Live data from Hacker News

Final thoughts on Ubiquiti

krebsonsecurity.com

231–238 of 238 posts

Re: Final thoughts on Ubiquiti

#231
post #218

Earlier quoted context omitted.

Yeah, this reflects my views too. He's using the veneer or pretext of journalism and reporting the truth in order for him to cover sloppy sourcing.

Have you even met any Journalists?

I know a good number of them.

Most do a lot more source verification than Krebs these days, dropping/shelving stories if they can't find corroborating evidence.

Re: Final thoughts on Ubiquiti

#232
post #216

Earlier quoted context omitted.

Because it's been an active court case?

When obviously wrong, failing to acknowledge it is an interesting choice. Maybe acknowledging it has legal repercussions, but so does the path taken.

Acknowledging it absolutely has legal repercussions.

Taking ownership is positive when the other parties are interested in an ongoing positive relationship. If the other party just wants the maximum blood/retribution, it’s just falling on your sword. And in the legal arena, that can be a lot more literal than you’d think.

In this situation, Krebs could easily be completely bankrupted by Ubiquiti with a naive statement of responsibility. If he stated it particularly naively, he might even face criminal charges.

I doubt he’d go to jail, but if he was that dumb, he might say similarly naive things at a criminal trial and end up there.

Lawyers jobs include keeping their clients mouths shut so they don’t footgun themselves like that.

Even if no one at Ubiquiti had a particular axe to grind, they have no personal relationship with him, and have no reason to NOT try to get as much out of him as they can. One could argue that they’d be negligent to those they do have a relationship with (partners, shareholders, employees) if they didn’t go after him as hard as they could, as long as they didn’t cause a PR nightmare.

Re: Final thoughts on Ubiquiti

#233
post #218

Earlier quoted context omitted.

Have you even met any Journalists?

I know a good number of them. Most do a lot more source verification than Krebs these days, dropping/shelving stories if they can't find corroborating evidence.

Most for sure, but even then most I know aren’t checking everything, all the time.

Which leaves a lot of crap out there.

And most of the industry is busy trying to stay afloat and shoveling whatever random thing they can find. Only the top couple percent has the luxury of taking or leaving something juicy (if it isn’t obviously a trap).

Re: Final thoughts on Ubiquiti

#234
post #32

Before people jump on this with super negativity... mistakes happen. What is Krebs' false positive rate? I think low enough that a simple, clear explanation of why it happened is sufficient. There's no weasel words or evasion here - he owns up to the error, apologizes to affected parties, and retracts all original posts. It's true that his reporting probably caused stress for Ubiquity. I'm curious what people think i…

> What is Krebs' false positive rate? What's more important is how those false positives are handled. In this case, it feels like it was swept under the rug and he avoided addressing for as long as possible. If he had simply addressed the problem head-on as the news came out and the FBI information became public, it would have been a different story. The way he rushed to report accusations from an anonymous source (w…

I wonder if the delay in addressing it was at the advice of his lawyer so that they could negotiate with the "oops" blog post as part of a settlement

Re: Final thoughts on Ubiquiti

#235
post #89

Earlier quoted context omitted.

Nobody competes with them as 'Apple for networking', but MikroTik is if anything a bit cheaper and better on the actual specs etc. - just without the snazzy UI and easy GUI (highly-G) config. There's probably a lot of people who'd love Ubiquiti gear ('gadget nerds', Linus Tech Tips viewers, gamers, etc.) to whom I wouldn't recommend MikroTik, but to anyone who's.. idk, heard of iptables, I would. All the gamer-market…

If you have heard of IPTables, go grab OPNSense. Mikrotek makes sense when you really really really care about having the cheapest possible 10g switch. AFAIK, there is nothing that competes apples to apples with the UDM in terms of a entry level managed switch / router / WAP offering (or the UDR, which does UDM + Telephony or distributed global management)

Yeah OPN/pfSense make ..sense too I think, haven't used them personally though. But there's some hardware (primarily thinking non-router/firewalls) you couldn't have or wouldn't want them to run on, and so you might buy MikroTik, and then use them for everything so as to have only one config system to learn.

I have the SXT for example (4G antenna/modem/router) so if I wanted a managed switch or another router or whatever I'd be more inclined to get a MikroTik one just to simplify my time configuring them, similarly to but even without Ubiquiti's snazzy auto discovery etc.

Re: Final thoughts on Ubiquiti

#236
post #127

Earlier quoted context omitted.

> This is a failure across many journalists Only one journalist was involved here. I think you meant "failing of many journalists" not "failure across many". > The amount of scrutiny applied to a source is inversely proportional with how much I want to believe the source. Why do you disbelieve a source that has been greatly scrutinized? Did you mean "directly proportional"?

The sense I read from the GP is that if I want to believe the source, I'm less likely to apply strict scrutiny to what they tell me. The more I want to believe, the less I'll dig into what I'm hearing. Some things are just too good to not believe.

[deleted]

Re: Final thoughts on Ubiquiti

#237

There was a lot of discussion from ex-Ubnt employees in a January 2021 thread※ related to outsourcing and incompetent management. From what I've read, they still show ads for their products in newer Unifi Controller web interfaces and don't have a way of disabling tracking. But now that the Krebs retraction has occurred, my brain doesn't know how bad/incompetent Ubiquiti is these days. Is there an updated-for-2022 so…

I was a bit disappointed with my Dream Machine Pro at the start, but now it's getting there - they now even provide a simple VPN solution that work on top of Wireguard. What's still missing is more advance routing exposed in the interface (like dnat) and it would be perfect. I have another one deployed in a shop and it's working fine, even with the harsh hardware condition it's put in (lot of dirt/dust from auto mech…

Do you have a link to the UDM Wireguard docs? I want to upgrade to one, but not until there is official support for wg tunnels

Re: Final thoughts on Ubiquiti

#238
post #89

Earlier quoted context omitted.

Nobody competes with them as 'Apple for networking', but MikroTik is if anything a bit cheaper and better on the actual specs etc. - just without the snazzy UI and easy GUI (highly-G) config. There's probably a lot of people who'd love Ubiquiti gear ('gadget nerds', Linus Tech Tips viewers, gamers, etc.) to whom I wouldn't recommend MikroTik, but to anyone who's.. idk, heard of iptables, I would. All the gamer-market…

If you have heard of IPTables, go grab OPNSense. Mikrotek makes sense when you really really really care about having the cheapest possible 10g switch. AFAIK, there is nothing that competes apples to apples with the UDM in terms of a entry level managed switch / router / WAP offering (or the UDR, which does UDM + Telephony or distributed global management)

I run OPNSense. They're not the same thing. I meant who competes in the WiFi HW space?
Post reply on HN