Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

391–400 of 486 posts

Re: Ubiquiti Networks Breach

#391
post #186

Earlier quoted context omitted.

Second this. I'm no great expert in this area but have greatly enjoyed using Ubiquiti gear for my home the past few years. If there is something else that offers a comparable experience at similar price point would be great to know. The Unifi Controller software has been some of the nicest I've used in a domestic setting.

Strange, I found the Unifi Controller web UI to be really poorly architected. 1) You start a .app that sits for a few seconds then requires you to launch the browser by clicking a button. While using the browser, you can't close the extra window for the controller. 2) On the browser, you go to a localhost website that has an invalid TLS certificate (you can a "Not Secure" warning) and have to click through to the uns…

But you can replace the certificate if you want to. But many users won't have a static IP address they can use to point to their controller, and many don't even own a domain, which means the self-signed certificate is the only option.

Re: Ubiquiti Networks Breach

#392
post #360

Earlier quoted context omitted.

Not only have they engaged in multiple interface redesigns with loss of features with no apparent gains, the last firmware update removed the ability for me to use the Protect app locally on my network without needing cloud access enabled. This breach has only confirmed my belief that my home cameras must stay off their cloud. Extremely dissatisfied.

>engaged in multiple interface redesigns with loss of features with no apparent gains Yeah, this has been really baffling. Their settings UI has been in a transition state between "Classic Settings" and "New Settings" for years . Neither is complete. Some settings are only in New Settings (e.g. WiFi AI), while many more are only in the Classic Settings (e.g. allow multicast from Ethernet to WiFi).

Their EdgeSwitch line has this same issue - legacy and new UI each with different functionality, and even less capability within UNMS (Now named UISP?). Frustrating.

Re: Ubiquiti Networks Breach

#393
post #331

Earlier quoted context omitted.

Can’t you still access a Unifi video server locally? What’s so hard about setting up a reverse proxy or VPN?

You can't do that anymore. You either have to buy their server or use their cloud, from my understanding. I am another considering migration away from them for this reason as well.

You can still use their UniFi Video NVR in local-only mode, though I think the last update for that ha shipped. The Protect platform may be different in this regard.

One of the great things about ubnt was the ability to self-host their management software on a Ubuntu VM or container.

Re: Ubiquiti Networks Breach

#394
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

> That phenomenon is called counter-signaling, which I first ran into listening to Dan Jurafsky making the point that if a menu uses the word "fresh", its a low-brow restaurant. A high-brow restaurant would never use the word "fresh" -- the freshness is implicit in the other signals. https://kelley.iu.edu/riharbau/cs-randfinal.pdf source: https://news.ycombinator.com/item?id=25713050

That’s cool, I read his book, The Language of Food, and think about these things all the time when reading menus now; and then like an annoying pedant, nudge my wife and point it all out.

Re: Ubiquiti Networks Breach

#395
post #22

No specific comments to the breach... But, I couldn't help but chuckle at We Take Your Security Seriously™. Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"

I'm sure it's also the case that your call is important to them. Isn't that what companies always say while making you wait on hold for 45 minutes?

Along with the stock, “due to COVID-19, our service sucks right now”.

Re: Ubiquiti Networks Breach

#396

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

I bought a UDM Pro so I could run Unifi Protect. I got three cameras deep and their SSO went down the other day. It was impossible to access from my phone, as their app only supports SSO login. WHAT? I bought this stuff so I could self-host and _not_ rely on other services. I guess I didn't do enough research when investing in new hardware. I didn't see anything in their spec. sheets or descriptions about needing clo…

You can allow local only logins, I believe, but it might be opt-in.

Re: Ubiquiti Networks Breach

#397

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

I’m not sure how it is that they still don’t have a hardware update to the USG3P that can enable both IPS and DPI without throttling network speeds to sub-80Mbps speeds. It’s been years now. I’m a big fan of the ecosystem and I’ve recommended it to many people but I’m constantly astonished by the slow pace of hardware updates.

UXG-Pro is the successor to the USG. It’s available in the EA store. I was tempted to get it but it’s $500 so I’ll wait for it to go GA.

Re: Ubiquiti Networks Breach

#398

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

Any idea what it would cost to develop a completely open source router?

Any running Linux kernel is a router. You just have to know how to configure it. Of course, you might be expecting a lot more than just a router, ie. DHCP, DNS, traffic shaping etc. It's all available in most distros.

Re: Ubiquiti Networks Breach

#399
post #383

Earlier quoted context omitted.

Give AVM and their Fritz!box products a go.

fritzboxes are everything but certainly no "prosumer"-type devices. Most of their "mesh" is still dual band. only the latest repeater "FRITZ!Repeater 3000" is tri-band and afaik there is no router yet available that supports tri-band.

Compared to ordinary consumer products, I'll keep listing them as prosumer. They aren't mikrotik, or barebones openwrt, rather like dd-wrt.

The hardware is indeed a bit lagging, I'm not arguing there, but it's not always (only) the hardware that makes prosumer.

Re: Ubiquiti Networks Breach

#400
post #331

Earlier quoted context omitted.

Can’t you still access a Unifi video server locally? What’s so hard about setting up a reverse proxy or VPN?

You can't do that anymore. You either have to buy their server or use their cloud, from my understanding. I am another considering migration away from them for this reason as well.

> You can't do that anymore. You either have to buy their server or use their cloud, from my understanding. I am another considering migration away from them for this reason as well.

Alternatively, you can use their hardware with an alternative serf-hosted NVR like zoneminder.

The cameras work just fine in standalone mode as RTSP sources.

Post reply on HN