Live data from Hacker News

Former Ubiquiti employee charged with stealing data and extorting company

justice.gov

241–244 of 244 posts

Re: Former Ubiquiti employee charged with stealing data and extorting company

#241

Ex-Ubiquiti employee here. Nick Sharp wasn't just a senior software engineer. He was the Cloud Lead and ran the whole cloud team. His LinkedIn profile will confirm it. This is why he had access to everything. Nick had his hands in everything from GitHub to Slack and we could never understand why or how. He rose to power in the company by claiming to find a vulnerability that let him access the CEO's personal system,…

Is this why Ubiquiti quality has fallen over the last ~2 years? I went all-in on Ubiquiti almost 3 years ago and I’ve been less than thrilled with the quality and level of support. This chaos that you say happened seems to line up with what I was seeing as a customer but everyone has been shocked at how UI has dropped in terms of quality.

A lot of tech is suffering from quality issues in the past 2 years: We're in the middle of a global pandemic. Components are being stripped out left and right to meet demand, especially in the automotive sector. Ubiquiti is no different, and their store being constantly out of stock is a clear indicator of that.

Personally, I would argue that Ubiquiti handled the pandemic much better than other companies. Take the Cloud Key firmware: Back when it was first released, the thing was so unstable it had to be reset every few weeks. Every firmware update required a factory reset. Nowadays, it's solid. Even flashing beta builds is a smooth, issue-free process. Features like person and vehicle detection in their Protect lineup are a much welcome addition, as is the revamp of the Protect app. All of this happened during the pandemic.

I know people whine about how Ubiquiti unified everything under a global login, but come on.. if it works, it works. It's hardly a reason to bash Ubiquiti because you're upset you temporarily have to sign into ui.com.

Now, maybe they are putting more effort into Protect than they are into the network side of things. I don't know, because I primarily use them for Protect. With that being said, I'm fairly satisfied.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#242
post #213

Earlier quoted context omitted.

> evidence linking him to the crime keyword is "evidence". Whenever a sympathetic person/cause becomes a target of IP-address based evidence HN is overflowing with posts that IP-address isn't an evidence :)

It wasn’t IP-address based evidence. It was a chain of evidence. His Paypal account being used to purchase a VPN. That same VPN being used to access the servers with close-hold, high level credentials. His home IP being associated with the VPN after a power outage at his house. So, we have electric grid evidence that matches up with IP evidence, that matches up with Paypal account evidence. I’m not saying he is guilt…

Or the perpetrator could have been one person, no need for it to be a conspiracy. I'm not saying it's probable, and the evidence sounds convincing. But I'm sure there are lots of unfalsifiable things that have actually happened, and frame jobs have happened. Not leaning on the luxury of throwing out uncertainties (or even just offhand devil's advocate like my original comment) doesn't make someone a nutjob. My point was that it coming from his home IP isn't the strongest of evidence. I only mentioned being a "patsy" because there's pretty much no other explanation (besides him lying) for his PayPal buying the VPN and the IP from his home address. If someone got into his home network and he works from home, it's not outside the realm of possibility, or even particularly farfetched, that someone got work and PayPal credentials and acted maliciously towards the company within his network. So please tone it down with the "conspiracy theory" rhetoric.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#243

Earlier quoted context omitted.

Certainly better than Juniper SRXs and Cisco Firepowers, however if you have a lot of mangle rules you'll run into issues. Had a large amounts of drops and even more reorders with just 600M going through a 1036 with c.200 mangle rules. Haven't run into any issues with Fortigates, yet. Time will tell. Thats for Firewall/nat/router style devices, for wireless we've got a large number of unify flying saucers. I've use m…

> Fortigates Are these running a free-software stack? Couldn't find info about it since fortinet website blocks Tor traffic.

No, if you're looking for strict FOSS ideology, they're probably not what you want ;-) It's all enterprise grade: Proprietary hardware (they have some ASIC for security processing, probably helped with GPs issues) and you only get software updates as long as you're on a support contract.

OTOH I know a lot of people who are pretty happy with them, but that might relate to the fact that I recently started at a company selling them (among other brands). What impressed me most was the well executed "single pane of glass" integration of the first deployment I saw; all switches could be easily managed from the FortiGate web interface. Compared to that the Unifi Manager feels like a chaotic hack job from the 90s.

(To be fair, at home I still use Unifi APs and the switches are based on bang-for-buck: The 8P GBe 2P SFP+ Mikrotik in the study and the 24P GBe PoE 4P SFP+ Aruba as a "core" in the basement [that is, once it arrives, for now an ancient Netgear switch has core switching duty], Firewall is a loaned FortiGate, which I will probably replace with an OPNSense when I have to return it -- I'd go all FortiNet if the basement switch alone wouldn't cost about as much as my PC, though).

Re: Former Ubiquiti employee charged with stealing data and extorting company

#244

Earlier quoted context omitted.

Could be fake. The employer is marked “Confidential.”

FYI It wasn’t confidential when I posted my comment, so something changed in the last 24 hrs after the news became public.

764 people have viewed your profile in the last 24 hours - also give us your CC details and we will show you who, sign up today ~ LinkedIn
Post reply on HN