Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

431–440 of 486 posts

Re: Ubiquiti Networks Breach

#431

Earlier quoted context omitted.

I bought a Unifi Dream Machine last year because it was an all-in-one device that seemed like the simplest way to have multiple VLANs on my home network, in order to segregate my IoT devices and security system from the rest of my home network. At the time, I didn't see any similar products. Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doe…

Has UI gone downhill ? or is it just because of all the negative feedback ? Data leaks happen! It shouldn't but that's just how the world is. UI has been honest about it, and informed every customer as a precaution. (I assume they're still investigating). I can't be sure, but since UniFi Video went offline at the same time the breach was announced, a week earlier than it was scheduled to, that might have been the ent…

I built up my companies network infrastructure on unifi gear the past two years. I did so because we don't have budget for a professional network engineer, but we do have some important network requirements that I needed to be able to set up with minimal learning curve. For the most part this turned out great, there's a powerful UI that lets you configure all of the basics. And lets you inspect everything without having to relearn a bunch of tools and concepts everytime. I'd say perfect for a situation where the CTO has to 'solve' the network.

What disappointed me is that some aspects are really unfinished, and it looks like there's no intention of it to be fixed.

For example we bought their pro firewall (which has been out for years), it's got 2 WAN ports for automatic fail over. To use the 2nd WAN port I had to switch over the UI back to legacy mode. Ok weird but I guess the new UI is still sort of new. But then it turned out that to configure automatic fail over in the most common way, I needed to ssh in and edit configuration files manually.

It didn't turn out to be very hard, but it was just jarring. One of their flagship products, and of the 4 ports it has, 1 port is not supported in their main UI and it's most common use is not possible even in their legacy UI.

Unifi Protect has similar incompleteness issues.

I don't think there's a company that does it better than Ubiquity right now, just disappointed that it stops there.

Re: Ubiquiti Networks Breach

#432

Earlier quoted context omitted.

Mikrotik? Easier? Do not get me wrong, I love Mikrotik, but easier would not the word I would be using. This image ( https://www.reddit.com/r/mikrotik/comments/jyjgnc/mikrotik_v... ) sums it up neatly. Also, Mikrotik is not directly comparable, you cannot replace Unifi Controller with Capsman.

Only thing disappoints me about Mikrotik is the wireless performance of their routers, which seems to that is more about the RouterOS then the hardware itself. You can never know if the next update will improve or worsen WiFi perf. Otherwise they have really good products.

It is both. Hardware-wise, many Mikrotik products are shipping with just 2x2 radio. Software-wise, even where hardware supports it, RouterOS doesn't support MU-MIMO and beam-forming (there is some preliminary support in the ROS7 beta, for selected chips). There are also some weird bugs, like when you have a client with Intel WiFi and it is unable to connect to VHT80 band... but all the other clients do not have such problem.

So in the end, for APs, I'm using Unifi.

Re: Ubiquiti Networks Breach

#433
post #431

Earlier quoted context omitted.

Has UI gone downhill ? or is it just because of all the negative feedback ? Data leaks happen! It shouldn't but that's just how the world is. UI has been honest about it, and informed every customer as a precaution. (I assume they're still investigating). I can't be sure, but since UniFi Video went offline at the same time the breach was announced, a week earlier than it was scheduled to, that might have been the ent…

I built up my companies network infrastructure on unifi gear the past two years. I did so because we don't have budget for a professional network engineer, but we do have some important network requirements that I needed to be able to set up with minimal learning curve. For the most part this turned out great, there's a powerful UI that lets you configure all of the basics. And lets you inspect everything without hav…

I agree there's a lot of unused potential with their existing product line, but as you said, nobody does it better currently.

I've been running Ubiquiti gear for years, from a single 2.4GHz UAP with the Edgerouter products, to my current setup with UDM Pro, 10 GB backbone and multiple NanoHD access points, and to use an Apple quote, "It just works". I don't have a complicated setup, just some basic VLANs, firewall rules, radius assigned VLANs via MAC, and IDS/IPS, so maybe that's why i'm not having any issues with it.

I have the technical skill to set it up from scratch if i wanted a second day job, but i don't anymore. I've run on homebuilt devices, on a Soekris net4801, on an Alix APU1D4, on m0n0wall and PfSense in various configurations, latest on a Netgate SG-3100, and while the SG-3100 comes very close to being a network appliance, it still managed to crash to a point where i was flashing it and setting it up over a USB cable, and while Netgate support was very helpfull, that's hardly something you'd ask the average consumer to do.

On the access point side of things the only real contender would be Meraki, but those are 2-3 times the cost of UniFi gear. You could of course also get a bunch of Zyxel/Netgear/whatever consumer devices and put them in bridge mode, and lose all central management.

Re: Ubiquiti Networks Breach

#434
post #314

Earlier quoted context omitted.

OpenWRT supports that.

Though you'll probably end up with Atheros wifi chipset on modern hardware... and I've found the OpenWRT drivers to be extremely unreliable when providing multiple SSIDs--- crashing every few days instead of weeks of uptime. I keep hoping that one of the OpenWRT snapshots will fix it, but this is something I've been fighting with for years on multiple pieces of hardware.

i have had different hardware running openwrt and never experienced problems regarding to multiple ssids...

maybe you have a known-bad hardware in regards to driver support, but that is absolutely not to be expected.

Re: Ubiquiti Networks Breach

#435
post #301

Earlier quoted context omitted.

Look at Ruckus

would be good to see more argument behind this?

as the name implies, that company made a ruckus in the prosumer segment like ubiquiti but since bought by Arris is declining same same (like you only get FW updates with registration).

Re: Ubiquiti Networks Breach

#436

As a former Ubiquiti employee, I'm sad to watch the slow decline of the company. There was a steady exodus of engineering talent through 2020. The CEO was focused on moving to countries where engineering was cheaper and employees complained less about constant crunch mode. If you search around, you can find interviews where he brags about closing the San Jose office because he thought everyone there was too entitled.…

Any idea what it would cost to develop a completely open source router?

Buy a small PC with lots of network ports and install VyOs [1] on it. If I recall correctly, Ubiquiti's EdgeOS is based on VyOs.

1. https://vyos.io/

Re: Ubiquiti Networks Breach

#437
post #40

I must admit - Ubiquiti has lost some of it's shine in the last few years, whilst AP and routing hardware seems to still be very good in terms of pricepoint, it does feel like the software side of things has been going in a very strange direction for quite some time. I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote…

For now, I’ve resorted to extracting the rootfs of the cloud key plus firmware images, and running UniFi protect in a LXD container on a raspberry pi. I’ve not tried this with their cloud access, and could not get the app to work with it yet. I’d like to do a writeup at some point, but not sure if I could get in legal trouble...

Re: Ubiquiti Networks Breach

#438
post #406

Earlier quoted context omitted.

> Living costs don't necessarily correlate with talent levels. As someone who lives in a low cost country: rubbish. There's a reason we're a lower cost. 1. We have a lower standard of education 2. We have a higher cost of technology (relative to average income) 3. We have a lower need for the luxury market where most technology resides You can also look at the proportion of field leaders. Are more from the developed…

> You can also look at the proportion of field leaders. Are more from the developed nations or the developing ones? Lower cost of living does not imply developing nation. Czhech Republic or Poland or Taiwan are developed nations, all with the cost of living a fraction of Bay Area. I see Ubiquiti dev center apparently moved to Latvia. You can argue it's a depressed region of the EU but it is not a developing country b…

Latvia? That's home to Mikrotik, this sounds quite dodgy. Prolly it was a move aimed at draining some talent from them.

Re: Ubiquiti Networks Breach

#439

PSA: with Mailchimp URLs, it's best to remove the `?e=xxx` URL parameter. That way, A) you can't be identified by the sender as the person who shared the email, and B) other people can't flood your inbox by clicking the "unsubscribe" link at the bottom of the email. In this case, the cleaned URL that should have been posted is https://mailchi.mp/ubnt/account-notification

Good call! This just keeps getting better, sharing the URL is such a natural thing to do but of course they need to add the tracking parameters to everything.

The ClearUrls Firefox extension often prevents this...: https://gitlab.com/KevinRoebert/ClearUrls

Re: Ubiquiti Networks Breach

#440
post #396

Earlier quoted context omitted.

I bought a UDM Pro so I could run Unifi Protect. I got three cameras deep and their SSO went down the other day. It was impossible to access from my phone, as their app only supports SSO login. WHAT? I bought this stuff so I could self-host and _not_ rely on other services. I guess I didn't do enough research when investing in new hardware. I didn't see anything in their spec. sheets or descriptions about needing clo…

You can allow local only logins, I believe, but it might be opt-in.

The protect app will now only work with cloud enabled. Previously you could sign in, then disable cloud, and your session would remain active. It doesn't work at all now with cloud access disabled.
Post reply on HN