Live data from Hacker News

Ubiquiti Networks Breach

mailchi.mp

91–100 of 486 posts

Re: Ubiquiti Networks Breach

#91
post #25

Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…

I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…

Do you know how ubiquiti's "edge" line compares to mikrotik?

Re: Ubiquiti Networks Breach

#92

Ubiquiti has typically been the "cloudless" provider which is why I've used their stuff. They've been sorta moving in a disturbing direction for cloud control. I don't want that risk.

Cloudless if and only if you run their gigantic bloated Java network management tool. I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.

I've been running the Unifi controller on a Raspberry Pi 2 for four or five years now with no problems that I can recall.

After the initial installation and configuration was done, I've probably only logged into it a handful of times.

(With the exception of their APs and said controller, I avoid Ubiquiti as much as possible, though.)

Re: Ubiquiti Networks Breach

#93

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

If you include a cloud key in the network there’s no need to connect to the ubiquity cloud. The cloud key runs an entirely local ubiquity management stack.

Ah, so my plan to buy a Dream Machine Pro would effectively mitigate this.

Re: Ubiquiti Networks Breach

#94

Ubiquiti had a data breach, but what could hackers possibly want to know which we didn't know already? All their customers are overpaid engineers who got sucked into dumb influencer marketing convincing them to buy overpriced industrial grade networking kit for their 50m2 flat.

While I would choose a less abrasive way of stating it, I agree with your underlying assessment. At the recommendation of basically every networking forum and subreddit, I bought some Ubiquiti stuff to power networking and wifi for a new place I recently moved into. It cost 3x what a mid to high-end Linksys would have cost, and as far as I can tell provides literally negative benefit for my purpose: Specifically, rat…

I'm sure their fancier equipment is probably a nightmare of a time sink but the little kits you can buy are dead simple for nontechnical people to set up and use. My parents have plaster walls and the modem lives in the basement so they have huge problems with coverage even though their house isn't very big. This is sort of silly but they connection speed gage on their router is super helpful because they get confused with things like checking internet speed.

Re: Ubiquiti Networks Breach

#95

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

You can disable remote login in the settings. It's the first thing I did when I got mine. So it's impossible to login to my router using my Ubiquiti account.

Can't comment on issues have been getting, but I only have good things to say about mine. It's not perfect and the learning curve can be steep, but it's miles ahead of any other routers I've used before. The only thing that came close was when I flashed dd-wrt on my old Linksys.

Re: Ubiquiti Networks Breach

#96
post #18

Ubiquiti is slowly becoming Sonos. The difference is, their potential for bad behavior, risks and attack surface is far, far greater.

Yes, that is worrying. I never hooked my USG up to the cloud, opting to run it from a local docker container.

Re: Ubiquiti Networks Breach

#97
post #45

Earlier quoted context omitted.

It's impossible to secure yourself against a devoted persistent threat group over the long term. The asymmetry of effort is not tractable to overcome. So they can take your security seriously, but they will be hacked, or they have already.

I think it is possible to secure yourself against a devoted, persistent threat group. I think it's expensive, but possible. Do you have data to back up your claim that no one, ever has ever successfully remained secure?

What evidence do you have that anyone has?

Re: Ubiquiti Networks Breach

#98

I did a double take after clicking through- when did Unifi change their URL to UI.com? I thought this was a clever scaled phishing attempt for a second. Come to think of it, how many times have they changed their URL/how many are there? feels like im being trained to do something stupid.

It's been that for as long as I can remember, but that's only a year or two.

Re: Ubiquiti Networks Breach

#99

As someone who was planning on buying Ubiquiti hardware for their house, this breach and a lot of the comments here are disconcerting. Are there any other alternatives that are more locally managed that people would recommend?

I use a fair amount of their equipment at home and I don't think that you need to be concerned with this. I run my controller on a server in my basement, and no part of it (besides the WAN port on my ERL) touch the internet. There is no "cloud" requirement.

The "dream machine" thing I don't get. I do like their Unifi AP line, though.

Re: Ubiquiti Networks Breach

#100
This is why cloud login for network devices is terrible. I use an EdgeRouter at home with no cloud connection and I'm quite happy with it, but I've used UniFi in another setting, and I am not thrilled at the ease of getting internal passwords and the like set on devices from any web browser, for instance.

Another company's network products I work with technically has a self-hosted version of their management service, but it doesn't scale down well (it expects dozens of GBs of RAM and to be running on SSD storage or it's not supported). I've regularly felt pressured to move to the cloud just to avoid the jankiness.

Post reply on HN