[HN Gopher] Ubiquiti all but confirms breach response iniquity
       ___________________________________________________________________
        
       Ubiquiti all but confirms breach response iniquity
        
       Author : parsecs
       Score  : 584 points
       Date   : 2021-04-04 19:28 UTC (1 days ago)
        
 (HTM) web link (krebsonsecurity.com)
 (TXT) w3m dump (krebsonsecurity.com)
        
       | jimnotgym wrote:
       | Hang on a minute there
       | 
       | > Ubiquiti's IoT gear includes things like WiFi routers
       | 
       | I understood IoT to mean wifi toasters, TVs and other home
       | appliances. Since when was a _router_ an IoT device? Are we going
       | to call all nework devices IoT now. This strikes me as taking
       | rather too much journalistic license.
       | 
       | In fact wtf is a _WiFi Router_. I use Unifi to deploy Wireless
       | Acess Points on a LAN with centralized control. It is possible to
       | do this without them having internet access at all, but it makes
       | it rather harder to update everything. This is miles away from
       | IoT.
       | 
       | Describing Ubiquity as a IoT company is like calling Cisco,
       | Juniper, Mikrotik and Aruba IoT companies. This sounds like an
       | attempt to feed the narrative that the IoT is going to eat us
       | alive.
       | 
       | Let us focus instead on what Ubiquity actually did wrong, isn't
       | that bad enough?
        
       | rosege wrote:
       | Opened HN to look to see what everyone was saying about the FB
       | hack, stayed for the Ubiquiti one.
        
       | bcrescimanno wrote:
       | It's disappointing to see a breach like this and even more
       | disappointing to see what (at least on the surface) appears to be
       | a lackadaisical response.
       | 
       | At someone who runs a UniFi network in my home with just 4 pieces
       | of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really
       | curious if there are solid alternatives for a managed home
       | network. UniFi really hit a sweet spot of price/performance that
       | made it a somewhat pricey; but, not totally unreasonable option
       | for the home.
       | 
       | Any suggestions from the HN crowd?
        
         | e40 wrote:
         | That is my exact configuration, too. Would love to have
         | alternatives.
        
           | heavymark wrote:
           | I'm not aware of any alternatives that are designed as well,
           | and if you switch the new option could just as easily be
           | hacked or if so it on it could also be hacked but you may
           | never realize. Though it's good for all these people to
           | pretend to threaten to leave since maybe that will get the
           | company to be a little more forth right which is all we can
           | really ask for these days.
        
         | ThatPlayer wrote:
         | I've heard good things about TP-Link's Omada series. Their
         | controller even looks like a clone of Unifi's
        
           | msbarnett wrote:
           | Last time I looked into this (admittedly several years ago),
           | TP-Link had a really poor reputation for not patching known
           | security issues in their firmware.
           | 
           | Not sure how much I'd trust their products unless they've
           | really done a 180 in terms of security in the last year or
           | two.
        
           | lostlogin wrote:
           | Having messed with TP-Links smart plugs, I've been really
           | impressed. They integrate well into Home Assistant too.
        
           | ed25519FUUU wrote:
           | Isn't TP-link a Chinese company?
        
             | catblast01 wrote:
             | Is ubiquiti a Chinese company?
             | 
             | Really, what a low effort idiotic post.
        
               | clajiness wrote:
               | We can assume what they were implying, but it seems like
               | a legitimate question.
               | 
               | Also, Ubiquiti is an American company, right?
        
               | hayst4ck wrote:
               | It's pretty hard to deny that Chinese US relations are
               | heating up. Supporting your own supply chain is becoming
               | a matter of national security, both in terms of potential
               | attacks (what if they load state software on Chinese
               | devices, especially as a response to military action),
               | and in terms of supporting your own industry.
        
               | TheRealDunkirk wrote:
               | 30 years ago, my, then-Representative, Mike Pence was
               | going around supporting tariffs on Chinese steel. I
               | thought tariffs were a Bad Idea, prima facie. Pence
               | explained that if we allowed China to decimate our steel
               | industry, we wouldn't be able to make tanks,
               | domestically. Cogito ergo sum, it was a _literal_
               | national defense issue.
               | 
               | I don't know where the steel issue stands any more, but
               | we've already been at war with China over intellectual
               | property for 20 years. It would make a great deal of
               | sense to subsidize domestic silicon fabs and computer
               | hardware manufacturing, and tariff foreign versions, for
               | the same reason.
               | 
               | It's no secret why Facebook is not allowed in China. They
               | know exactly what it really does, and what its true value
               | is, and they're not willing to allow that leverage to the
               | US, and it's disturbing that their lack of reciprocity
               | doesn't seem to cause much concern.
               | 
               | It's kind of disgusting that we've outsourced so much of
               | our infrastructure to a country which, in another
               | generation, is going to become the world's most powerful.
               | China is playing the long game. We're willingly giving up
               | our lead because we've built our post-70's society on the
               | almighty stock option, and our myopic focus on only the
               | next quarter.
        
               | catblast01 wrote:
               | I don't deny any of that. But where is most of the
               | hardware for just about any network and computing
               | equipment manufactured? Questioning if tplink is made in
               | China is pretty low effort and pointless.
               | 
               | A thoughtful analysis would ask why an onshore supplier
               | would fundamentally be any less vulnerable to political
               | adversaries.
        
               | sngz wrote:
               | being made in china and being a Chinese company are very
               | different things and the risks are different.
        
               | 0xy wrote:
               | Much like Cisco being exposed to US supply chains leaves
               | them vulnerable to tampering by US intelligence through
               | physical interception, merely being made in China is a
               | security risk.
        
         | someonehere wrote:
         | I dumped their gateway/security appliance in favor of Opnsense
         | box. Never looked back or regretted it. Their security
         | appliance is not as granular as I would want and the Opnsense
         | was a learning opportunity for me.
        
         | monkey34 wrote:
         | While I've not yet made the purchase, I'm eyeing a Synology
         | RT2600ac (https://www.synology.com/en-us/products/RT2600ac) and
         | an MR2200ac (https://www.synology.com/en-
         | us/products/MR2200ac#specs). It seems like they'll be adding
         | VLAN support in their 1.3 release
         | (https://community.synology.com/enu/forum/2/post/130414), which
         | should be nice for adding dedicated VPN and guest networks.
         | 
         | For me it's one of the few options available because my ISP
         | forces me to use a transitional IPv6 technology called "MAP-E,"
         | which the UniFi products don't support. I switched ISPs after
         | purchasing my equipment and ended up with $700 of dead weight.
        
           | ImprovedSilence wrote:
           | I recently went with two 2200acs. Been mostly pleased, but
           | there were some settings i had to play with to get the right
           | router to use some of the more distant devices.. without
           | custom settings it trys to load balance devices over choosing
           | based on signal strength, thus a far device from the main
           | router had an unusable connection..
        
           | tw04 wrote:
           | I've deployed several syno routers and extenders and have had
           | 0 calls for support, they seem to just work.
           | 
           | The lack of mounting options and Poe power are obviously a
           | downside for a lot of implementations but overall they appear
           | to be solid.
        
           | miles wrote:
           | https://www.amazon.com/gp/customer-reviews/R3GCUBZSITZCYS/
        
             | xyst wrote:
             | I can at least verify a portion of the second claim of this
             | reviewer's post. A section of the EULA does dictate that
             | Synology grants itself the right to conduct an audit to
             | protect their intellectual property.
             | 
             | "Section 7. Audit.Synology will have the right to audit
             | your compliance with the terms of this EULA. You agree to
             | grant Synology a right to access to your facilities,
             | equipment, books, records and documents and to otherwise
             | reasonably cooperate with Synology in order to facilitate
             | any such audit by Synology or its agent authorized by
             | Synology."
             | 
             | https://www.synology.com/en-us/company/legal/terms_EULA
             | 
             | I can't verify the claims about "Peoples' Republic of China
             | PRC" being allowed to enter a non-Chinese citizen's home
             | (US citizen) to protect IP. Might be applicable to Taiwan
             | or Chinese citizens.
             | 
             | I am not a lawyer so I cant determine whether this EULA is
             | enforceable in the US or EU. Regardless of enforceability,
             | I would be hesitant to buy Synology products as well. Who
             | knows what backdoors they have implemented in order to
             | satisfy the Chinese government.
        
               | tw04 wrote:
               | Given synology is owned and operated out of Taiwan, it's
               | rather silly to make claims about the prc.
               | 
               | As far as I know that clause was created years ago when
               | people were using key generators to make keys for
               | surveillance station licenses. I don't know of anyone who
               | has ever actually been audited.
        
               | broknbottle wrote:
               | Microsoft can and does the same thing for Windows
               | licensing compliance..
        
               | miles wrote:
               | I'm only aware of similar terms in their volume license
               | agreements. Do you have a pointer to such terms in their
               | standard, off-the-shelf Windows versions? Cannot find
               | anything here: https://www.microsoft.com/en-
               | us/Useterms/Retail/Windows/10/U...
        
             | ImprovedSilence wrote:
             | Fwiw, i have 2 synology routers, and did not have to create
             | a cloud account or use the cloud to setup. Its there, and
             | an option, and you can get other plugins if u have the
             | cloud account, but by no means is it required for setup or
             | use.
        
           | qsi wrote:
           | Thank you for that link, I had not realized Synology had
           | moved into the router space, and I've been running Synology
           | NASes for almost a decade! Generally I've been happy with
           | them, and on the few occasions I need tech support, it was
           | surprisingly good (going on with zero expectations based on
           | other companies' support in the past).
        
         | kyrra wrote:
         | Unifi's router isn't all that great. I would go with other
         | software (like opnsense), which is the recommendation of some
         | others out there.
         | 
         | Their switches and APs are still really good. For alternatives,
         | it depends on your goals. How many configuration options do you
         | need? Is cloud management bad? Any more.
         | 
         | For consumer: Google, Eero, Orbi and some of the others are
         | good. If you want more control, you need to venture into the
         | SMB and Enterprise space.
         | 
         | Unifi, Engenius, Aruba Instant On, Tp-link Omada, Mikrotik,
         | Ruckus and maybe some others. It really depends on your desired
         | feature set.
        
       | xyzzy21 wrote:
       | "The Cloud" absolutely can NOT be trusted with anything serious.
       | I'm still amazed serious people actually think it's a smart or
       | wise idea. It's become a "Go to the fridge and get the box" type
       | of mindless laziness by far too many marketers and developers.
        
         | Black101 wrote:
         | It's going to get much worst before it gets better.
        
       | lifeisstillgood wrote:
       | Off topic but is there a good guide to middle level home network
       | setup - something like using OpenWRT on (Rpis?) and turning that
       | into a router and couple of access points.
       | 
       | I was going to press buy on the setup for some ubiquiti products
       | till a couple of days ago :-(
        
       | imwillofficial wrote:
       | I used to be a die hard Ubiquiti fan. They have fallen from grace
       | in a big way. Disappointing.
        
       | arbitrage wrote:
       | So, what happens now? Will Ubiquiti be held to task, by anyone?
        
         | imwillofficial wrote:
         | They've lost my business.
        
           | kiwijamo wrote:
           | Ditto and they have also lost my recommendations. If I hear
           | any friends thinking of Ubiquiti, I will be pointing them
           | towards articles like the one we are discussing. I had been a
           | bit wary of then since their push for cloud SSO etc, but
           | these recent events have put the final nail in the coffin for
           | me. Personally I am migrating my family's network to MicroTik
           | gear.
        
             | lucb1e wrote:
             | A friend of my boss recommended Ubiquity semi-recently.
             | We're a small IT company, plenty of theoretical expertise
             | but no dedicated network admins, so it made sense to go on
             | a recommendation.
             | 
             | The fact that doing _anything_ , for example assigning a
             | VLAN to a switch port, requires you to first setup a
             | mongodb server on your machine before you can install the
             | controller software tipped me off to the quality of what we
             | had bought. The device also gets like 80degC while idle.
             | 
             | This controller software is now on isolated hardware, we
             | trust the thing about as much as an old Android phone, and
             | that was just from our impression as security people
             | without knowing of any breach.
             | 
             | I see it as a good thing that other friends of $friend will
             | be spared that recommendation after this news.
        
               | gerdesj wrote:
               | It's not a massive ask to install MongoDB.
               | 
               | Unifi stuff is quite cheap for what you get for a simple
               | reason: Each one does not need to run a webserver and all
               | that stuff. This means that the pretty stuff has to run
               | elsewhere. For a single site you can use a phone app and
               | for multi site setups and MSPs you have the controllers.
               | 
               | The controller can be run on a Windows PC with a next
               | next install or a Linux box with pretty minimal setup
               | requirements.
               | 
               | It sounds like you might want to go the app route
               | otherwise if you are an IT company (I own a 20 person one
               | - so also small) then find the one screen doc with around
               | 10 copy and paste instructions once you have say a small
               | Debian or Ubuntu minimal installed. You could also run up
               | a Win10 VM and install the Windows distro quite easily.
        
               | amluto wrote:
               | Whatever one may thing of the quality of MongoDB, they
               | are asking you to install a defunct version.
        
               | kiwijamo wrote:
               | And it only works with MongoDB shipped with older
               | versions of Debian. The current Debian doesn't even have
               | the most current version of MongoDB (due to Debian policy
               | of backporting security fixes only) but even that is too
               | new! In the future it would not surprise me the least to
               | find that the only way to use the Unifi controller will
               | be by using a non-supported distro.
        
               | imwillofficial wrote:
               | Meraki has captured my fancy lately. Expensive but a
               | pretty great value prop.
        
               | lucb1e wrote:
               | Frankly, all we needed was a switch where you can add
               | VLAN tags and send them to a trunk port. And I suppose a
               | password on the "I would like this VLAN on this port,
               | please" interface is also necessary, but I think that
               | already concludes the grand list of requirements.
               | Everything else we control on the router.
               | 
               | It doesn't have to be network equipment in the
               | traditional sense: any old linux server will do, it's
               | just that it needs to have a couple dozen network ports.
               | Traffic can be limited to a gigabit per second between
               | all the ports combined (no need for multi-gigabit
               | backplanes or switch fabrics or what the correct term for
               | that is). I'd almost buy a big USB hub and connect USB-
               | Ethernet adapters, but that feels more hacky than core
               | infrastructure is supposed to be.
        
               | posguy wrote:
               | I support two Meraki MX64 routers, they are definitely
               | expensive and have repeatedly caused issues for my
               | clients when their ISPs force an upgrade of the
               | associated modem. Not sure what shenanigans Cisco has
               | done with Meraki, but I have wasted hours with them on
               | the phone trying to get these MX64's to DHCP from a new
               | cable modem.
               | 
               | Ended up swapping in an Archer C7 on OpenWRT with a LTE
               | modem to ensure business continuity for the client while
               | working with Meraki's abysmal support to get their router
               | to work correctly.
        
               | lostlogin wrote:
               | > The device also gets like 80degC while idle.
               | 
               | This sounds like a 8 port poe switch. They get hot.
               | However they also don't seem to mind it.
        
               | lucb1e wrote:
               | I'm not worried for the switch, I'm wondering about the
               | useless power draw of the gazillion switches they sold.
               | An idle switch should be barely above environmental
               | temperature, not produce gaming PC levels of heat.
               | 
               | It's not PoE and more than 8 ports.
        
           | karlshea wrote:
           | I was pretty sure I'd never buy any more hardware from them
           | after the UniFi 6.x releases, but after this I'm totally
           | sure.
        
           | unstatusthequo wrote:
           | Plaintiff lawyers will come into effect if there were actual
           | damages as a result of this. Has anyone heard of actual
           | breaches of their own networks as a result? If not, probably
           | no actual damages = class action plaintiffs don't care
           | because no $ for them. Of course this is generalizing but
           | this is usually the calculus. I know this because I am a
           | cyber attorney.
        
             | ejb999 wrote:
             | even without actual damages, there will be a securities
             | class-action lawsuit for anyone that lost money on the
             | stock.; and as usual lawyers will collect big payouts, and
             | shareholders will get a few dollars if they are lucky.
        
               | harry8 wrote:
               | Get a few dollars from who? The owners of the company
               | will have to pay themselves because they messed up? What
               | a great reason to pay lawyers and clog up courts at
               | taxpayers' expense.
        
         | LgWoodenBadger wrote:
         | I'm done buying ubiquiti equipment. 6 devices, and 3 family
         | members I recommended ubiquiti to who also have multiple
         | devices.
         | 
         | Clearly the market exists for what they're offering. I am
         | surprised at the serious lack of alternatives.
        
           | commandar wrote:
           | HPE seems to be aiming squarely at Ubiquiti with their Aruba
           | Instant On line (which is distinct from the Aruba Instant
           | line because what's life without some confusing branding?). I
           | installed some of their APs and switches in my home a few
           | weeks ago and it's working well. It ended up a little less
           | expensive than comparable UBNT gear would have been and
           | there's actual availability on their Wifi6 APs.
           | 
           | The APs are cloud managed only, but, personally, I trust HPE
           | not to make a complete clown show of things the way UBNT has.
           | But that's absolutely going to be a deal-breaker for a lot of
           | people ( _especially_ with the way UBNT 's now poisoned the
           | well to a degree).
           | 
           | The big hole in that lineup is a gateway device. They just
           | don't have anything comparable to the UDM (Pro). I'd be
           | surprised if they don't eventually introduce _something_ ,
           | though, given how the rest of the lineup seems pointed
           | directly at the niche Ubiquiti is currently occupying.
        
             | sigg3 wrote:
             | > The APs are cloud managed only, but, personally, I trust
             | HPE not to make a complete clown show
             | 
             | That is unwise on the long-term, though. The technology is
             | there so you don't have to trust anyone, so why do you
             | choose to trust them when they're not offering cloudfree
             | solutions?
        
               | commandar wrote:
               | Because it was the best available option in my price
               | range in all other aspects and I honestly don't care all
               | that much where the AP controller for my home network is
               | located. The APs will continue to work while offline and
               | I'm unlikely to even look at the controller interface
               | more than a handful of times a year provided the vendor
               | doesn't do anything that will outright break things. I
               | honestly don't care if it's hosted inside my network or
               | not.
               | 
               | Ubiquiti has a history of poor software releases that
               | break things and now of trying to gloss over a serious
               | security breach. I'm less worried about HPE in that
               | regard.
        
         | skybrian wrote:
         | As Matt Levine often reminds us, everything is securities
         | fraud. This looks like a good case for a class-action
         | shareholder lawsuit?
        
           | arbitrage wrote:
           | I am looking forward to my cheque in three years for $5.37.
        
       | gvkhna wrote:
       | I'm still on board with Uniquiti, tons of equipment and it
       | wouldn't make sense to switch everything over for small
       | operations. But this is extremely disappointing, they're
       | definitely moving in a little bit of a different direction then
       | where many of us would hope.
       | 
       | More shiny products that increase bottom line is great but many
       | IT officials rely on UniFi as well, I wonder how they're
       | responding to enterprise customers.
       | 
       | I just hope this incident will at least get them to put some
       | emphasis on security again as well.
        
         | ex_ubiquiti wrote:
         | > they're definitely moving in a little bit of a different
         | direction then where many of us would hope
         | 
         | it pains me to say this because I was there for the UniFi glory
         | days: The old Ubiquiti is dead and gone. Almost everyone I know
         | quit.
         | 
         | I hope they can land on their feet and return to the glory days
         | but I don't have much hope. The company got toxic fast at the
         | end
        
           | gvkhna wrote:
           | Based on username/comment, let me ask, what is next?
           | 
           | Because the platform integration and ease of administration,
           | no one else has and it's great for simple networks.
        
             | ex_ubiquiti wrote:
             | Several of us from the UniFi team went to competitors but
             | we're focused more on enterprise.
             | 
             | We always thought MikroTik was one of the biggest
             | competitors for low cost equipment. Our main advantage was
             | the UBNT community and having famous supporters like Troy
             | Hunt which MikroTik didn't have. The community fell apart
             | after the redesign killed it and I don't think people like
             | Troy Hunt will endorse Ubiquiti now so it should be
             | interesting to watch what comes next
        
         | neartheplain wrote:
         | >I'm still on board with Uniquiti
         | 
         | Freudian slip?
        
         | liaukovv wrote:
         | I wonder if you could extract costs of migration from ubiquity
         | with a lawsuit
        
           | madeofpalk wrote:
           | Sounds like a pain that's not worth it.
        
           | nomadiccoder wrote:
           | You shouldn't.
        
             | liaukovv wrote:
             | Why not?
        
       | teeray wrote:
       | What I'm curious about is, if I run my own controller on my own
       | hardware, do I need to be concerned about this? I could
       | understand supply chain concerns... I've held off updating
       | anything while this plays out. But all these "breach! breach!"
       | stories fail to spell out who is affected and what they need to
       | do.
        
         | ev1 wrote:
         | Force pushed updates overnight turned local controllers into
         | requiring ui.com single sign on, iirc.
        
         | Nextgrid wrote:
         | If the compromise is widespread enough then the attackers might
         | have gained control of the update infrastructure allowing them
         | to push out malicious firmware to your devices.
        
           | js2 wrote:
           | These blanket statements don't apply to everyone. It depends
           | which Ubiquiti hardware you own and how you've configured it.
           | 
           | For example, I run the UniFi controller on my FreeNAS server.
           | There are no forced updates to it. It doesn't update unless I
           | update it. The firmware on my APs doesn't update unless I
           | update them from my controller.
        
             | lucb1e wrote:
             | So it's a game of luck, depending on whether you updated
             | your firmware? I would call that "affected" rather than
             | "unaffected".
             | 
             | Just because not everyone installs security patches within
             | a few months after they come out (it says the breach had
             | been ongoing for two months) doesn't mean that therefore it
             | doesn't apply to everyone. In the strict sense, indeed not
             | everyone will have been compromised, but it totally applies
             | to you in the sense that through business as usual
             | (assuming that includes installing security updates), you
             | can be compromised.
        
             | ncphil wrote:
             | Agreed. My only gear is an EdgeRouter-4. Unlike the
             | Mikrotik it replaced you have go up, find the latest fw
             | file, download and install (that Mikrotik router wasn't
             | designed to handle 1 Gbps and at the time the next step up
             | cost more than the ER).
        
               | lucb1e wrote:
               | So unless it hits news channels major enough that you
               | hear about it or there is a bug that you isolate to be
               | due to outdated firmware, you probably won't ever patch
               | security issues in your _edge_ (outside-facing) router?
        
               | ncphil wrote:
               | I've got a recurring calendar item that prompts me to go
               | up and check for updates every week, and I do what it
               | says because after over 25 years in sysadmin I _know_
               | that the first time I ignore it I'm going to get stung.
               | With Mikrotik I originally had auto update turned on, but
               | later had a script that emailed me when an update was
               | available (so I could schedule a manual update a couple
               | of days later after checking the forums for anything
               | apocalyptic).
        
             | izacus wrote:
             | Unless you're manually verifying the content of your AP
             | firmware updates (which is a bit hard since they're
             | closedsource), I don't understand what you're trying to
             | say.
             | 
             | The firmware could be compromised at the source so your
             | FreeNAS doesn't help at all when you download and apply a
             | compromised firmware update.
             | 
             | Unless you're not updating your APs and keeping them
             | vulnerable in that way :)
        
               | js2 wrote:
               | I was addressing "attackers might have gained control of
               | the update infrastructure allowing them to push out
               | malicious firmware to your devices."
               | 
               | In my case, no, they cannot push anything to my devices.
               | Obviously, I could pull down compromised firmware. But
               | that's always a risk with software that I don't
               | personally verify, which is like 99.9% of software.
               | 
               | As a side note: obviously this security incident doesn't
               | give me a whole lot of confidence in how they run their
               | systems, but at no point has it been alleged that
               | Ubquiti's firmware updates have been tampered with.
        
               | amluto wrote:
               | Depending on your configuration, you can ssh in from the
               | UniFi cloud portal. If so, the cloud could easily ignore
               | your settings and push a persistent backdoor.
        
               | js2 wrote:
               | I do not have remote access enabled.
        
         | gerdesj wrote:
         | You probably don't need to be concerned(ish). I run a
         | controller for 32 "sites" across the UK with 1 to 13 APs per
         | site and a few switches. I keep it behind HAProxy but with
         | fairly minimal changes (from memory.)
         | 
         | I have stuck with controller 5.13.32 rather than moving to 6.x
         | just yet. It's an LTS version and I'm still waiting for the
         | whinging to stop on the forums. I also watch the AP firmware
         | and that has had some interesting times over the last few
         | months. I've confirmed dodgy AP versions on my sites and
         | backrevved and held accordingly.
         | 
         | I treat the whole thing the same way I do any other system. I
         | come out in spots when people mention clouds and IT in the same
         | sentence, so I have not knowingly enabled any cloudy
         | integrations from my controller to UBNT. Specifically, I have
         | not enabled "Remote Access".
        
         | izacus wrote:
         | If you read the original post, the they noticed a breach when
         | someone put an "unknown" VM on their server infrastructure. The
         | attackers also got signing keys for firmware.
         | 
         | So even if you run a local controller, I see two very serious
         | vectors:
         | 
         | 1. The "Ubiquiti account signin" functionality - you probably
         | had it off, but I'd like a confirmation that it doesn't keep a
         | backdoor open anyway.
         | 
         | 2. Having a malicious firmware update put on the servers. If it
         | took months for someone to find the vulnerability, who knows
         | how long the servers could push a compromised
         | controller/firmware builds for the hardware.
        
           | elric wrote:
           | The self-hosted controller UI uses your browser to fetch crap
           | from UI.com. Mine just launched a request to net-fe-static-
           | assets.network-controller.svc.ui.com/videos/empty, which I'm
           | sure is perfectly reasonable...I can think of a thousand
           | legit reasons why my network controller would need to load,
           | erhm, an empty video. _sigh_ I wish I could trust them.
        
       | Normal_gaussian wrote:
       | So ubiquiti can't be trusted. What are the suggestions for
       | running a ssries if home and small office networks in rented
       | buildings (no cabling?). A UDM + nano ap / flex HD as wireless
       | bridges & mesh wifi gave VLANS, performance monitoring, and an
       | ease of use that let even a junior UI dev implement use it easily
       | and correctlywhile complying with all lease req's.
       | 
       | With the world of work at home exploding there seems to be a big
       | missing link here.
       | 
       | I'm sitting with a big list of q's that I'm not sure I have a
       | decent amount of time to answer. Does switching to
       | pfsense/openwrt/something open source work with mesh? With ease
       | of set up? Do enterprise brands offer anything worthwhile here?
       | Do I have to regress to letting machines connect to unsecured
       | networks?
        
         | simple_phrases wrote:
         | OpenWRT does mesh networking and OpenWISP allow centralized
         | management of networking appliances. The latter is compatible
         | with the former.
        
       | efitz wrote:
       | You get great insight into the character of the leaders of a
       | company watching how breaches are handled. Companies that put the
       | customer first are transparent, and quickly take action (even if
       | painful to customers) to ensure that customers' data and systems
       | stay intact and confidential. Companies that try to gloss over,
       | hide or downplay things indicate that the leadership does not
       | respect their customers and is only interested in maximizing
       | profit/minimizing loss.
        
         | ex_ubiquiti wrote:
         | Most of the US leadership and many of the US employees quit in
         | recent years. The CEO wanted to focus on international offices
         | where employees were cheaper. It was backfiring while I was
         | there and I heard it only got worse after I left.
         | 
         | Sad situation. I knew a lot of good people there who cared
         | about making good products during the UniFi glory days.
         | Everything collapsed fast. I knew we were in trouble when the
         | CEO's early employee friends were disappearing and their
         | offices were being closed without warning.
        
           | phil21 wrote:
           | Really sad to see.
           | 
           | I still see no realistic alternative for the "distributed
           | decent wifi at a reasonably SMB scale" wireless product
           | though. Miraki I guess is as close as it gets, but then you
           | are locked in 100% cloud and it's certainly not remotely the
           | same price point.
           | 
           | I am relegating Unify to manage my APs and (some) switches
           | for ease of use - while I enjoy CLI fun, it gets old doing
           | routine stuff the for the 100th time.
           | 
           | Hopefully another company really steps up in this space,
           | because I can't imagine having to go back to the dark days of
           | individually managed APs and all that.
        
             | jefurii wrote:
             | OpenWISP has been mentioned elsewhere on this page.
        
             | msh wrote:
             | Meraki go is their direct unifi competitor.
        
               | youngtaff wrote:
               | Trouble is the firewall in the Meraki Go Gateway only
               | does 250Mbps - bit crap if you've got gigabit fibre to
               | the house
               | 
               | https://www.meraki-go.com/products/security-gateway/
        
         | dustinmoris wrote:
         | > You get great insight into the character of the leaders of a
         | company watching how breaches are handled.
         | 
         | No, that is too late. You get even sooner an even greater
         | insight into leaders of a company based on the things they
         | build. Does a hardware company try to force its users to move
         | things to a proprietary cloud for no clear benefit? You know
         | it's a company run by ar*eholes. Nothing more to know.
        
         | rossipedia wrote:
         | If I can vent for a second, this company _has no leadership_.
         | None. Things may have changed in 2 years, but I doubt it. I was
         | messaged almost daily by random employees asking wtf was going
         | on with the company. They were afraid for their jobs.
         | Practically no one respected the CEO, and he was the only
         | C-suite exec. There. Was. No. Leadership.
         | 
         | There was no company wide communication, and all communication
         | channels were made private, and if you sent an email to more
         | than a couple people you were directly rebuked by the CEO.
         | Nobody felt like they were trusted, and the norm was for most
         | engineers to have absolutely zero idea of what was happening in
         | the company outside of their direct project.
         | 
         | Teams were constantly at odds and pitted against each other,
         | and the CEO never resolved any conflicts between teams or
         | employees. The company (at least the software side) was treated
         | like Thunderdome. Some team leads and office managers took care
         | of their people, but most people were just beaten down. I don't
         | think I'd ever seen a less motivated, more dejected group of
         | software developers than I did during my time there.
         | 
         | IMO, this kind of bullshit clown show starts from the top. And
         | as long as the top doesn't want to fix it, it won't get fixed.
         | And since software almost invariable ends up reflecting the
         | structure of the organization that produced it, you get this
         | kind of security shit show.
         | 
         | I hope this is the last one and they get their act together.
         | But realistically I can't believe that'll happen.
        
           | ex_ubiquiti wrote:
           | > There was no company wide communication, and all
           | communication channels were made private
           | 
           | I couldn't understand why the ex-Amazon cloud lead was also
           | in charge of Slack. When he made all channels private and put
           | a Slackbot in every channel to monitor conversations, I knew
           | it was all over. I'm worried his Slackbot logs are part of
           | the leak. Guy had his hands in everything :(
           | 
           | Same guy who took over GitHub and forced everyone into his
           | self hosted source control because he couldn't trust Github.
           | That decision didn't pay off.
        
             | sngz wrote:
             | > Same guy who took over GitHub and forced everyone into
             | his self hosted source control because he couldn't trust
             | Github.
             | 
             | sounds smart to me. I wouldn't trust github either.
        
             | rossipedia wrote:
             | I mean, I didn't necessarily agree with all of his methods
             | or reasonings on everything, but I've come to realize a lot
             | of times his hands were just as tied as ours. And the
             | draconian surveillance stuff? Yeah, he was directed to do
             | that. One guess by whom.
             | 
             | He was "in charge" because he convinced Robert that he was
             | the right guy for the job by finding a security flaw that
             | let him log into Robert's personal UniFi Protect setup at
             | his home. At that point Robert basically gave him carte
             | blanche, but also started directing him to lock everything
             | down. More than a bit of paranoia there, in my opinion.
        
               | ex_ubiquiti wrote:
               | He was in charge of cloud when he "found" a way to forge
               | Ubiquiti SSO logins for any user using his root access to
               | the SSO signing secrets.
               | 
               | In the Krebs article the whistleblower calls out forging
               | SSO logins as one of the things that was compromised. If
               | the attacker is really an ex-employee like Ubiquiti says,
               | then it's scary that the SSO signing keys aren't even
               | being rotated after the account forgery stunt.
               | 
               | > Adam says the attacker(s) had access to privileged
               | credentials that were previously stored in the LastPass
               | account of a Ubiquiti IT employee, and gained root
               | administrator access to all Ubiquiti AWS accounts,
               | including all S3 data buckets, all application logs, all
               | databases, all user database credentials, and secrets
               | required to forge single sign-on (SSO) cookies.
        
             | lima wrote:
             | > I couldn't understand why the ex-Amazon cloud lead was
             | also in charge of Slack. When he made all channels private
             | and put a Slackbot in every channel to monitor
             | conversations, I knew it was all over. I'm worried his
             | Slackbot logs are part of the leak. Guy had his hands in
             | everything :(
             | 
             | He did.... _what_? That sounds like straight out of a
             | Dilbert comic.
        
           | cactus2093 wrote:
           | > I hope this is the last one and they get their act
           | together. But realistically I can't believe that'll happen.
           | 
           | The good thing about them being a public company is there is
           | some accountability from outside the company. Looks like
           | they're already being investigated for fraud for downplaying
           | the breach and their stock price took a big hit. Hopefully
           | this all leads to the CEO being replaced and things turning
           | around.
        
           | lostlogin wrote:
           | If you had the power, what you would do?
           | 
           | From the outside it seems like accepting fault and product
           | returns would smooth waters. Acknowledge faults on their own
           | forums and Reddit subs and also provide times lines for fixes
           | (then stick to them and update threads!)
           | 
           | The hardware is mostly good. The weird bugs and company
           | management are turning a strong community of users against
           | Ubiquiti.
        
       | GekkePrutser wrote:
       | Ubiquiti should _really_ stop making cloud logins mandatory. The
       | latest stuff (UDM /UDM Pro, Cloud Key G2) must be connected to
       | their cloud at installation time. Remote access can be turned off
       | but an admin account connected to their cloud remains.
       | 
       | Without those ties to their infrastructure, this breach would not
       | be as severe. It would just cause an attacker to see what I've
       | bought from them, nothing else.
       | 
       | I'm glad I can still use the unifi controller in docker without
       | any ties to UI.com however their later stuff like Unifi protect,
       | access, talk etc no longer works with that.
        
         | ex_ubiquiti wrote:
         | I worked there and I didn't even understand why we had to force
         | cloud logins on Dream Machine. In the early days we were all
         | about letting people run their own controller hardware and not
         | requiring cloud logins. No one could ever tell us why we had to
         | force everyone to the cloud. It was a mandate from above
        
           | GekkePrutser wrote:
           | Thanks for that insight!
           | 
           | I guess it's for the usual reasons. Telemetry / product
           | improvement, and also more marketing data. Data is the new
           | gold :)
        
       | xvector wrote:
       | Ubiquiti has lost my business. And with the recent issues with
       | Netgate/PfSense [1], it looks like OpnSense is the way to go.
       | 
       | [1]: https://arstechnica.com/gadgets/2021/03/buffer-overruns-
       | lice...
        
         | de6u99er wrote:
         | This reads like a horror story, but reminds me of a guy my boss
         | hired once against my objections.
        
           | tediousdemise wrote:
           | Indeed. Even more terrifying is using an unsafe language like
           | C rather than Rust or C++ for systems development. _shudders_
        
             | bogwog wrote:
             | C++? Safe??
        
               | tediousdemise wrote:
               | Smart pointers? Automatic memory management?
        
               | UncleMeat wrote:
               | They help a little. But there are so many more ways of
               | introducing vulns to C++ programs than just double frees
               | and use-after-free. Replacing all your pointers with
               | shared_ptr won't give you a safe program. Not even close.
        
         | jessebarton wrote:
         | why would you not just run OpenBSD with PF.
        
           | bpye wrote:
           | Why should I choose OpenBSD over FreeBSD or even Linux with
           | nftables?
        
             | dijit wrote:
             | If you're really asking, and not making a point;
             | 
             | PF is created and primarily maintained by OpenBSD
             | 
             | OpenBSD's base system (without extra packages) includes PF
             | and has a focus on security.
             | 
             | PF in freebsd is several major versions old.
             | 
             | nftables (like iptables before it) is rule based and not
             | bucket based. So high numbers of rules will not affect pf's
             | performance like it does with nftables.
             | 
             | But, for home users, probably not noticeable. Though I
             | prefer the syntax of PF personally.
        
               | ta20210405 wrote:
               | >nftables (like iptables before it) is rule based and not
               | bucket based.
               | 
               | What does this even mean? Do you have any documentation
               | to explain?
               | 
               | >So high numbers of rules will not affect pf's
               | performance like it does with nftables.
               | 
               | This is wrong. From OpenBSD documentation:
               | 
               | "More lines being evaluated for each packet will result
               | in slower performance."
               | 
               | [0]https://www.openbsd.org/faq/pf/perf.html
               | 
               | It's not 2001 any more. Nftables and Linux have left the
               | BSDs in the dust.
        
               | dijit wrote:
               | The key is "for each packet", because it's bucket based
               | it will entirely skip evaluation for packets that do not
               | match. This is due to how the rule set is compiled, but I
               | can see how it could be confusing if you're used to
               | iptables and only think in those terms.
               | 
               | I posted the architectural diagrams of both in another
               | comment on this thread yesterday, I think you missed
               | that.
        
               | ta20210405 wrote:
               | >The key is "for each packet", because it's bucket based
               | it will entirely skip evaluation for packets that do not
               | match.
               | 
               | That is how it works in nftables.
               | 
               | >but I can see how it could be confusing if you're used
               | to iptables and only think in those terms.
               | 
               | Considering you're misunderstanding some basics about
               | nftables and iptables here, I think you need to look in
               | the mirror.
               | 
               | >I posted the architectural diagrams of both in another
               | comment on this thread yesterday, I think you missed
               | that.
               | 
               | I saw, and it only reenforced the fact that that's how
               | nftables works. Hilariously enough, the OpenBSD webpage
               | crashed and wouldn't load, giving various 500 and 42X
               | errors.
        
               | hyperpl wrote:
               | Wireguard has also been stable on OpenBSD which helped me
               | with my throughput on my apu2d router hardware.
        
               | fuzzy2 wrote:
               | Could you expand on what you mean by "bucket based"?
               | Maybe the so-called "tables"? They sound pretty identical
               | to ipset on Linux.
        
               | dijit wrote:
               | Here's how a packet flows through netfilter[0], and
               | here's how it flows through pf[1].
               | 
               | [0]: https://upload.wikimedia.org/wikipedia/commons/3/37/
               | Netfilte...
               | 
               | [1]: http://mailing.openbsd.misc.narkive.com/jtIB9W3w/pf-
               | packet-f...
        
           | hyperpl wrote:
           | I switched from pfsense + Ubiquiti to OpenBSD + Ruckus and
           | couldn't be happier. While the web UIs were cool for a day,
           | with the command line I feel as though I understand exactly
           | what I have setup a bit better. Ruckus UI is also much more
           | friendly than Ubiquiti's - I had to actually install mongo db
           | + VM/dock just to configure my Ubiquiti WAP? Seriously?
           | 
           | I just wish I had completely deleted my Ubiquiti account when
           | I sold my WAP.
        
             | apple4ever wrote:
             | What Ruckus gear are you running? Last I looked it was
             | pretty expensive.
        
               | amluto wrote:
               | eBay. The secondary market for high-end network switches
               | is excellent if you're a buyer.
        
               | apple4ever wrote:
               | Ya I did some research and it's not bad at all. And
               | ruckus is pretty good with their firmware options.
               | 
               | In fact I'm buying two new R710s to replace my very old
               | UAC AP Pros. Was going to get the new AP 6 LR but after
               | UIs current woes (and them dropping support for my APs
               | way too early) I'm done with them.
        
               | wcfields wrote:
               | I ran into issues with firmware on a ZoneDirector 1200
               | and some R610's that were out of support contract.
               | Totally functional and all, but couldn't bring them
               | current.
               | 
               | Though, After using Ruckus in Corp/Enterprise they've
               | sold me on how capable their APs are, it's real deal high
               | density stuff.
        
             | ridiculous_fish wrote:
             | What hardware are you using?
        
           | posguy wrote:
           | Does OpenBSD with PF have a nice web interface to
           | administrate the firewall, DHCP server, WLANs, etc from?
        
       | lazyweb wrote:
       | Mentioned it before, but since a few days ago my unifi devices (2
       | wifi APs, a small switch, plus one Debian VM with the controller,
       | all on it's on VLAN) are not allowed to do outbound traffic
       | anymore, with the exception of NTP, DNS and one trusted apt
       | mirror.
       | 
       | Looking at the firewall logs it seems the devices try to ping
       | (ICMP type 8) a bunch of AWS IPs every few hours. The controller
       | tries to connect 80/443 on different AWS IPs a lot more often,
       | even without me navigating the web interface. Other than that, no
       | ill effects. Device firmware update notifications are gone, just
       | says "up to date" now.
       | 
       | Interestingly, I still see the ad for their "dream machine" on
       | the dashboard, as it seems to be baked into the controller. It's
       | also trying to load external resources from "net-fe-static-
       | assets.network-controller.svc.ui.com" while navigating the new
       | web interface. The "classic" interface still seems to be truly
       | self-contained. Using the latest controller version as of today
       | (6.1.71-15061-1).
       | 
       | Condensed firewall logs for reference below. Not that it matters
       | much, but why not.
       | 
       | Unifi controller VM:                 zgrep unifidrop
       | /var/log/syslog\* | grep "SRC=$unificontroller" | awk '{print
       | $12, $21}' | sort | uniq -c | sort -h            5
       | DST=13.224.246.17 DPT=443       5 DST=143.204.174.59 DPT=443
       | 5 DST=143.204.174.83 DPT=443       5 DST=34.210.116.187 DPT=80
       | 5 DST=34.211.38.191 DPT=80       5 DST=34.218.198.60 DPT=80
       | 5 DST=99.84.5.14 DPT=80       5 DST=99.84.5.24 DPT=80       5
       | DST=99.84.5.51 DPT=80       5 DST=99.84.5.82 DPT=80       7
       | DST=13.224.246.67 DPT=443       7 DST=13.225.74.11 DPT=443
       | 7 DST=13.227.220.19 DPT=443       7 DST=13.227.220.38 DPT=443
       | 15 DST=54.201.165.155 DPT=443       25 DST=44.239.243.150 DPT=443
       | 28 DST=44.238.226.202 DPT=443       28 DST=52.89.51.163 DPT=443
       | 28 DST=54.218.175.125 DPT=443
       | 
       | Unifi devices (all ICMP 8):                 zgrep unifidrop
       | /var/log/syslog\* | grep -v "SRC=$unificontroller" | awk '{print
       | $12}' | sort | uniq -c | sort -h            2 DST=13.224.230.94
       | 2 DST=143.204.9.24       4 DST=99.84.6.169       6
       | DST=52.84.94.172       6 DST=54.230.54.165       24
       | DST=52.222.138.169
        
         | philjohn wrote:
         | The ping is probably the uptime and connectivity monitor, which
         | can be disabled. It regularly sends a ping to ping.ubnt.com.
        
           | mnemnc wrote:
           | Or configured to a different (your own) endpoint
        
           | lazyweb wrote:
           | You're probably right, but blocking doesn't seem to be a
           | problem. I'm going to leave it like that for now. Not sure I
           | would need any more firmware updates for hardware which came
           | out 3-4 years ago anyway, but I think enabling
           | 13.224.195.59:443 for the devices only (not the controller)
           | would trigger and download firmware updates.
        
         | ex_ubiquiti wrote:
         | Is that going to the trace service?
         | 
         | There was a falling out between teams while I was there because
         | the cloud team wanted to collect stats from APs even when users
         | disabled analytics in the UI. It was so bad that some of the
         | developers and one of the leads quit because they didn't want
         | to be a part of it.
         | 
         | Someone on Reddit started reverse engineering it
         | https://www.reddit.com/r/Ubiquiti/comments/lwr4ud/update_ubi...
         | The APs are reporting things like connected clients and client
         | stats according to recent dumps. Do you have analytics disabled
         | in the UI and this is still happening?
        
           | lazyweb wrote:
           | Yep, analytics is disabled. Thanks for the link, didn't look
           | into the data being sent. But I can't confirm my devices
           | trying to send out data if I SSH into them (just tried it for
           | the 1st time).
        
         | electro_blah wrote:
         | LOL sounds like somebody installed a rogue device on your
         | network.
        
         | xyst wrote:
         | I have said this before, but would like to reiterate that I am
         | never touching or buying anything branded as Ubiquiti or owned
         | by Robert Pera.
         | 
         | This hardware is far from cheap and consumers are literally
         | paying for adware/spyware. I really hope Ubiquiti stock takes a
         | nosedive over the next year.
        
           | ahupp wrote:
           | How is it "adware/spyware"?
        
           | knowaveragejoe wrote:
           | Fwiw, Ubiquiti hardware is actually quite cheap.
        
             | Sebb767 wrote:
             | Depending on your viewpoint. Compared to an enterprise
             | setup with similar features? Basically free. Compared to
             | your average all-in-one home router, however, these are
             | _very_ expensive.
        
               | theshrike79 wrote:
               | > Compared to your average all-in-one home router,
               | however, these are very expensive.
               | 
               | Compared to your average all-in-one home router, however,
               | these are also markedly less shitty.
        
               | ncallaway wrote:
               | Right. Which feels like it meets the criteria of "far
               | from cheap" pretty well.
        
               | sliken wrote:
               | The nano with WIFI-6 is $99, the decent all-on-one
               | routers with wifi-6 I've seen are around $200.
        
               | [deleted]
        
           | hrrsn wrote:
           | Care to elaborate?
        
       | brian-armstrong wrote:
       | Has anyone looked at Ubiquiti's firmware signing? Would it be
       | possible to patch it to retain the drivers and kernel but replace
       | the configuration layers? Being able to homebrew some config
       | would make the equipment more valuable to us I think.
        
         | KirillPanov wrote:
         | Ubiquiti does not lock their bootloaders like phone
         | manufacturers do.
         | 
         | It is very, very easy to run vanilla Linux (or even OpenBSD) on
         | their hardware. I do exactly this:
         | 
         | https://news.ycombinator.com/item?id=26645062
         | 
         | Octeons (not Octeon-TX) are amazing processors. Ubiquiti makes
         | killer hardware. I hear their software is junk but wouldn't
         | really know since I always erase it immediately after unboxing.
        
           | simple_phrases wrote:
           | New equipment checks firmware signatures.
        
           | catblast01 wrote:
           | > An intel goldmont won't use much more power and can easily
           | do gigabit sqm and wireguard/IPSec without breaking a sweat.
           | Can any of these nearly 2 decade old MIPS/ARM designs come
           | close? I don't understand the hype for the hardware either.
        
           | jjeaff wrote:
           | Can you still take advantage of the hardware accelerated
           | features? Because I use a little er-x and if you turn on qos,
           | that disables the hardware acceleration and top speeds are
           | cut considerably.
        
           | rexfuzzle wrote:
           | AFAIK they've started locking them now, since about v5 if
           | memory serves. Got a couple gathering dust now because of
           | this.
        
           | bscphil wrote:
           | Do you run Debian on Ubiquiti's access points too?
        
         | gertrunde wrote:
         | People have been running OpenWRT on Ubiquiti gear for quite a
         | long time iirc.
         | 
         | [https://openwrt.org/toh/ubiquiti/start]
        
           | Hikikomori wrote:
           | Afaik performance will be abysmal on edge router series as
           | the npu isn't used.
        
             | KirillPanov wrote:
             | From firsthand experience: performance is in fact awesome
             | on the edgerouters (4, 6, 8, and 12) using plain-vanilla
             | Linux.
             | 
             | It's a big honking MIPS chip with firehose connections to
             | the ethernet PHYs. Precisely the kind of device you want
             | for a router.
        
               | joshspankit wrote:
               | Awesome at what level?
               | 
               | Are we talking DPI at 1Gbps symmetric?
        
               | Hikikomori wrote:
               | Then you are better off buying something with a beefier
               | cpu that costs less since it doesn't have an npu.
        
               | sigg3 wrote:
               | Please elaborate.
               | 
               | What are the thruput measurements on OpenWRT when
               | compared to ER-.. stock firmware, with hw accel or with
               | DPI..?
               | 
               | I have an ER-4 to be able to use the entire wan
               | connection, but on stock firmware I must disable DPI to
               | enable hw acceleration (otherwise the thruput floors). I
               | don't use DPI atm, so no big loss.
               | 
               | Can you utilize the hw accel in openWRT too?
        
           | adriancr wrote:
           | couldnt find dream machine support there unfortunately, shame
           | since I have one gathering dust now
        
       | tgpc wrote:
       | Long-time Ubiquiti fan here
       | 
       | Their lack of Wifi 6 across the range, and the security problems
       | drive me to look at alternatives. Found the Netgear WAX610. Very
       | happy with them.
        
       | ta20210405 wrote:
       | Amateur hour at Ubiquiti. Sadly they leave us without a decent
       | replacement. Mikrotik is the only contender and they leave a lot
       | to be desired.
        
         | dt3ft wrote:
         | I recommend fortinet as replacement for USG. Not as cheap, but
         | you get what you pay for.
        
       | rossipedia wrote:
       | > Ubiquiti also hinted it had an idea of who was behind the
       | attack, saying it has "well-developed evidence that the
       | perpetrator is an individual with intricate knowledge of our
       | cloud infrastructure. As we are cooperating with law enforcement
       | in an ongoing investigation, we cannot comment further."
       | 
       | I personally don't believe this. IMO, this is a company who is
       | looking for a fall guy, and _most likely_ it's going to be
       | somebody who raised a stink about all the security problems
       | during their time there.
       | 
       | Form your own opinion, I'm just a guy who worked at Ubiquiti for
       | a year, raising all kinds of hell about the security,
       | architectural, and operational problems that I saw while I was
       | there.
       | 
       | But what do I know...
        
         | edoceo wrote:
         | I hope you don't end up fulfilling your own prophecy
        
           | rossipedia wrote:
           | I'm pretty sure I'm safe. I left as soon as I could (almost 2
           | years ago) once I realized how institutionally broken the
           | company was.
        
         | judge2020 wrote:
         | Given they were stupid enough to spin up some VMs, I doubt it
         | was someone that knew what they had access to. A skilled
         | attacker would stay dormant sucking up all data accessible via
         | the AWS API (including s3 stuff) and potentially keep access to
         | the infrastructure for years.
        
           | throwaway8581 wrote:
           | This kind of analysis is basically worthless because you
           | don't know whether they are operating at multiple levels of
           | deception by, e.g., making you think they are a stupid script
           | kiddie and that you successfully wiped them out.
        
             | LilBytes wrote:
             | If they had root access to an AWS account, this is exactly
             | what you would expect.
             | 
             | If there's a cyber security firm that's been hired to
             | provide analysis they're going to be combing through egress
             | traffic to find anything suspicious. But, egress traffic is
             | difficult and expensive to analyse.
             | 
             | Worse yet, the attackers could easily just sit there and
             | not use their attack methods for a little while and start
             | up their compromises in weeks or months. You couldn't be
             | certain nothing's still there till you ripped the AWS
             | resources out and replaced them.
        
           | smashed wrote:
           | There is no evidence that this did not also happen.
        
             | brippalcharrid wrote:
             | And if it is happening, we might hear about that in a few
             | years' time, if it's discovered, and if it's brought to
             | light in circumstances that are conducive to the vendor
             | making a public disclosure (eg. which are impossible to
             | cover up).
        
           | [deleted]
        
         | TeMPOraL wrote:
         | That would be the reverse of the usual strategy, wouldn't it?
         | Most companies seem to try to pin breaches on sophisticated
         | hacker groups backed by nation states. But then, they benefit
         | from the perception of a threat that's impossible to defend
         | from (so there wasn't anything they could do) - whereas
         | Ubiquiti benefits from people thinking the attack was just a
         | small actor that couldn't possibly threaten Ubiquiti's
         | customers.
        
           | woofie11 wrote:
           | Accusing whistleblowers of criminal activity?
           | 
           | That's a pretty common ploy. Been there, done that. Early in
           | my career when I was naive enough to try to whistleblow on
           | things over my head.
        
             | tobr wrote:
             | I'd love to hear that story, if you can share it!
        
             | TeMPOraL wrote:
             | Accusing whistleblowers and reporters is indeed common - it
             | pretty much seems the standard behavior in infosec in
             | particular.
             | 
             | What I meant was something different. The breach, as I
             | understand it, was quite critical. Ubiquiti in this case
             | could take the standard corporate spiel of "it has
             | hallmarks of a nation state attack, there was nothing we
             | could do" bullshit disclaimer - but given the nature of
             | this breach, every customer of theirs would now be
             | wondering if $Enemy has put malware in their infra, and
             | whether it isn't a good idea to smash it all with a hammer
             | and buy new one from someone else. So I suspect Ubiquiti is
             | going the other way, blaming it on a single,
             | inconsequential individual, that absolutely, positively
             | didn't give access to anyone else, and thus nobody's infra
             | was in any danger.
             | 
             | (Note: I have no inside knowledge, or even any deep
             | knowledge, of this topic - I'm just a random Internet
             | person speculating.)
        
           | peteretep wrote:
           | > nation states
           | 
           | Nation state is not a fancy infosec way of saying country
        
             | cutemonster wrote:
             | Why don't they say "country"? Or just "nation"?
             | 
             | (Can it really be because "nation state" is more fancy?)
             | 
             | I can understand, though, why they don't say "state" --
             | maybe that'd sound as if a single state in the US had
             | attacked
        
             | TeMPOraL wrote:
             | Nah, most of the time it's just a fancy infosec way of
             | saying "it was likely ordinary criminals, or even some
             | script kiddies, but it would be quite embarrassing to admit
             | that".
        
           | rossipedia wrote:
           | Yes, you're right. But I don't really expect them to make the
           | "smart" or "usual" play. That would honestly surprise me.
           | Now, pinning it on somebody that was generally disliked
           | because they constantly blocked things that had obvious
           | gaping security holes? Basically sicking law-enforcement on
           | somebody out of pure spite? I can absolutely believe that.
        
           | ex_ubiquiti wrote:
           | There was a lot of infighting and turf wars when I finally
           | quit. I'm not even surprised that this latest turf war
           | spilled into the news.
        
         | electro_blah wrote:
         | So, why & how did you do this?
        
         | ghughes wrote:
         | This quote says nothing at all. _Obviously_ the perp is someone
         | with intricate knowledge of their network.
         | 
         | They might as well come out and say they have well-developed
         | evidence that the perpetrator has an IQ over 50.
        
         | geoduck14 wrote:
         | When I'm bored, I sometimes intentionally take comments out of
         | context, just to see where they go, I know this isn't what you
         | ment, but I like to pretend:
         | 
         | >Form your own opinion, I'm just a guy who worked at Ubiquiti
         | for a year, raising all kinds of hell about the security,
         | architectural, and operational problems that I saw while I was
         | there.
         | 
         | You are a lawn man/woman.
         | 
         | Security problems: I have to show my badge EACH TIME I go to
         | the bathroom
         | 
         | Architectural problems: these bricks are the WRONG COLOR!
         | 
         | Operational problems: The painters used the WRONG COLOR OF OFF
         | WHITE!
         | 
         | Again, I know this isn't what you ment, but I enjoyed
         | transposing a well written critique of their software from
         | (presumably) a knowledgeable software guy into a lawn person in
         | a jumpsuit.
         | 
         | Thank you, amd have a good day.
        
         | rossipedia wrote:
         | I mean, don't get me wrong, there absolutely _is_ somebody
         | who's responsible for it, but I wouldn't place any money on
         | Ubiquiti being able to figure out who it really was.
         | 
         | They want to brush this under the rug as fast as they can, and
         | that means using the opportunity to pin it on somebody that's
         | been "problematic".
        
           | ex_ubiquiti wrote:
           | I remember the cloud lead they hired out of Amazon was as
           | toxic as they come. If he's still in charge I can see him
           | blaming his own team members.
           | 
           | The culture at Ubiquiti collapsed in my last year there. The
           | company was unrecognizable because everyone was quitting so
           | fast.
        
         | someonehere wrote:
         | For LastPass, did they enforce the policy to mandate 2fa for
         | everyone's vault? Where I work they mandate 2fa be enabled.
         | Some orgs overlook this.
        
         | dylan604 wrote:
         | Are you volunteering for the role? It almost reads as if you
         | are expecting to be named on a list of potential suspects.
        
           | rossipedia wrote:
           | Heh... no. I quit two years ago, well before all this
           | happened. I have ideas about who this "Adam" is, and I also
           | have some suspicions about who they're accusing as the
           | culprit. But that's all they are. Hunches.
        
           | admax88q wrote:
           | Or he _is_ the culprit trying to get ahead of the story.
        
         | vvanders wrote:
         | Damn, that's pretty depressing.
         | 
         | I really wouldn't like to migrate away but I can't say all the
         | info that's been coming back has been making me want to have
         | them as a part of my network infrastructure.
        
           | bpye wrote:
           | During this week I've been playing around with replacing my
           | USG with my existing home server - it already has two NICs -
           | my first thought was to run OPNSense in a VM but nftables on
           | NixOS seems to work well enough - there are a few examples
           | floating online [0,1]. OpenBSD even supports the USG [2] but
           | I couldn't think of much reason to keep the extra hardware.
           | 
           | The next thing I want to do is reflash my Unifi APs with
           | OpenWRT [3] - the hardware is fine, but at that point I'll
           | get all the support without the controller software.
           | 
           | My home environment is fairly basic so moving away isn't too
           | hard - this would obviously be much harder for a small
           | business...
           | 
           | [0] - https://francis.begyn.be/blog/nixos-home-router
           | 
           | [1] - http://www.willghatch.net/blog/2020/06/22/nixos-
           | raspberry-pi...
           | 
           | [2] - https://www.openbsd.org/octeon.html
           | 
           | [3] - https://openwrt.org/toh/ubiquiti/start
        
             | zrail wrote:
             | > The next thing I want to do is reflash my Unifi APs with
             | OpenWRT
             | 
             | My understanding is that this doesn't work anymore because
             | Ubiquiti started signing firmware. Your link also goes to a
             | blank page.
        
               | kelnos wrote:
               | Depends on the hardware, I guess? I bought an AC AP Pro
               | last fall and had no problem flashing OpenWRT on it.
        
               | bpye wrote:
               | That's odd, the link works for me but the wiki was very
               | slow earlier. From what I've read Ubiquiti have made it
               | harder to flash new hardware, but even the new ax APs are
               | supported by OpenWRT. There is a commit with some info -
               | it seems there is a way to disable signature verification
               | [0].
               | 
               | [0] - https://git.openwrt.org/?p=openwrt/openwrt.git;a=co
               | mmit;h=fb...
        
             | lostlogin wrote:
             | > replacing my USG with my existing home server
             | 
             | I like this idea too, but would prefer that the router was
             | physically separated and before any hardware that was in
             | the network.
             | 
             | Is this a pointless concern?
        
               | vageli wrote:
               | It's hard to say whether or not the concern is pointless
               | without knowing its basis. Why do you want it physically
               | separated?
        
               | lostlogin wrote:
               | I had assumed a setup which had several VMs, with one
               | being a PFSense or similar to be less secure than a
               | standalone firewall. Reading about the pros and cons
               | leads me to conclude that security in a virtual setup is
               | just fine.
        
               | jefurii wrote:
               | If you have your router in a separate box then you won't
               | have to take down your whole network if you have to
               | restart your VM host.
        
               | neolog wrote:
               | If your server is vulnerable to some threat, adding
               | another barrier in front of it could help.
        
             | zbrozek wrote:
             | I _do_ run opnsense in a VM and am very happy with the
             | setup. My requirements for APs are simple but hard to
             | satisfy. Ceiling mount, PoE, present-day-best 802.11
             | standard, and openwrt-capable.
        
           | posguy wrote:
           | I want to fire Ubiquiti, but where can I go to get my router,
           | wireless access points and switches in one management
           | interface? There are plenty of poorly performing consumer
           | grade options out there which hide all complexity, but they
           | break in fun ways (eg: Google WiFi creating loops in the
           | network when users try to do wired backhaul) and only tackle
           | part of the stack.
           | 
           | I really just want to manage an OpenWRT based network with
           | one central web interface and not have to deal with
           | corporate/state entities deciding to push fun changes out in
           | the management interfaces that power these systems.
        
             | frombody wrote:
             | Meraki?
        
             | bpye wrote:
             | It's an interesting idea to have a single pane of glass
             | management experience for OpenWRT - given that all config
             | is under UCI [0] it seems very possible. One of the things
             | on my todo list is to try and get Nix to push config to my
             | Unifi APs when I flash them with OpenWRT.
             | 
             | [0] - https://openwrt.org/docs/guide-user/base-system/uci
        
               | posguy wrote:
               | Take a look at https://openwisp.io/docs/ as it can
               | accomplish this today.
        
               | bpye wrote:
               | That's very neat - though I think orthogonal to my Nix
               | plan. Certainly suits anyone that wants to manage
               | multiple APs from the same interface however.
        
             | kccqzy wrote:
             | > Google WiFi creating loops in the network when users try
             | to do wired backhaul
             | 
             | That's very surprising to hear. The decades-old spanning
             | tree protocol can prevent that. I in fact have a friend who
             | has done the exact same thing (Google Wifi with wired
             | backhaul) with no problems. It switches from 802.11s to STP
             | with no problems.
        
             | simple_phrases wrote:
             | Check out OpenWISP. It works with OpenWRT.
        
             | mopsi wrote:
             | I keep seeing the requests for central management
             | interface, which leave me somewhat puzzled. Why do you need
             | in a home environment? I run a small network with one big
             | router and several access points, and at least with
             | Mikrotik's gear, it's pretty much fire and forget. It has
             | CAPsMAN[1] to centrally manage wireless networks, but I've
             | found it to introduce unneeded complexity. Auto-updates[2]
             | don't need any central management either. Monitoring can be
             | done through SNMP[3], and there's a REST API too[4].
             | 
             | [1] https://wiki.mikrotik.com/wiki/Manual:CAPsMAN
             | 
             | [2] https://wiki.mikrotik.com/wiki/Manual:Upgrading_RouterO
             | S#Rou...
             | 
             | [3] https://wiki.mikrotik.com/wiki/Manual:SNMP
             | 
             | [4] https://help.mikrotik.com/docs/display/ROS/REST+API
        
               | posguy wrote:
               | I have a good deal of experience with Mikrotik's
               | offerings, and I am not looking to power networks I
               | support with a patchwork of different systems that each
               | have their own interface.
               | 
               | Most of the value proposition of the Unifi lineup is I
               | can look at a single website that I host and see the WiFi
               | clients connected to an access point, what switch feeds
               | that access point internet (and whether its linked at
               | gigabit or 100Mbps), uptime on all devices involved in
               | the stack, whether the client has poor WiFi quality,
               | trouble DHCPing, etc.
               | 
               | The single pane of glass to view everything when I am
               | many miles from the networks I support is essential.
               | Compared to when these sites were on PFSense before
               | migrating, these networks have improved uptime, rapid
               | remediation of issues, and changing VLANs, SSIDs and
               | labeling each client on the network is a snap.
               | 
               | Edit: Borrowed /u/bpye's single pane of glass term
        
               | torwayburger wrote:
               | > Most of the value proposition of the Unifi lineup is I
               | can look at a single website ...
               | 
               | > The single pane of glass to view everything when I am
               | many miles from the networks I support is essential
               | 
               | It's also why we're talking about this.
        
               | apple4ever wrote:
               | Only because they made it cloud based.
               | 
               | If they never forced people to create a cloud account -
               | and instead allowed people to choose - this would be
               | wildly different.
        
               | mnemnc wrote:
               | Did I miss something here? I run a Unifi network with a
               | local account and don't recall being forced to create a
               | cloud account.
        
               | JamesSwift wrote:
               | The UDM, UDM Pro, and I think _all_ newer controller
               | software require cloud login at some point in the
               | process.
        
               | philjohn wrote:
               | They do - first thing I did though was then go in and add
               | a local account, and disable remote access (I have a
               | wireguard tunnel that terminates on a server behind my
               | firewall if I need remote access).
        
               | Godel_unicode wrote:
               | It's definitely not all the new controllers, although
               | with the UDM line you might be right. I think there's a
               | huge intersection between people who would buy those
               | specific devices and people who are perfectly happy to
               | have remote access to their control plane in the cloud.
        
               | posguy wrote:
               | The UDM and UDM-Pro force you to set up a UI.com account,
               | and cannot be used with external Unifi controllers like
               | one you might run on a server, PC or cloud key
               | (Ubiquiti's management software on a Power over Ethernet
               | powered dongle, does not require a UI.com account).
        
               | jaywalk wrote:
               | The UDM and UDM Pro _are_ the controller, and you can
               | disable all of the cloud nonsense after initial setup.
        
               | JamesSwift wrote:
               | You can disable on the UDM but I don't believe the UDM
               | pro allows you to. Thats just what I've heard though, so
               | might not be accurate.
        
               | jaywalk wrote:
               | The UDM Pro does allow it. I've got one, and all of the
               | cloud stuff is disabled.
        
               | JamesSwift wrote:
               | It looks like what I was referring to is that they
               | recently made the initial controller setup on the
               | cloudkey require a cloud account [1], but you can migrate
               | to local only after the initial setup.
               | 
               | So the only remaining 'local only' from start to finish
               | is for self-hosted I guess.
               | 
               | [1] - https://www.youtube.com/watch?v=gNkXAe0aOAg
        
               | Godel_unicode wrote:
               | I have a cloud key gen2 plus and do not have a UI.com
               | account. I would classify getting the network controller
               | setup without having one initially "mildly annoying but
               | worth it".
               | 
               | I'm also floored at the number of people who are spinning
               | the existence of a self-hosted controller as somehow a
               | bad thing...?
        
               | spockz wrote:
               | It is also about dark patterns. I never had the cloud
               | option enabled. One night after a long day I upgraded the
               | controller software. I noticed a message like "do you
               | want to login?" and wasn't awake enough to realise that
               | it asked for my ui.com account and that after that cloud
               | management was enabled _and_ my phone switched to
               | authenticate from a direct connection with the local
               | credentials to using the ui.com credentials.
        
               | [deleted]
        
               | [deleted]
        
               | kweinber wrote:
               | It seems the hackers currently in your network must value
               | those same features. Very convenient.
        
               | posguy wrote:
               | I don't use a UI.com account to connect to the Unifi
               | controller I host (as I don't need their inconsistently
               | working NAT traversal to get to my controller), hopefully
               | the networks I support are safe due to not being
               | entangled with Ubiquiti's cloud infrastructure.
               | 
               | Anyone who is forced to get a UI.com account (eg: UniFi
               | Dream Machine and UDM-Pro owners) should change their
               | credentials and do a factory reset on their routers and
               | Access Points ASAP.
        
               | lostlogin wrote:
               | > do a factory reset on their routers and Access Points
               | ASAP
               | 
               | This is a miserable user experience. If you do a reset
               | and don't know the SSH password on APs or cameras you get
               | to spend a hellish few hours crawling though ceiling
               | insulation, climbing ladders and physically resetting
               | devices. It's so shit. I've just done it, but not due to
               | security concerns, but instead because of a UDM-P
               | crapping out randomly.
        
               | beezischillin wrote:
               | Mikrotik itself had security problems before. Tom
               | Lawrence covered a lot of this on YouTube. I can
               | recommend his channel on the topic.
        
               | Causality1 wrote:
               | Frankly I wonder at how big some of these peoples' houses
               | are. My single seven year old Nighthawk router covers an
               | entire 2300 square foot home and penetrates the brick
               | walls to reach halfway up the street.
        
               | roland35 wrote:
               | My house had a problem since the cable came in on one
               | corner of my house, and my office was on the other side.
               | Browsing was ok but things like video calls suffered, at
               | least until I went with a Unifi BeaconHD.
        
               | Spooky23 wrote:
               | Depends a lot on the house. My house is <2000 sqft, but
               | signal, especially 5Ghz propagates poorly though old
               | school plaster walls.
               | 
               | It wasn't a problem until covid when multiple meeting or
               | other streams just performed poorly on a marginal
               | network. The Ubiquiti gear made it easier to run antennas
               | for optimal signal.
               | 
               | The hot thing to do is to shit on them, but I'll be
               | sticking with it. They'll emerge better from this crisis
               | and if you think that any competitor in this price point
               | is better, you're delusional.
        
               | ethbr0 wrote:
               | Also, foil-backed insulation [0]. I finally figured out
               | they insulated the hell out of my house with this stuff.
               | 
               | Works amazingly on heating and cooling bills, but it's a
               | pretty solid wall to radio waves.
               | 
               | [0] https://www.ibhs.co.uk/foil-backed-mineral-wool-50mm-
               | thick-x...
        
               | lostlogin wrote:
               | COVID had me setting up more UniFi APs. It held up
               | incredibly well for moving large files across VPNs and
               | running multiple Zooms for work places and school.
               | 
               | COVID must have been a massive boost to their bottom
               | line.
               | 
               | I'm no market analyst, but the last year, even including
               | the last week, has been very good to Ubiquiti.
               | 
               | https://www.nasdaq.com/market-
               | activity/stocks/ui/advanced-ch...
        
               | lotsofpulp wrote:
               | That's not my experience, all the way from Meraki
               | enterprise access points to the standard consumer
               | WRT54GL.
               | 
               | First problem is 5GHz is terrible at going through walls,
               | I don't believe it will even go through a single brick
               | wall and maintain decent bandwidth. Even 2.4GHz is
               | considerably slowed by 2 or 3 drywall/plywood
               | obstructions.
               | 
               | Second problem is can the mobile device you're using
               | return that signal through all those walls to the access
               | point. I have noticed an huge increase in quality and
               | snappiness of FaceTime and other high up and down
               | bandwidth activities once I added more access points so
               | that connections are going through only 2 or 3 walls.
               | 
               | For another reference, I have a hotel that needed to
               | upgrade its network to meet the brand standards for
               | signal strength in all the rooms, and we had to end up
               | installing 6 access points in the drop ceiling of each
               | hallway 15 guest rooms in length (each guest room is
               | ~15ft wide, so the corridor was ~225ft long). It resulted
               | in the elimination of almost all guest complaints about
               | the wireless network.
        
               | lostlogin wrote:
               | Getting signal to devices isn't a problem, but it's not
               | easy having an AP receive signal from a low power device.
               | Multiple APs is the way to go in my experience.
        
               | sokoloff wrote:
               | Mine's only slightly larger than that (mostly by virtue
               | of having 3.5 levels, not by X-Y size), but the original
               | plaster walls attenuate the hell out of 5GHz signals. I
               | have two APs, one in the basement and one on the second
               | floor and even with that, I'm considering adding two more
               | inside and a dedicated one outside to serve the patio/BBQ
               | area as I can readily tell the speed difference to
               | internal file and backup servers if I'm in the same room
               | as an AP vs on another floor or outside.
               | 
               | Make no mistake, it still "works" with just one, only
               | slower.
        
               | gedy wrote:
               | > the original plaster walls
               | 
               | Ah, the ones that have wire mesh underneath? That would
               | do it.
        
               | sokoloff wrote:
               | No. My house predates the widespread use of expanded
               | metal mesh style of lath. Just the old wood strip lath
               | and thick, horsehair plaster.
        
               | lostlogin wrote:
               | Somehow I have managed to spend most my time in a house
               | that has concrete and brick stopping 5G, a house with
               | wooden walls that block RF and foil insulation under the
               | floor which is even worse, and a workplace environment
               | that has literal faraday cages all around.
               | 
               | I like UniFi in wall access points in the room I'm
               | inside.
        
               | igetspam wrote:
               | My house is about that size. My detached garage is
               | 400sqft. My barn is 1600 sqft. And my travel trailer is
               | 37" long. My network comes into the house and the
               | wireless needs to cover all of the structures because we
               | need into in all the places. It's all spread over about
               | an acre and a half. I run ethernet to a PoE AP in the
               | garage, through an overhead crawl space that covers thale
               | span between the house and the garage, I have b2b radios
               | between the house and barn and the trailer has an LTE
               | router/wifi repeater that picks up wireless from the
               | barn.
               | 
               | Not super complex but no single nighthawk is gonna do it
               | and the unifi management interface does the job. I'm not
               | cloudy though.
        
               | vel0city wrote:
               | I run two AP's hard wired to the PoE switch in my closet.
               | These AP's being in the hallways on opposite sides of my
               | home. I run them at lower power so I don't have an
               | excessive amount of RF blasting into neighbor's homes,
               | but I still get good signal quality to/from each AP.
               | Because I now have two AP's running on different channels
               | I've effectively doubled my network throughput overall.
               | 
               | One important thing to think about when planning your
               | WiFi deployment is if you have things that have poor
               | connectivity, everything on that channel suffers. I can
               | have several devices running at several hundred megabits
               | of quality, but a single device being really slow bogs
               | down the channel and suddenly everything else starts
               | getting lots of jitter and overall poor network
               | performance despite most devices having good signal
               | quality. Also, your device may show it has good signal
               | _strength_ but it might be poor quality (bad SNR) so in
               | reality its a poor link speed. Having things physically
               | closer usually results in better average SNR, meaning
               | higher speeds for everything on the channel.
               | 
               | Also, as others have mentioned 5GHz might make it through
               | a wall without a lot of stuff in it, but its not going to
               | penetrate very well through several walls. Having my AP's
               | in the hallways means there's usually only one wall with
               | minimal stuff in it between a device and the AP, so each
               | device usually reports at least several hundred megabits
               | of throughput possible.
        
               | sylens wrote:
               | I feel the same way - my Nighthawk is going strong with
               | custom firmware, but my friends with Ubiquiti gear try to
               | get me to replace it with a bunch of Unifi stuff every
               | time I talk to them.
        
               | sigg3 wrote:
               | What firmware?
               | 
               | I need new APs soon.
        
               | alasdair_ wrote:
               | I use three unifi AP-Pros for my 3500 sq ft home plus
               | front and back yard.
               | 
               | I possibly could have done it with two if I ignored the
               | outside areas but one definitely wasn't enough even with
               | careful placement.
               | 
               | Edit: obviously 2.4ghz penetrates further, but 4k
               | streaming on multiple TVs doesn't go well with the
               | bandwidth (and interference) on 2,4
        
               | qsi wrote:
               | Probably not big by US standards, but WiFi attenuation
               | across multiple floors is such that an AP in the living
               | room won't provide any decent signal one floor straight
               | up. Depends on the materials and layout of your house...
        
               | namibj wrote:
               | This also means you can re-use a frequency with just one
               | floor in between and no issues, and with a horizontally
               | directional antenna, possibly even on adjacent floors.
        
               | bonestamp2 wrote:
               | > Why do you need in a home environment?
               | 
               | I definitely don't "need" it. But it's veeeeeeeery
               | convenient. Especially when it comes to security, being
               | able to see which devices have updates and perform them
               | all from one screen, is extremely convenient. I'm highly
               | interested in paying for convenience at home.
               | 
               | Thankfully I don't use their cloud based management
               | interface -- as far as I know this breach does not affect
               | my local UniFi Controller. Hopefully this is a rude
               | awakening and Ubiquiti goes back to their old consumer
               | focused approach.
        
               | lostlogin wrote:
               | > I keep seeing the requests for central management
               | interface, which leave me somewhat puzzled. Why do you
               | need in a home environment?
               | 
               | Crap wifi was a huge thing I dealt with. Unifi fixed that
               | completely. The ability to run a relatively complex
               | network (by home network standards) with multi access
               | points is nice, but the ability to administer them
               | without CLI interface is great. I loved my edge router
               | but touched it with trepidation. It was rock solid except
               | when I was sucking with it. Unifi suits/suited the
               | enthusiastic amateur.
               | 
               | > I run a small network with one big router and several
               | access points, and at least with Mikrotik's gear, it's
               | pretty much fire and forget.
               | 
               | Unifi used to be too, with an interface that was a bit
               | difficult to navigate (settings spread among about 20
               | tabs, but it was possible to get the job done without
               | sshing to components).
               | 
               | Now it's flakey. I just rebuilt my last week which was
               | working fine but I couldn't log in and the UDM-P screen
               | said it required resetting. Dark times.
        
               | qsi wrote:
               | Similar to the other responses, it's the fact that I can
               | manage my network remotely from a simple app or UI. This
               | helps me answer phone calls from my family asking why
               | Netflix doesn't work on TV #2, when I'm not at home.
               | Won't solve all problems, but at least I can narrow it
               | down and troubleshoot.
               | 
               | And I like the fact that I can an overview of the state
               | of my network; one of my wired links to an AP would
               | degrade to 100 Mbps at times, and being able to see the
               | link speeds easily was very helpful (it was a bad
               | ethernet cable in the end).
               | 
               | Before I moved to Ubiquiti I had a spate of problems with
               | my fiber broadband, which would stop working for a few
               | minutes at random, resetting my RDP connections. I had a
               | vendor-supplied Linksys (I think?) router, and trying to
               | troubleshoot it was painful. If I ever have such problems
               | again I'll have much better diagnostics.
               | 
               | That said, I won't buy any Ubiquiti gear that requires
               | the cloud, and my faith in the company is eroding. But,
               | like others, I would be at a loss what to replace my gear
               | with at the moment. I just hope it'll function well
               | enough until either Ubiquiti gets it act together
               | (again?) or a viable competitor arises.
        
               | thinkloop wrote:
               | > it was a bad ethernet cable in the end
               | 
               | Checking the cable is like checking if the power is on,
               | it is NEVER the cable - except in networking for some
               | reason. Half the time it's the cable.
        
               | oarsinsync wrote:
               | Network cables (copper and fibre) have a limited bend
               | radius. Most people don't think about this and will bend
               | a cable beyond tolerance, which will eventually result in
               | the cable not working correctly, and/or manifest as
               | intermittent issues.
               | 
               | I suspect that's the most common cause of network cables
               | 'going bad' in the home.
        
               | magicalhippo wrote:
               | I learned this back in school, when the previous years
               | students had laid new Ethernet cables from the classroom
               | to the server room, but the machines would only get 10M
               | and not 100M link as they should.
               | 
               | Didn't take us long to notice they had laid the cable
               | like electricians, neatly following the contours of a few
               | door frames with tight 90 degree bends.
               | 
               | Glad I learned that lesson early.
        
               | luag wrote:
               | You might be interested in Gl.inet.
               | 
               | It uses OpenWRT, and you can access it remotely.
        
               | joshspankit wrote:
               | > Why do you need in a home environment?
               | 
               | To answer this for me personally (and I suspect this is a
               | pretty common answer): To use the best, and to explore
               | technologies that I might suggest to business clients.
               | 
               | Business clients _love_ central management interfaces.
               | 
               | As well, I'm honestly kind of done with managing fiddly
               | "snowflake" devices, and central management interfaces
               | usually come with the ability to standardize the config
               | across devices.
        
               | mavhc wrote:
               | Mikrotik have not been able to keep up with the latest,
               | or previous to latest wifi standards, seems like it's
               | become too complex
        
               | KozmoNau7 wrote:
               | Skipping wifi 6 seems like a smart move, with 6E on the
               | horizon. It includes all the things that should have been
               | part of the standard in the first place, so why get your
               | hardware certified for 6, if you have to get it
               | recertified for 6E anyway shortly after?
               | 
               | 6 doesn't add very much over 5 in real world setups, very
               | few devices even support 802.11ax yet, and the bleeding
               | edge has never been Mikrotik's target segment.
               | 
               | 6E gear is not really available anywhere yet, so it's
               | really only an issue for people who just _have_ to have
               | the latest gear at all times. For the majority of people,
               | 802.11ac /wifi 5 is what their hardware supports, so
               | that's what they need.
        
             | bayindirh wrote:
             | I know TP-Link is no Ubiquiti, but I run two identical
             | small networks (VR-2100 routers with RE-200v4 extenders
             | running in mesh mode), and it's pretty solid so far.
             | 
             | You can access your network from Tether app via cloud if
             | you wish, too. When you enable Mesh, everything is
             | controlled via the router. You don't need to manage
             | anything on the extenders.
             | 
             | RE200 can work as an AP if you can get them a CAT5, or can
             | provide wireless to Ethernet capability. I don't need home-
             | wide VLANs and other exotic stuff (for a home network), but
             | you can adjust QoS on the router in three levels and it has
             | an embedded OpenVPN server if you fancy.
             | 
             | While not network related, you can temporarily or
             | permanently turn off all LEDs on the devices so they don't
             | create any light pollution, something I love to have.
             | 
             | All in all it's a great package, for my home network, at
             | least.
        
             | [deleted]
        
             | growse wrote:
             | I was going to look at OpenWISP, which looks like it can
             | centrally manage a whole bunch of kit, including openwrt
             | and also edgeswitch devices.
        
         | inetknght wrote:
         | > _I 'm just a guy who worked at Ubiquiti for a year_
         | 
         | Would you be able to point to unofficial compatible operating
         | systems for Ubiquiti devices? I want to remove Ubiquiti
         | software from the devices I bought and paid for.
        
           | ex_ubiquiti wrote:
           | The gear is locked down to UniFi firmware. Some of us wanted
           | to open it up to alternatives like OpenWRT but that wasn't an
           | option for us.
        
         | late2part wrote:
         | So, did you do it?
        
         | vmception wrote:
         | yeah this is just a good as just saying it "has the hallmarks
         | of a state-level attack", pointing at Russia and calling it a
         | day
         | 
         | everyone believes it
        
           | harry8 wrote:
           | That may have worn thin, nowadays. The average response here
           | would have been described as cynical in the past. The
           | Russia/China scapegoat had been way overused to the point
           | where I'm cynical every time it comes up probably even where
           | it's actually true, one time in a hundred or whatever.
           | 
           | Nobody blames the NSA in these circumstances, ever.
        
             | Hjfrf wrote:
             | Google did it with an allied op recently. Not NSA, but as
             | close as we're likely to hear about. https://www.technology
             | review.com/2021/03/26/1021318/google-s...
        
               | elliekelly wrote:
               | Do we know for sure it was an allied operation?
               | Everything I saw mentioned a "Western government
               | operation" which doesn't necessarily exclude the NSA.
        
       | tpmx wrote:
       | By now we'll have to ask: Is it realistic to expect hardware-
       | oriented companies to build secure software?
       | 
       | (Yes, Apple exists.)
        
         | ryandrake wrote:
         | Most hardware companies don't care in the slightest about
         | software quality. To them, software is just another line item
         | on the Bill Of Materials, like a bolt or piece of sheet metal.
         | You either have some overworked intern who knows C cobble
         | something together that barely works or you buy it from the
         | least expensive supplier. When the build is ramping, at the end
         | of the assembly line somebody is going to flash _something_ on
         | the device, and they are not going to stop the line to worry
         | about a security hole.
        
           | [deleted]
        
         | simple_phrases wrote:
         | iOS exploits are cheaper than Android exploits because iOS
         | exploits are so plentiful in comparison[1].
         | 
         | [1] https://www.cyberscoop.com/ios-zero-day-zerodium-high-
         | supply...
        
         | eertami wrote:
         | I think your question is wrong, it should be: Is it realistic
         | to trust any company to build completely secure software?
         | 
         | I don't see your point about Apple, unless you're being
         | sarcastic for comedic effect. Apple release software with
         | security flaws too. In fact a zero-click security vulnerability
         | present in the Apple email client was posted on this very page
         | only three days ago[1].
         | 
         | [1]: https://news.ycombinator.com/item?id=26664714
        
         | jnwatson wrote:
         | This wasn't about the security of their "software", as in the
         | thing that's running on your device. This was about their
         | backend security. That's a much, much tougher call to make.
        
       | d-funct wrote:
       | What no one seems to be really discussing is how paranoid should
       | people be around this breach?
       | 
       | Is it a case of you probably want to rebuild machines that have
       | default usernames/passwords? Or is it more whatever can be seen
       | in the Ubiquiti UI might be been accessed by third parties?
        
         | rovr138 wrote:
         | > Is it a case of you probably want to rebuild machines that
         | have default usernames/passwords?
         | 
         | I mean, regardless, most probably, the answer to this is yes.
        
       | wnevets wrote:
       | breaches can happen to anyone however as a customer the way
       | Ubiquiti has been handling this is really disconcerting.
        
       | hrgiger wrote:
       | I keep one 6p behind isp router to manage home network, they have
       | good hardware but i didnt like the idea exposing to cloud, only
       | allowed local dns, ntp. And removed all port listeners from ubi
       | in sbin then touched a new file with same name. Latest firmware
       | complained a lot but worked at some point. I am not sure i am
       | fully secure but quite happy with performance
        
       | ghostpepper wrote:
       | I would love to see a competitor spring up targeting the same
       | enthusiast/prosumer segment. It seems like there are quite a few
       | ex-employees with knowledge of how to build it.
        
       | TwoNineFive wrote:
       | On this subject, does anyone know what is up with the reddit sub,
       | r/ubiquiti? Seems to be run by u/briellie. She(?) seems like a
       | really toxic person with some kind of business relationship with
       | Ubiquiti like a reseller or something.
       | 
       | The Reddit sub seems like they are actively trying to suppress
       | discussion of this issue. There's some allegations of censorship
       | on the sub, but I'm not seeing it... which might actually just be
       | confirmation that they are censoring. I don't know.
        
         | moxzyros wrote:
         | There was a recent discussion[1] on the sub with 1K upvotes and
         | over 500 comments about the breach and I routinely see unabated
         | salty posts and comments about Ubiquiti's downward spiral. I
         | have lurked on the sub for several years (I manage a bunch of
         | Ubiquiti gear) and I never got the impression people were being
         | censored or moderated into submission.
         | 
         | Are there any particular examples of suppression or links to
         | the allegations of censorship? The sub did recently begin
         | allowing equipment picture posts again by popular demand. [2] I
         | suppose an uncharitable interpretation is that that move was
         | appeasement to distract from the breach issue.
         | 
         | [1]
         | https://www.reddit.com/r/Ubiquiti/comments/mgm4o7/whistleblo...
         | 
         | [2]
         | https://www.reddit.com/r/Ubiquiti/comments/mi0679/rule_chang...
         | 
         | Edit: Formatting
        
       | worik wrote:
       | I can believe that they do not keep logs of the database access.
       | As brain dead as it sounds.
       | 
       | I have been in the position of implementing a client on a API I
       | do not control. The owners of the servers (colleagues but in a
       | different country) do not seem to know what logs are.
       | 
       | We get random failures from the server. I can pin down to the
       | second when they occur (not closer because of network lag). I
       | suspect that the server is failing under load, but the way I
       | would find out is to... Read the logs.
       | 
       | My foreign colleagues do not respond to me, ghost me entirely,
       | when I ask them to inspect the logs.
       | 
       | Perhaps it is a Windows/Azure thing?
        
         | jiggawatts wrote:
         | Logs are typically off by default in most Enterprise software,
         | or goes nowhere by default which is basically the same thing.
         | 
         | Logs cost money to both collect and store. Not everyone is
         | cheerfully burning through VC capital. Some people have
         | budgets.
         | 
         | Speaking of log collection, simply dumping the logs into a
         | central repository is the same as taking the garbage to the
         | landfill. Collecting trash just results in a big collection of
         | trash.
         | 
         | Extracting useful information from a huge pile of logs is non-
         | trivial. You'd have to know at least one query language,
         | probably several if you work on big enterprise systems. You'd
         | have to know a bunch of esoteric things like how to convert the
         | long decimal strings to a number so that you can interpret as
         | any one of a dozen timestamp formats as an actual datetime in
         | UTC, _and then_ convert that to local timestamp so that you can
         | tell when something actually happened. And so on.
         | 
         | All of this is merely a prerequisite for finding a specific
         | instance of what you know is there.
         | 
         | You know what you'll never find in logs? Things you didn't know
         | to look for! That's unfortunately about 90-99% of what you
         | actually need to know, making logs typically about 1-10% as
         | useful as you'd like.
         | 
         | Did I mention they cost money? Have you _seen_ how many arms
         | and legs Splunk charges these days? Why would you pay that much
         | for something that is less than a tenth as useful as it could
         | be?
         | 
         | The fundamental problem is that discipline doesn't scale. You
         | can't expect a hundred thousand IT operations guys to all do
         | everything all of the time, in spite of the non-technical
         | finance guy holding on to the purse strings like he's gripping
         | a life preserver after going overboard in a raging storm.
         | 
         | PS: I turned logging on extensively for a recent Azure project.
         | Some logs cost more than the service they were monitoring. I
         | mean sure, I could turn off the unnecessary logs, but how do I
         | know _ahead of time_ which ones will be necessary or not? I don
         | 't have a time machine! I can't go back and turn off the logs I
         | won't need... later.
         | 
         | PPS: Have you noticed all logging companies charge by the
         | gigabyte? What incentive do you imagine they have for improving
         | the efficiency of the log transfer and storage formats?
        
           | [deleted]
        
       | spurgu wrote:
       | Am I the only one annoyed with the expression "all but"? To me it
       | sounds like the complete opposite. "All but confirms" to me
       | sounds like they're "doing everything else than confirming" /
       | "all other things except confirming".
        
       | dustinmoris wrote:
       | I find it really strange that so many claim that they need
       | Ubiquiti and that there is "sadly" no other good alternative.
       | What are people doing with their home networks? What are they
       | comparing it with? Has anyone actually tried some of the mesh
       | networks from TP-Link or other brands? I have one at home and
       | honestly I don't even know what the admin management looks like
       | because I never have to go there and do something. What are
       | people doing? Is it that I am so ignorant to some needs which
       | people have that they constantly need to tweak their networks at
       | home or is it just a symptom of Ubiquity kit that requires users
       | to constantly do something with it that now they think they need
       | all that fancy management stuff because they got used to do so
       | much maintenance work on something that should just work without
       | ever having to touch it again?
        
       | dmix wrote:
       | Looks like a basic ransom request but pushing malware to the '85
       | million' devices through automated automated would be far more
       | damaging.
        
       | vr46 wrote:
       | So this week, I have gone from having a single little USG and a
       | massive order planned for loads of kit to stopping them
       | automatically updating the firmware and dropping that order.
       | Extremely annoying, but not as annoying as if this had happened
       | in a couple of weeks.
        
         | tifadg1 wrote:
         | So what are vendor are you changing to now?
        
           | vr46 wrote:
           | None! Going to keep my jerry-rigged-Heath-Robinson networks
           | with the existing mesh and switches until things resolve to a
           | satisfactory juncture.
        
       | [deleted]
        
       | kbumsik wrote:
       | I was about to buy Ubiquiti products and it is disappointing.
       | 
       | Are there good alternatives other than DIYs like PfSense/BSD?
        
         | dt3ft wrote:
         | Fortinet?
        
       | haberman wrote:
       | Can companies be held responsible for damages from data breaches?
       | 
       | If they could, it seems like it would incentivize more caution
       | about what data is collected, and more investment in the security
       | of that data.
       | 
       | I also imagine an insurance industry, where the insurers then
       | have expectations about what kinds of security must be in place
       | to get reasonable premiums.
        
         | redler wrote:
         | Yup, this is more or less how "cyber security" policies work.
        
           | elliekelly wrote:
           | Unless it's changed in the last two or three years cyber
           | security insurance policies seem only to cover the cost of
           | notifying customers of the breach and paying for credit
           | monitoring for whatever period of time is required in each
           | customer's specific jurisdiction. (When last I looked, in
           | most states it's none.) Every time I looked into cyber
           | security insurance it wasn't worthwhile at all because it
           | didn't provide any meaningful coverage. Maybe for a small
           | startup with a _lot_ of PII it would make sense but I think
           | most companies would probably come to the same conclusion.
        
             | boston_clone wrote:
             | It may be worth reviewing cybersecurity insurance policies
             | with your legal team!
             | 
             | At a former company, we had a nasty case of BEC with a
             | vendor that ultimately cost us well over six figures - over
             | 90% of the loss was recouped by filing a claim with our
             | insurance.
        
       | ksec wrote:
       | HN probably get tired of me banging on about it.
       | 
       | But is about time Apple come back to Wireless and Router
       | business.
        
       | aneutron wrote:
       | I'm thinking it won't be long before folks roll their own distro
       | of Unifi APs and switches.
        
       | smiley1437 wrote:
       | Anyone know if Apple will be putting out a wifi mesh system,
       | maybe integrated into Homepod Minis? Apple already 'owns' me, I
       | might as well have them run my Wifi too and ditch my unifi gear.
       | 
       | At least Apple seems to care about privacy and security, even if
       | it is a self-serving marketing scheme.
        
         | lostlogin wrote:
         | Their wifi line used to be excellent.
         | 
         | Having APs that could be hardwired would be a requirement for
         | me. The less wifi the better.
        
       | MindTooth wrote:
       | After seeing that they did not capture the logs. What is the
       | "proper" way of storing said logs? I guess you need a remote
       | logserver like logstash to store them. But what service does
       | actually send the logs from the server to a central storage.
       | 
       | Looking into Loki, Graphite, etc. But I'm a bit at a loss where
       | to begin.
        
       ___________________________________________________________________
       (page generated 2021-04-05 23:02 UTC)