hang a press pass around your neck doesn't mean you should be allowed to recklessly spread highly damaging lies about people with impunity.

Re: Final thoughts on Ubiquiti

#209
post #33

Earlier quoted context omitted.

The problem from my end though is, who really competes with them? No one else offers the same level of control at the same (or even close) price point.

I've heard good things about MikroTik?

It's really cheap for hardware (maybe except Chinese whitebox), and software is flexible.

Re: Final thoughts on Ubiquiti

#210
post #83

Earlier quoted context omitted.

They saw the light :) I have an older device (first in 5 Ghz I think) and I was beginning to think I should upgrade it to .

Hmm I just redownloaded the 'unifi network' thingy. For one I had to go through a screen of threats telling me I shouldn't use a local application that only reminds me of the threats you have to go through when downloading the LGPL version of Qt. For two, the app is incomprehensible, it wanted me to create a "local administrator account" after i opted out of an online account and then it didn't find my old unifi ap t…

> it wanted me to create a "local administrator account" after i opted out of an online account

What alternative would you prefer? Anyone on the network can configure it? Just a password with no username?

> I still have an old version of their admin app on an old computer and that one just finds the AP and lets me configure it. So if they could do it 10 years ago they could do it now too, should they wish to.

The answer to security issues is... worse security?

> and then it didn't find my old unifi ap that is working just fine thank you.

You need to release the device from your old Unifi deployment, or factory reset the device. You don't want anyone on your network to be able to adopt your devices and seize control of your network.

Post reply on HN