[HN Gopher] Security Issue: Cloud Site Manager presented me your...
___________________________________________________________________
Security Issue: Cloud Site Manager presented me your consoles, not
mine
Author : amaccuish
Score : 262 points
Date : 2023-12-14 16:42 UTC (6 hours ago)
(HTM) web link (community.ui.com)
(TXT) w3m dump (community.ui.com)
| js2 wrote:
| Also on r/Ubiquiti:
|
| https://old.reddit.com/r/Ubiquiti/comments/18hgpw1/security_...
|
| https://old.reddit.com/r/Ubiquiti/comments/18hs684/no_offici...
| NelsonMinar wrote:
| These are really bad, and both very recent. One post is a
| Reddit user who is seeing camera images from other Ubiquiti
| installations. The other is a general discussion about the lack
| of response from Ubiquiti so far.
| teamspirit wrote:
| So the guy makes the initial post, within an hour UI team reaches
| out to him to gather more info and the next post is a criticism
| of their handling!
|
| What's wrong with people? I think 1 hour response to a forum post
| isn't unreasonable or am I wrong?
| jbverschoor wrote:
| And nothing for 16hrs. So probably there is something wrong.
| And it's seems pretty critical. Status page doesn't show
| anything
| WesolyKubeczek wrote:
| I don't know if it's expected of status pages to signal
| security incidents and bugs if you technically can still use
| your (and other people's) console.
|
| (Putting on buck teeth and fidgeting with something) But but
| but akchyually, it's not an outage, you see.
| PeterisP wrote:
| If other people can access your console, then this feels
| like a case where it's negligent not to have an intentional
| outage, shutting down all remote access to all cloud
| consoles until this is fixed.
| Petersipoi wrote:
| Why would users want them to advertise a vulnerability on the
| status page before the issue is fixed? I would want them to
| keep this as quiet as possible until the issue is resolved.
| x0x0 wrote:
| To enable workarounds and/or stop the bleeding.
|
| There's many places where no network is strongly preferable
| to network that could be open to hackers.
| JAlexoid wrote:
| I mean... It's not even "no network". Once the management
| connection is severed the network equipment doesn't stop
| operating at all.
| Ekaros wrote:
| All users should be informed so they can decide if to pull
| the plug or not on their devices...
| alsodumb wrote:
| Nothing's wrong with people angry about this. What's wrong with
| the company letting it happen in the first place?
| bastardoperator wrote:
| If someone was actively stealing your car, and 911 told you
| they're an hour out, would that be acceptable? Having carte
| blanche access to someone else's network equipment seems like
| the highest emergency a company like Ubiquity could have.
|
| I don't know if the time frame is acceptable, but I know I
| would have reached out to the customer versus waiting around
| for a DM once the alarm was rung.
| wannacboatmovie wrote:
| > If someone was actively stealing your car, and 911 told you
| they're an hour out, would that be acceptable?
|
| In Seattle they don't even show up anymore, they tell you to
| fill out a form online...
| simfree wrote:
| You have to search the streets yourself and be your own
| advocate if you want to recover your stolen car.
|
| In the last 8 years SPD has become completely unmotivated
| to do their job despite never having their budget cut.
| Adjacent police departments like Kirkland and Lake Forest
| Park are much more willing to do their job, but they fire
| officers who don't do their job, while SPD retains these
| caustic, non-performing officers.
|
| So long as we let our officers in Seattle getaway with
| billing fraudulent hours that weren't worked, ignoring core
| job duties, and slow rolling the duties that they do do, we
| will be stuck with an ineffective police force.
| ImJamal wrote:
| >In the last 8 years SPD has become completely
| unmotivated to do their job despite never having their
| budget cut
|
| The budget was absolutely cut.
|
| https://apnews.com/article/business-police-
| seattle-6730ec66e...
| Arnavion wrote:
| >The Seattle City Council has approved a 2022 budget that
| cuts police department spending from previous years [...]
|
| 2022 was not 8 years ago.
| ImJamal wrote:
| I do not read "In the last 8 years" as 8 years ago, but
| within in the last 8 years. Do you read it differently?
| Arnavion wrote:
| In your interpretation the number 8 has no significance
| in that sentence, since "In the last 1000 years" would
| have the same meaning.
| ImJamal wrote:
| I could say the exact same thing for your interpretation.
| Why not just say 1000 years ago the budget wasn't cut? It
| would have the same meaning. Oh wait, it wouldn't have
| the same meaning because 8 and 1000 years are quite a bit
| different.
|
| 8 years is probably not meaningless for the poster. He
| probably moved there 8 years ago or had his car stolen
| back then and is saying nothing has improved since then
| despite there being no budget cuts.
|
| It makes no sense to say in the last X years if the poser
| just mean X years ago. It would cause unnecessary
| confusion.
| Arnavion wrote:
| >I could say the exact same thing for your
| interpretation. Why not just say 1000 years ago the
| budget wasn't cut? It would have the same meaning.
|
| Because it would not have the same meaning. The point of
| the phrasing is that the time the Seattle PD stopped
| being motivated to do their job was close to eight years
| ago, and they have continued to be unmotivated since
| then.
|
| "1000 years ago the budget wasn't cut" does not convey
| that information.
| ImJamal wrote:
| If the poster meant 8 years ago they stopped being
| motivated he would have just said that. The post didn't
| say that. You are just tangling yourself in word play to
| try to get the post to mean something different than it
| does.
| djohnston wrote:
| You're parsing this incorrectly mate. "In the last 8
| years" means in any of the last 8 years, which is
| different than in the last 1000 years.
| hobotime wrote:
| The SPD has lost hundreds of officers and hasn't recouped
| them.
|
| "Defund the Police" has consequences.
| fwip wrote:
| The SPD has lost officers, yes, despite offering hiring
| bonuses higher than ever. This is not because they don't
| have enough money, but because the prestige of being a
| police officer in Seattle has declined.
| enumjorge wrote:
| While defund the police was ill-though out, let's
| remember that it was a response to the continued use of
| excessive use of force by police. As one of the parent
| commenters said, SPD has a poor track record of
| disciplining misconduct of their officers. People will
| take increasingly desperate measures if they feel like
| they're not being heard. The idea that you'd do away with
| police was short sighted and didn't make sense since the
| beginning, but the situation SPD finds itself in is
| partially a self-inflicted wound.
| ImJamal wrote:
| The police chief is appointed by the mayor. If people
| feel like they are not being listened to or there is too
| much abuse maybe they should elect a mayor that will deal
| with it?
| fwip wrote:
| Yes and no. Traffic enforcement and dispatch positions
| were moved to another funding line item outside of the
| SPD. This was the city council attempting satisfy calls
| to "defund the police", while not actually reducing the
| amount of money allocated to policing.
|
| https://southseattleemerald.com/2023/09/14/opinion-
| debunking...
| myko wrote:
| "The new budget includes funds for 1,357 officers and SPD
| says right now, there are 1,120 officers on the force--
| which leaves 237 open jobs."
| globular-toast wrote:
| 20 years ago in school our English teacher had us read a
| science fiction short story about a robbery. I wish I could
| remember the name of it. The essential idea was that
| robbery was at some point legalised and nobody really cared
| because they just claimed on insurance. With more and more
| of our possessions being basic commodities (cars,
| electronics, IKEA furniture etc.) and everything of
| importance being digital, this seems to be coming true now.
| bell-cot wrote:
| From very dim memory:
| https://en.wikipedia.org/wiki/Flatlander_(short_story)
| olyjohn wrote:
| Anymore? They've never shown up for this kind of stuff as
| long as I can remember.
| chrisandchris wrote:
| That's not a good comparison.
|
| 911 is paid by taxes for being 24/7 available. It is also a
| public service. Ubi is free (at least I don't pay for any of
| my Unifi consoles, besides the initial cost). It is also a
| private company, free (as in beer) to do as they like.
| bentruyman wrote:
| Do you think Ubiquiti has hundreds of people on staff to
| watch their forums to triage every issue within seconds of it
| being posted? I'm curious what level of support would be
| satisfactory to you, in this instance.
| lbotos wrote:
| Not OP but you don't need 100s of staff monitoring the
| forum. You need a webhook that filters on "security" in the
| title and post it in the relevant slack channel. I do
| expect UI have a 24/7 paid support/security team and I'm
| sure _someone_ could say "uh, this looks real what's going
| on?"
| bentruyman wrote:
| Ah yes the typical engineer response of "just <insert
| system>".
| tw04 wrote:
| Yes, damn those engineers for coming up with solutions to
| problems I personally believe are unsolvable based on
| nothing but personal feelings.
|
| Ignoring the fact that flagging when certain keywords are
| posted is probably built into the forum software
| itself... I had that with phpbb back in 2001.
| bentruyman wrote:
| I just find it funny when engineers trivialize solutions
| that they themselves wouldn't employ. Like yeah, I'm sure
| your phpbb solution was a proper vulnerability reporting
| and triaging system.
| paxys wrote:
| You must not have had any dealings with the police in any US
| city if you think that they will come running in minutes if
| someone is stealing your car.
|
| There is an escalation path for security tickets at most
| large companies, and a community forum post is not it.
| bastardoperator wrote:
| You sure about that?
|
| Chicago: 3.46 minutes
|
| Los Angeles: 5.7 minutes
|
| Seattle: 7 minutes
|
| Dallas: 8 minutes
|
| Miami: 8 minutes
|
| New York City: 9.1 minutes
|
| Atlanta: 9.5 minutes
|
| Houston: 10 minutes
|
| Detroit: 12 minutes
|
| Denver: 13 minutes
| cyral wrote:
| Go on any of those city subreddits and read the stories
| of 911 not picking up or refusing to come out because
| "you can file a report online".
| bastardoperator wrote:
| That's called anecdotal evidence. I've had police come
| slow and come fast. 911 also prioritizes calls, so it's
| possible you're being rate limited by them and not the
| actual police. The data from their apps tells a different
| story, maybe they're fudging it, I just don't think
| making blanket statements about timing based on someone
| else's story gives me an accurate picture.
| cyral wrote:
| The problem is calls that are never picked up, and calls
| that are "resolved" by telling the caller that a stolen
| car is no biggie, ruin these "stats".
| SV_BubbleTime wrote:
| This is pretty simple, if you cannot be down for an hour...
| don't buy Ubiquity.
|
| Enterprise sucks a lot of the time, but this is what you are
| supposed to be paying for.
| bdcravens wrote:
| Update the status, and discuss it more in the open. Obviously
| with any security issue there's reasons to keep some
| discussions private, but it feels like they're attempting to
| minimize it, the same way a restaurant doesn't want their
| customers to hear about the mice in the kitchen.
|
| https://status.ui.com/#past-incidents still says "no incidents
| reported today"
| alt227 wrote:
| I think you are missing the point. the point is this should
| never ever happen in whats considered to be SMB enterprise
| products. Peoples businesses and livelihoods are at stake. The
| fact that it did happen is bad enough, the rest is just the
| icing on the cake. you made the point about a 1 hour response,
| howewver 18 hours after that response there is still no update
| anywhere for lots of worried customers.
|
| If Ubiquiti was my company and this post was posted on my
| forum, I would be having status messages/emails out to all my
| customers, updates on status pages, warnings on website logins
| etc. Hiding this in a private DM with a single customer is
| terrible, and they even told the world thats what they were
| doing which was a kick in the nuts.
| tw04 wrote:
| If I reported to a vendor that I had unfettered access to other
| people's cloud console, and it was the fourth such report, I'd
| expect them to shut down access to the console until they
| figure out what's going wrong.
|
| Instead, they're "looking into it" or something?
|
| I guess they'll just hope nobody does anything nefarious like
| change the passwords on every switch/router/AP they have access
| to then get remote access?
| emilyst wrote:
| Imagine being able to shut off all Ubiquiti console access in
| the world instantly, by posting about a grave security issue
| (real or not) and having a few compatriots to do the same in
| a short amount of time. You could trivially block a
| business's access to its own security cameras on a moment's
| notice, among other things.
|
| If the response to an unverified issue were "just shut
| everything down" you effectively have implemented an
| exploitable DoS in your own incident policy.
| cyral wrote:
| I was typing exactly this when I saw your comment. This
| could very well be a real issue, but could also be a
| nefarious attack or even just incompetence. I've done
| support before and there are always users convinced that
| they are "hacked" or that we are doing something shady
| because they forgot their friend logged in on their device
| or forgot that they actually made two accounts in the past.
| tw04 wrote:
| This was posted 18 hours ago. If you can't either verify
| the user has actual access to other people's consoles (at
| which point you should be immediately turning access off)
| in 18 hours, then you should probably just close up shop
| because you have no business providing remote access to a
| can of soup much less someone's firewall.
|
| If the user in question was making it up, you should also
| have posted within minutes of discovery that the user in
| question (and multiple other people) were making false
| claims.
|
| Again, they've chosen the "we're looking into it" route
| which is always reassuring.
| kevincox wrote:
| > If you can't either verify the user has actual access
| to other people's consoles [...] in 18 hours, then you
| should probably just close up shop
|
| It's impossible to prove a negative. Maybe they believe
| that this was user error/malice but are doing more
| research to confirm this and find evidence of a
| vulnerability.
| tw04 wrote:
| >It's impossible to prove a negative. Maybe they believe
| that this was user error/malice but are doing more
| research to confirm this and find evidence of a
| vulnerability.
|
| So it's impossible for me to prove that nobody has walked
| through my front door today? I'm quite confident it
| isn't. I'm also confident if they have sane logging in
| place, they can prove accounts weren't being accessed by
| unauthorized users.
|
| You're also talking in vagaries like they're hunting a
| ghost. They've been interacting with a willing end-user
| who originally reported the error.
| judge2020 wrote:
| For what it's worth, all reports and screenshots of this
| seemed to have happened within the same hour, so it might've
| been fixed quickly. I definitely would expect this to get a
| public postmortem within 48 hours, though (maybe Cloudflare
| has ruined my postmortem timeline expectations).
| meltyness wrote:
| This place has quite a rap sheet.
|
| https://news.ycombinator.com/item?id=29411775
| https://news.ycombinator.com/item?id=9331512
| https://www.reddit.com/r/Ubiquiti/comments/t7br4a/since_the_...
| magicmicah85 wrote:
| Do they by any chance use a CDN for their cloud console? This has
| burned organizations so many times before where they cache the
| dynamic data and not static data.
| twisteriffic wrote:
| I wouldn't expect to be able to administer the resources if
| this was just a caching issue. Seeing them yes, administer them
| no. Unless their authx design is tragically bad.
| bink wrote:
| "Full Access" could mean a lot of things. I don't see
| anything suggesting they could make changes (though I haven't
| read the entire thread). The user could just assume they have
| full access because they can see everything.
| fotta wrote:
| there was a comment in one of the reddit threads that
| someone was able to create a vlan on someone else's network
| BHSPitMonkey wrote:
| It's hard to be certain while we're just speculation, but
| a view caching bug could make it _look_ like you're
| making changes to the other user's console even if
| they're actually going to your own console.
| EE84M3i wrote:
| It could also be caching something that contains a token
| that can perform other actions. The disparate reports of
| different pages and being able to navigate make it sound
| like this is at some API level, not literally caching the
| console page view.
| twisteriffic wrote:
| This is my line of thinking. It's bonkers if that's the
| case - sign of a completely broken mindset towards auth.
| kevincox wrote:
| If your login/access token request is cached this could
| happen. But that may qualify as "tragically bad".
| pixl97 wrote:
| Yep, this would be my guess. Something like "UserID" gets
| cached per node and suddenly you're seeing the wrong persons
| data.
| larvaetron wrote:
| That was my first thought, it sounds similar to what happened
| with Klarna[1] a few years ago.
|
| [1] https://news.ycombinator.com/item?id=27301219
| cooljacob204 wrote:
| I really wish they weren't forcing everything to their cloud
| services for exactly things like this.
| snom380 wrote:
| Are they forcing people to the cloud services? (I'm still
| running without cloud enabled.)
| jbverschoor wrote:
| Remote access anything should be banned. Just use a
| VPN/wireguard.
|
| Reverse control is such a mess and the application is not the
| place to handle this
| bradyd wrote:
| A VPN is remote access.
| jbverschoor wrote:
| Of course, but it's at a different layer and it works
| differently. It's also something that can be swapped.
| chunkyks wrote:
| The hilarity that goes with this is that their VPN has been
| broken for years - android and iPhone both deprecated protocols
| that were considered insecure, but ubiquiti hasn't seen fit to
| add any others. It has been _years_.
|
| Their security posture is trash, which is unfortunate for a
| company that plays a central role in security
| SparkyMcUnicorn wrote:
| Yeah, I use Tailscale instead:
| https://github.com/SierraSoftworks/tailscale-udm
| cmsj wrote:
| I love Tailscale, but you are really then just substituting
| one company's remote access for another's. I'm quite
| certain that TS are more capable of creating a secure
| system than Ubiquiti are, but still, the principle of not
| trusting others with access to your network, is violated by
| TS.
| SparkyMcUnicorn wrote:
| It works with Headscale.
|
| https://github.com/juanfont/headscale
| michaelnoguera wrote:
| I agree that enabling any form of remote access
| controlled by a third party increases attack surface, but
| I also feel like Tailscale has earned more of my trust
| than other vendors with the quality of their past
| security responses.
|
| https://news.ycombinator.com/item?id=33695886
|
| (If anyone has examples of Tailscale incidents ending
| badly please share and I'll update my trust accordingly,
| but to date I haven't heard any.)
| fragmede wrote:
| That incident ended badly for anyone that had a Windows
| box and got 0wned. Tailscale's response was good, but my
| trust in the software they produce was damaged by that
| incident. I'm a current Tailscale user (esp with their
| AppleTV app), but that incident wasn't good.
| WillPostForFood wrote:
| https://help.ui.com/hc/en-us/articles/7951513517079-UniFi-
| Ga...
|
| They do now support Wireguard and OpenVPN in addition to
| L2TP. OpenVPN looks like it is only available on newer
| hardware though.
| InTheArena wrote:
| Just stop.
|
| OpenVPN and Wireguard work fine. I am using it right now.
| bink wrote:
| AFAIK you can disable remote access via their cloud. I do think
| they still force you to use the cloud credentials for internal
| access, however.
| cmsj wrote:
| I think you need at least one ui.com user, but you can also
| add local users. I control my unifi stuff through a local
| admin user.
| InTheArena wrote:
| no. you can use a local account.
| ubiquitithrow wrote:
| Ex Ubiquiti employee here. I barely recognize the company any
| more. The company always had problems but we had a lot of smart
| and hard working peopl in the early days. People are always
| amazed when I tell them how small the company was when we made
| Ubiquiti and UniFi into household names among nerds.
|
| Some of those people remain. UI-Marcus in that link is a good
| person. The company went into a steady decline after the CEO
| started centering the company around the offices in Portland and
| China. Portland was home to the UX designers who wanted to
| redesign everything to look nicer but didn't understand how
| customers used our products. Portland was also home to Nick
| Sharp, the cloud lead who tried to extort the company and lied to
| the press about hacks. The favorite office in China made the
| FrontRow product, which failed so badly that I doubt anyone has
| heard of it. These people were supposed to be the future leaders
| of the company, but everything they did was a disaster. We could
| all see the writing on the wall and left. Well, almost everyone.
|
| I don't even know which Ubiquiti office owns the cloud any more
| because everyone working on cloud at Ubiquiti either quit or was
| laid off after the cloud lead went to prison for extorting the
| company.
|
| I hope the company can get back on track some day. It's sad to
| see all of our old work decay like this.
| 12345hn6789 wrote:
| >We could all see the writing on the wall and left. Well,
| almost everyone.
|
| >It's sad to see all of our old work decay like this.
|
| This is very common. Happened at my old company. Your last 2
| paragraphs are 1-1 the experience of many of my coworkers and
| I. Very, very sad.
| aurareturn wrote:
| I hooked my home up with 3 Unifi AC Pros + ERPOE5 in 2015/2016.
| They've been running for 8 straight years without ever
| restarting. Never had a problem.
|
| Granted, I never updated the firmware in the 8 years. Heck, I'm
| not even sure how I can get back to the web UI to control them.
| wil421 wrote:
| Use the Unifi phone app to manage them. You can manage the
| APs themselves without logging into anything. I'd recommend
| updating the firmware after 8 years, you can always do a hard
| reset to get the original back.
| SparkyMcUnicorn wrote:
| Hard reset will not automatically downgrade the firmware.
|
| And I don't think it's a good idea to manage multiple APs
| using the app instead of from the controller. Managing a
| single AP from the app is ok, but I think you'll run into
| problems when you have multiple in a network.
| aaronax wrote:
| It is unlikely that a home user has network functions in
| use that rely on the controller.
| SparkyMcUnicorn wrote:
| My point still stands for multiple APs.
|
| For example, you can't set up meshing from the mobile
| app. Best you can do is give them all the same
| SSID/password, and they also have to be wired in that
| scenario.
| TheNewsIsHere wrote:
| Hard agree. Especially if you have something like the
| UDM/UDM-P and are managing VLAN-specific SSIDs and so
| forth.
| sonicanatidae wrote:
| Its fine to use at home, but I see a lot of people pretend
| these are Enterprise devices and use them as such. They are
| upgraded consumer gear, at best, imo.
|
| Source: I've been working with unifi gear for the past 4+
| years and use a basic unifi setup at home, since it was free
| to me. I wouldn't have bought it.
|
| Like all things, YMMV. I'm glad to hear its working like you
| need it to.
| notyourwork wrote:
| What would you have a bought instead? In my experience
| there isn't anything comparable in the consumer space. I'd
| love to be shown I'm wrong. I use both their network gear
| and security setup (door bells, cameras).
|
| I'm not sure there is another company offering the same
| solution with ease of setup and low overhead to manage. Is
| there?
| gene91 wrote:
| That sound like a terrible workplace.
|
| For your own home, if not Ubiquiti, what do you use nowadays?
| lotsofpulp wrote:
| Not the person you replied to, but I like Aruba Instant On.
|
| https://www.arubainstanton.com/
| aetherspawn wrote:
| Looks good but lacks layer 3 and fiber aggregation switches
| which we use in our SMB.
| mook wrote:
| Hmm, that looks like it must be centrally managed from the
| internet? Not saying it's not an appropriate replacement
| for Ubiquiti, but that seems like an opportunity for the
| same issues to show up... something that isn't remotely
| managed might be better instead.
| lotsofpulp wrote:
| I think the "InstantOn" functionality requires internet
| for setting up, but it seems like there is a way to
| manage it locally without the use of the "InstantOn"
| functionality:
|
| https://www.arubainstanton.com/techdocs/en/content/get-
| start...
|
| Some more discussion here from years ago:
|
| https://community.arubainstanton.com/communities/communit
| y-h...
|
| Although, I imagine this type of stuff may not be made to
| work well without internet.
| hughesjj wrote:
| Tplink for aps and mini PCs for routers
| dixie_land wrote:
| TP links are cheap and well made for its price, if you
| don't care that the CCP has a backdoor to every device
| sgerenser wrote:
| I use TP link access points with my own cloud controller
| (running in docker container on my LAN) and a separate
| wired router. I don't think there's any concern with
| access points "phoning home" in this configuration.
| depingus wrote:
| > the CCP has a backdoor to every device
|
| This is huge! Please link me to the evidence to back this
| up.
| mike_d wrote:
| China deploys plausibly deniable backdoors into
| internationally shipped network devices. Bugs that are
| remotely exploitable if you know they exist, but not
| obvious enough that they provide justification for the
| devices to be banned from import. These consumer devices
| are not exploited for intelligence gathering, but rather
| deployed as proxies that fall into one of two common
| buckets: acting as SOCKS proxies to relay attacks, and
| allowing a remote operator to scan for nearby wireless
| networks and bridge into them.
|
| The NDAA blacklist was a happy compromise by the US
| government of banning the most egregious vendors that
| might find their way into sensitive facilities (Huawei,
| Hikvision, etc) while letting consumer focused brands
| that do the same (TPLink, Jetstream, Wavlink, etc) slip
| by so it didn't appear at face value to be a blockade of
| all Chinese made networking gear.
|
| Taiwan on the other hand is less concerned about how
| China perceives their relations and bans all these
| vendors. They also ban Zoom.
| jstarfish wrote:
| It'd be easier to just Google it.
|
| Grievances start with "made in China" and end with
| firmware hacks from May of this year.
|
| https://blog.checkpoint.com/security/check-point-
| research-re...
| depingus wrote:
| "We are unsure how the attackers managed to infect the
| router devices with their malicious implant. It is likely
| that they gained access to these devices by either
| scanning them for known vulnerabilities or targeting
| devices that used default or weak and easily guessable
| passwords for authentication"
|
| This implies the opposite of "the CCP has a backdoor to
| every device". Vulnerable devices from all manufacturers
| get exploited like this all the time.
| jandrese wrote:
| I've had pretty bad luck with TPLink APs temporarily
| dropping connections and being just generally unstable.
| Even when you can put OpenWRT on them the hardware is just
| kinda buggy.
| depingus wrote:
| I think OP means the Omada EAP's, which are dedicated
| access points and not the routers. I have 2 EAP225's that
| have been better than the Ubiquiti it replaced.
| scrlk wrote:
| I've been considering MikroTik recently (specifically the
| RB5009 series). Main downside I've read about so far is that
| the UI/UX is a bit rough.
| bastard_op wrote:
| You think the UI is rough, try the cli.
| carlhjerpe wrote:
| There's a learning curve indeed, but it's also
| essentially just a thin wrapper around nftables (read
| iptables) so you learn about Linux networking by using
| them
| bastard_op wrote:
| I've been using unix and linux since the 90's and linux
| full-time on every system of mine, and Tik's still seemed
| entirely counterintuitive to me. I'd rather just deal
| with iptables and linux directly without the wonky cli.
| sonicanatidae wrote:
| I prefer the cli for Mikrotik, but that's true for most
| firewall, routers, etc.
|
| YMMV.
| doubled112 wrote:
| I actually found the Mikrotik CLI easy to learn because
| it and the GUI are basically 1:1.
|
| For example:
|
| /ip/firewall/filter add
|
| is in the UI under the sidebar IP -> Firewall, then the
| Filter tab, then click add. The parameters are named the
| same in both too.
| lbotos wrote:
| I have a mikrotik https://mikrotik.com/product/hap_ac3 that
| I bought as a sort of test and it's been working fine for
| my needs. the webUI isn't the best, but wiki docs were
| pretty straightforward and I've been decently happy.
| cyberax wrote:
| I don't get all the Mikrotik UI hate. It's not winning any
| beauty contests, but it's straightforward and it works
| well.
|
| I've been using their devices for years, and I haven't had
| any problems setting them up.
| favorited wrote:
| There are some really terrible UI choices in SwOS, like
| not labeling rows of checkboxes so users need to hover
| over each one with their mouse to see a tooltip.
| deep_origins wrote:
| Anyone using Mikrotik these days? Been Mikro-curious for
| awhile and always see them thrown around as a Unifi
| alternative. Yet to hear of any firsthand implementations
| though.
|
| [0] https://mikrotik.com/
| sam_lowry_ wrote:
| I have half a dozen Mikrotik hAP AC and wAP AC devices with
| Openwrt used in various places for work and for home.
|
| Rock-solid hardware and muuuch better UX that RouterOS.
|
| Don't remember when I setup those, but probably well before
| Covid. Really fire-and-forget devices.
| bastard_op wrote:
| As a network engineer, I've considered them for my house,
| the price is right, but:
|
| 1) Their main push seems to use a thick client for admin
| which is a big no to me, otherwise the web ui in theory
| looks ok-ish. 2) Looking at their cli guide, it was cryptic
| as hell to me, and I deal with everything from cisco,
| arista, aruba, juniper, fortinet, pan, whatever from a cli
| or gui.
|
| This was mostly confirmed a few weeks back, another old
| network engineer friend of mine hit me up asking if I've
| ever dealt with Mikrotik, and said no, but I knew where he
| was going. He'd screwed with it for a day or so supposedly
| just trying to make some L3 vlans, and finally a day or so
| later told me he'd made it work, but has never dealt with
| anything so terrible to configure from either gui or cli
| after having tried both, and he's another 20yr+ network
| engineer like me I trust not to be stupid.
|
| That was all I needed to hear for future consideration.
| snuxoll wrote:
| Mikrotik has had WinBox for as long as they've been
| around and there's a lot of inertia around using it, but
| WebFig and the CLI are the only things I use (though I do
| have The Dude running through Crossover because it's
| useful).
|
| Where you run into problems with 'tik gear is the
| differences that L3HW acceleration introduced into the
| mix. They didn't do what every other switch vendor does
| and limit features to what the switch chip supports and
| hide everything that the CPU can't handle away, so you
| have multiple ways of approaching most issues which threw
| me for a look as somebody who had been running JunOS gear
| in his lab for a while.
|
| Once you get a feel for it then it's pretty
| straightforward to work with everything, though somebody
| used to an older generation of NOS like classic IOS (and
| associated clones) would have an easier time than me.
|
| For reference, here's the config for my CRS317 acting as
| my "core" switch: https://gist.github.com/snuxoll/d63a155
| aa2155f53736a99d1cb27...
| qmarchi wrote:
| Their "thick client" (aka Winbox) is effectively
| replicated in the web UI at this point.
|
| Yeah, the CLI is a bit weird, but it's built on the same
| API calls that the web UI makes. So they're oddly
| consistent.
| ahoka wrote:
| What does "L3 VLAN" even mean?
| radiowave wrote:
| For sure, VLAN config is one of the most extremely "How
| and why did anyone end up designing it this way?"
| thought-inducing areas of Mikrotik config.
|
| But I will say that the boxes of theirs that I bought
| about ten years ago are still going strong, never had a
| device fail on me, still receiving OS updates, still able
| to export and re-import my config to any of a wide
| variety of newer devices when the time comes.
|
| Clearly they're not the right choice for everybody, but
| there are certainly up sides, if you're willing to
| grapple with the config.
| seany wrote:
| Ruckus 730/750/850 with unleashed firmware
| tekla wrote:
| Aruba. Some jank in the software, but the gear has been rock
| solid
| sl360 wrote:
| The Instant-On gear is physically almost identical to the
| professional line, but with heavy software limitations.
|
| Best built hardware I've used, and I'd still be using their
| PoE at home if they didn't patch out SSH/REST access a few
| years ago.
| allarm wrote:
| Not sure if they sell it outside of EU, but Keenetic is
| absolutely awesome. Been using their routers for a while,
| have a wifi mesh configured in my home built on their
| devices.
|
| https://keenetic.com/en
| alt227 wrote:
| Draytek routers are not perfect, the UI lacks polish, but I
| have never had one fail on me yet. Solid kit (even though you
| do need to keep up with the firmware updates to keep them
| secure)
| sunbum wrote:
| While I havn't been keeping up with what was going on, the
| second I started seeing ads for ubiquti I knew something had
| gone deeply wrong.
| chewmieser wrote:
| Hadn't heard of FrontRow (as you assumed) so went looking for
| information about it and it looks like they may have repurposed
| it for the Access Reader Pro? Haha that's a way to move them.
|
| What a miss... And weird product category for them...
|
| Also interesting, apparently Ubiquiti came out with a video
| editor too around that time for FrontRow:
| https://www.reddit.com/r/Ubiquiti/comments/t9jz2n/ubiquiti_l...
|
| Curious - what was the size of Ubiquiti when "we [you and your
| tean] made Ubiquiti and UniFi into household names among
| nerds"?
| callumjones wrote:
| Wow, I always wondered why the Access Reader Pro had such a
| weird design - it was just a repurposed product from a
| completely different catagory.
| teruakohatu wrote:
| Here is the FrontRow website from 2017:
|
| https://web.archive.org/web/20170929122826/https://www.front.
| ..
| qwertox wrote:
| > Portland was home to the UX designers who wanted to redesign
| everything to look nicer but didn't understand how customers
| used our products.
|
| MirkoTik has also been updating their UI this year and it's
| only getting worse.
|
| They are starting to put everything into auto-collapsed
| sections so that instead of just scrolling down the page you
| now must remember the section's title and open it in order to
| access the controls. There are hundreds of sections.
| cmsj wrote:
| Mikrotik's UI was terrible to begin with, just a big 90s
| smorgasboard in the style of My First Visual Basic App.
| karolist wrote:
| The Dude. edit: more context, that's the Win UI manager
| with the 90s look for MikroTik. It's not pretty but I know
| fairly large ISP admins swearing by it
| https://mikrotik.com/thedude
| dishsoap wrote:
| I like it, it just works and everything in it makes sense.
| Very refreshing compared to a lot of the things we have
| today.
| vetinari wrote:
| Winbox UI might be not according to the latest UX fashion,
| but is pretty effective.
| lencastre wrote:
| Some people like VB6 and its aesthetic.
| bogantech wrote:
| Webfig I presume?
|
| The first rule of webfig is: don't use webfig
| qwertox wrote:
| There were no issues with Webfig.
|
| These newly collapsed sections are tabbed sections in
| WinBox, so there you've had the problem since the
| beginning.
|
| It's a matter of preference and I've always preferred
| Webfig. I'm a MikroTik user since 2013 and have 9 devices
| which I like a lot. I only used WinBox when I misconfigured
| them a bit in order to access them via the MAC address.
| sgt wrote:
| Makes it useful for someone who doesn't really use Mikrotik
| a lot to be able to browse through and explore.
| jbverschoor wrote:
| > Portland was home to the UX designers who wanted to
| redesign everything to look nicer but didn't understand how
| customers used our products.
|
| That means they're not UX designers, but simply illustrators
| without actual illustration skills
| robertlagrant wrote:
| Or they're UX designers without actual UX design skills?
| LeoPanthera wrote:
| I bought a FrontRow! I loved it! It still works, although the
| battery doesn't hold much of a charge anymore.
|
| It always seemed funny to me that the door access readers re-
| used the case from it.
| giobox wrote:
| Is it true the failed FrontRow hardware was repurposed into the
| Unifi door fob scanning thing/product ("Access Reader Pro")? I
| recall reading this somewhere, and the hardware appears to be
| identical:
|
| >
| https://www.theverge.com/circuitbreaker/2017/8/15/16146354/f...
|
| > https://c3aero.com/products/ua-pro
|
| I was absolutely floored when I saw the announcement of the
| FrontRow device - what a bizarre thing to have brought to
| market for a network hardware company. I can only imagine
| someone somewhere got far too caught up in the "wearable" hype
| a few years ago.
| fest wrote:
| I can't really go into details, but FrontRow wasn't the most
| bizarre thing Ubiquiti was working on, just the one that got
| reasonably close before being shelved.
|
| IIRC Access reader isn't the only product the FrontRow R&D
| cost/stock of parts was tried to be recouped, but at that
| time I wasn't working there anymore.
| sonicanatidae wrote:
| How many years now has it been since Unifi implemented broken
| VPN and won't fix it?
|
| 5, by my count and still climbing.
| adamjc wrote:
| > Portland was home to the UX designers who wanted to redesign
| everything to look nicer but didn't understand how customers
| used our products
|
| I think that's every single piece of modern software to date. I
| call them "Dribbblrs", because it's like they take inspiriation
| from these websites (e.g. Dribbble) that fetishize things that
| look pretty but are dogshit to use. I really wish it would end
| but I don't see it happening unless there's a revolution from
| within the UX community (which I am not a part of).
| jonathantf2 wrote:
| It's a weird one because they had a decent product line and
| just seem to be making really weird choices - I assume to
| market to the home/"pro-sumer" crowd instead of actual
| businesses? They just came out with a network switch with RGB
| for damnsake.
|
| A few of my IT clients have UniFi routers and they're quite
| lackluster for the price - pretty UI but loads of broken
| features and bugs galore, and you can't manage them centrally
| like the rest of the UniFi kit.
| hkchad wrote:
| > a network switch with RGB for damnsake.
|
| This actually my turn out to be VERY useful. As someone who
| runs Unifi at home w/ a stupid amount of VLans, being able to
| color code them at the switch will come in real handy when I
| just go and start unplugging stuff and rearranging as does
| happen. If they update it to flash VLan color while unplugged
| using the LCD screen it will be even MORE useful. We can hate
| on RGB all day just for RGB sake but when it has a use, more
| the better.
| dclowd9901 wrote:
| Damn, I interviewed there a while back and turned down an
| offer. Kinda glad I did now.
| fest wrote:
| Can you weigh in on the decision to require UniFi controller
| instead of providing on device configuration interface as well?
| AlexandrB wrote:
| That was part of the UniFi product since day 1, no?
| fest wrote:
| Yes, but I always found it strange (though I lack any
| exposure to "enterprise" networking equipment).
| baby_souffle wrote:
| It makes good sense for large distributed deployments.
|
| One page to update everything rather than have to connect
| to each device and push a config. The controller also
| "back-ports" the configuration as appropriate for a given
| device. Declare a vLan once, don't have to worry about
| which cli version is running on a given switch and adjust
| your command accordingly.
|
| These things don't matter much when you only have one
| physical location / few devices but if you're an IT guy
| that manages networking across every physical building in
| a school district...
|
| Since the device tries to phone home, it's also a NAT
| buster which is invaluable when you're drop-shipping
| equipment to customers and have little control over your
| environment but need to be able to promise some level of
| functionality.
| xoa wrote:
| > _I hope the company can get back on track some day. It 's sad
| to see all of our old work decay like this._
|
| Agreed, and it really was amazing work. As someone who started
| using and then deploying UniFi in maybe 2015-2016ish and found
| it a revelation, it's been tremendously depressing see so much
| potential and such a community utterly squandered. I can only
| imagine what it's like for someone on the inside. Nevertheless,
| thank you so much for your work and all the others who helped
| make it happen. If nothing else it did at least really blaze a
| trail and show what could be done, and contrary to this issue
| without any cloud bullshit and subscription lock-in. Even were
| Ubiquiti to truly implode, that showing of what could be done
| would remain and by its nature the kit would remain useful for
| a long time.
|
| There have been some mildly positive signs recently though,
| even if the UX churn remains shitty. There has been small
| shoots of progress on actual core features, years and years and
| years late granted, but not entirely too late. I wonder if the
| emergence of TP-Link's Omada as a clear, direct same-niche
| competitor has lit any fires there?
| neilv wrote:
| Why did Ubiquiti open product/engineering offices in China?
| syntaxing wrote:
| I really wish there was an open source equivalent that's user
| friendly. I run OPNSense but the learning curve is steep and I
| wouldn't recommend it to family because of it. I've been debating
| Firewalla but this same issue can happen since the control panel
| is cloud based.
| Arnavion wrote:
| Well, since we're talking about delays in security responses,
| OPNsense is in the same boat.
| https://news.ycombinator.com/item?id=34839161
| ojfkwai wrote:
| I have a lot of complaints about OpnSense. But how exactly is
| that a similar security response?
|
| That wasn't a security incident for OpnSense. It was a CVE
| for an optional package most users probably don't have
| installed. Sounds like not-an-emergency to me. That user is
| completely unreasonable. Opnsense should refund their money
| (if any lol) and tell them to pop off.
| Arnavion wrote:
| >That wasn't a security incident for OpnSense. It was a CVE
| for an optional package most users probably don't have
| installed.
|
| First of all, the point is that the OS didn't release CVE
| fixes for the packages in its repositories even though it
| had already committed those fixes to version control.
| Notice that my comment specifically talks about "delay in
| security response", not that it was an "emergency".
|
| >That user is completely unreasonable. Opnsense should
| refund their money (if any lol)
|
| Second, I recommend reading the comment you respond to
| carefully before you rush to make an account to respond to
| it. "That user" is me. The GH thread has a clear comment
| from me that I did not pay them any money and do not have
| any expectation of support.
|
| Third, notice that the point of the GH thread was me asking
| what their policy of releasing CVE fixes was. You seem to
| think I was some Karen complaining that they hadn't
| released the fix. All I asked was a confirmation that
| they're aware that they're shipping a package with a CVE,
| that they've already fixed the package but just not
| published it, and what their policy is for releasing fixes
| in general.
|
| They could've responded with something like "We're aware of
| the CVE but we don't plan to release the fix in 23.1. Our
| policy is to only release bugfixes for non-critical
| packages in the next stable release, and we consider os-
| haproxy to be a non-critical package."
|
| Instead they got weirdly defensive about it, tried to
| lecture me about how OS releases generally work, called me
| "rude" (ironic), and locked the issue.
|
| The ultimate point is that OPNsense delays security fixes.
| Maybe you think it's okay because you think some OS
| packages are critical and this one wasn't. Maybe you think
| if an OS can't articulate its security fixes release policy
| without getting combative, then it's hard to take its
| security seriously. The decision is yours.
| radicality wrote:
| If it was open source, would you recommend Unifi to your
| family? I feel like family will either be technical enough to
| understand OPNSense, or not technical at all at which point
| even Unifi is not something they'll manage themselves.
|
| I actually run OPNSense for myself at home, but for my parents
| I deployed full Unifi. This way if there's any problem, I can
| remotely look at the network in the cloud console and try and
| see what's wrong.
| kube-system wrote:
| > I feel like family will either be technical enough to
| understand OPNSense, or not technical at all at which point
| even Unifi is not something they'll manage themselves.
|
| Agreed. Major ISPs in the US (and I presume many other
| places) offer routers that work well enough to satisfy the
| requirements of any non-technical household and often come
| with provisioning/troubleshooting features that enable the
| ISP to provide technical support if necessary.
|
| In the old days, ISP-provided devices often lagged behind
| other consumer or prosumer network offerings, and it made
| sense to swap them out... but that's not really the case
| today. Today, swapping out the ISPs router is probably going
| to make a non-technical user's life harder, unless they have
| someone technical to manage it for them.
| olyjohn wrote:
| ISP gear is still trash. It's just better for the user,
| because the ISP won't bitch and moan and tell you your
| hardware is unsupported.
| kube-system wrote:
| "Trash" is subjective.
|
| Satisfaction happens when a product or service meets the
| user's requirements. A new Cisco catalyst setup may be
| technologically superior to my mother's ISP provided
| router, but it might not make it easier for her to play
| Candy Crush on her iPhone if she forgets the wifi
| password.
| olyjohn wrote:
| I suppose you're right. Just after seeing my family lose
| internet a bunch of times due to the ISP supplied router
| just straight up failing, I don't have much confidence in
| the hardware. Also I don't think that rebooting the
| router once a week because it's frozen makes it a quality
| product that brings satisfaction. I've never seen an ISP
| supplied router that isn't like this. But that could just
| be my personal experience.
|
| I mean, when the first thing you hear when you call your
| ISP, is to "reboot your router" on a recorded message,
| doesn't that throw a red flag to anybody else? I don't
| use high end gear at home like Cisco, either, but it has
| never needed a reboot.
| x0x0 wrote:
| No, AT&T is still shipping with a router that cannot hit
| more than 50% bandwidth on any of 3 devices from under 5
| feet. With one wood + pressboard wall between me and the
| router, 25%.
|
| This is symmetric gigabit product, but still.
| kube-system wrote:
| You've described a technical problem, not a non-technical
| problem.
|
| I'm not familiar with that device, but a non-technical
| user might not care about that "problem", as long as
| their device does the task they are intending to perform.
| fragmede wrote:
| The problem is being described technically, which is more
| useful than the non-technical description of the problem,
| which is "I don't know, the Zoom isn't working, and the
| kids can't watch their Netflix at the same time".
| kube-system wrote:
| Yes, but Zoom and Netflix will work great on 50% or 25%
| of 1gbps. Heck, they'll work great with 5% of 1gbps.
|
| I am sure that AT&T's CPE equipment is lackluster, but
| that doesn't mean it won't work to do basic tasks to the
| satisfaction of a home user.
| x0x0 wrote:
| I dunno what to say, but it does not do basic tasks to
| the satisfaction of people who buy 1gb internet
| connections.
|
| I can tell you from experience that large downloads and
| uploads cause latency-sensitive applications to stutter
| in a way that is fixed by using ubiquiti gear.
|
| In your defense, you did say non-technical household, but
| I dunno -- I don't think that wanting to use, eg,
| backblaze for backup and not have that tank zoom makes
| you a technical household.
| syntaxing wrote:
| I think UnifiOS is pretty straight forward (at least for my
| generation). I don't think I would recommend it to my parents
| but I did to a sibiling and they managed to setup their own
| system with only a little bit of help from me. I also sent
| them the awesome lazy admin VLAN guide which helped a ton.
| bityard wrote:
| I'm pretty bad at coming up with business ideas, but one that I
| think would work, if I ever got the time to do it, is a user-
| friendly x86 router firmware centered around the idea of making
| it as easy as possible to set up and control your network and
| its devices.
|
| On my home network, what I really want is the ability to define
| one or more networks (VLANs, if you will) and then place
| devices in those networks. When you click on a device, you are
| then able to do things like give it a static IP, look at the
| traffic it's generating, shape its traffic, disallow traffic
| from/to certain ports, kick it off the network at certain times
| of day, allow it access to the local network but not the
| Internet, change its DNS resolvers, etc.
|
| In order to do these things on most routers, if they offer the
| ability at all, you need to jump around to different places in
| the UI and manage each service as its own thing. OPNSense is
| great (and it's what I currently use) but it's UI is really
| just multiple little windows into the various sub-services that
| the firmware provides. Separate page for _all_ the firewall
| rules, another for _all_ the DHCP leases, etc. It works, but it
| 's kind of frustrating to use, especially when you're not
| digging around in it every day.
|
| The business model would be: everything open source, but three
| "tiers" of releases: 1) free "beta" releases featuring new and
| lightly-tested features for the adventurous. 2) "stable"
| releases via subscription (paying customers have access to the
| source code and build tools) 3) "freeloader" releases, the same
| as "stable" but with a 6-9 month delay.
|
| Devil is in the details of course, but if I had any
| entrepreneurial bent at all, I think it would be a big
| improvement over the current state of things.
| stusmall wrote:
| One possible explanation for this can be a mistake in caching.
| While it is tempting to log in and see if you can see other
| people's consoles... that just might put you in the cache for
| someone else to see.
|
| There is no way for us to know what is causing the bug and what
| will help without official word for Ubiquiti but logging in can
| only possibly hurt and won't help.
| SigmundA wrote:
| Yeah seems like a caching issue where the cache isn't properly
| segmented by user.
| tomkinstinch wrote:
| For anyone with a UDMP looking to disable remote access via UniFi
| servers, the setting isn't under the Network application, it's
| part of the higher level console management:
|
| Console Settings (menu on left) -> Advanced (heading) -> "Remote
| Access (checkbox)"
|
| Or via: https://$UDMP_IP/console-settings
|
| (Hopefully the setting applies locally...)
| cmsj wrote:
| And note that to see the Remote Access checkbox, you need to be
| logged into the console as a ui.com user, not a local user.
|
| If you have disabled Remote Access and instead want to use the
| phone app via a VPN, you may have to add it manually. There's a
| (+) button for that, and then a "Need help?" option, which
| contains a way to manually add by IP/user/password.
| _rs wrote:
| If only you could do this with the Protect app...
| twisteriffic wrote:
| Had a "is this actually your local console?" Prompt from protect
| this morning. I'm getting a bad feeling about this.
| awill wrote:
| I have a few unifi things at home, and for the most part, they've
| been good, and work well together. But this sort of stuff is very
| concerning, and forcing the cloud account on everyone is really
| stupid.
|
| But what are the alternatives. Firewalla seems to be a good
| alternative, but they don't do APs, leaving me with a mixed
| system.
| elteto wrote:
| Using the cloud is not required, you can set everything up with
| local access. Certain products, like Protect, do require cloud
| access. But not the base networking stuff.
| latentcall wrote:
| I use a Firewalla with TP-Link Omada AP's, works great. Don't
| really mind the mixed system aspect. Recommend!
| awill wrote:
| why not use an Omada gateway/router too?
| apearson wrote:
| From I remember Firewalla (app only) is more dependent on the
| cloud than Unifi
| miles wrote:
| > Firewalla seems to be a good alternative
|
| https://old.reddit.com/r/firewalla/comments/14gf1j1/major_se...
|
| https://old.reddit.com/r/firewalla/comments/177egzl/summary_...
| zzzeek wrote:
| im running unifi here and I've never dealt with any of this
| cloud stuff, there's a checkbox called "enable remote access"
| that defaulted to false for mine and I'd never check that box,
| so hopefully it's not actually "forced" ?
| Macha wrote:
| My decision to not enable remote access feels vindicated now.
| throwaway202312 wrote:
| If I had to take a guess they might be using a CDN like
| Cloudflare and temporarily misconfigured a cache rule...
| freedomben wrote:
| When people ask me why I don't use Ubiquiti products, and I tell
| them that I don't trust companies with closed/proprietary
| offerings with something as critical as this, I get a lot of
| skepticism and even eye-roll. Open source isn't a silver bullet,
| but if I were self-hosting my own "cloud" controls I wouldn't be
| worried about something like this.
| luckydata wrote:
| honest question, who do you trust that provides either high end
| residential or SMB type networking gear that works well? The
| average residential stuff is all garbage and I was looking into
| unifi because seems to work better but I'm open to suggestions.
| aftbit wrote:
| I personally run a bunch of obsolete Aruba, Juniper, and
| Ruckus gear at home. It works pretty well, doesn't cost very
| much, generally doesn't require licenses or cloud, and
| supports every feature under the sun. The only problem is
| power consumption, but I don't mind burning ~200W on my whole
| house's network infrastructure.
| tokamak wrote:
| Feels like the issue Steam had with caching
| https://securityaffairs.com/43189/security/steam-users-data-...
| cmsj wrote:
| The real question here for me is: why is my data not flowing
| through Ubiquiti's servers end-to-end encrypted?
|
| They should be able to accidentally send my data to another user
| and have it merely result in a decryption failure.
| smcleod wrote:
| I think you mean encrypted at rest (data) with you holding the
| decryption key not e2e (https/tls) which is from your network
| to their network.
| rekoil wrote:
| I have been hoping for them to go this route for a while now,
| maybe eventually they will.
| calamari4065 wrote:
| I built a UniFi network 6 or 7 years ago. I was pretty excited,
| as the hardware seemed properly solid. A touch expensive, but I
| was expecting it to run forever, essentially.
|
| The hardware was actually really good from what I could tell. Not
| a single issue that wasn't caused by my own misconfiguration. But
| the software, woof. The software was designed to do exactly one
| thing: look impressive to execs in a board meeting. It was nearly
| unusable for me. I don't recall any specifics, but all you really
| need to know is that it took multiple days to get a simple home
| network with a single AP and a single router set up. It was so
| much effort just to log in to the damn thing.
|
| I went into this project excited at the prospect of all the cool
| monitoring and analytics I could do. Fancy security and remote
| access and whatnot. After I finally got everything configured, I
| never touched it again. There were a few times when I needed or
| wanted to get into it, but I couldn't remember the specific
| incantation and combination of software needed to access it, so I
| just didn't.
|
| I'd _love_ to have a solid system built on quality hardware.
| UniFi is notionally exactly what I want, and exactly what a _lot_
| of hackers and tinkerers want. But the quality of your hardware
| is pretty much irrelevant if your software wasn 't designed to be
| used by humans.
|
| So I'm stuck using consumer routers with open firmware. It's fine
| I guess.
| riley_dog wrote:
| I run OPNsense, but use UniFi hardware. I rarely ever have to
| interact with the UniFi software as it's only there to
| configure the hardware.
| aftbit wrote:
| OPNsense can target UniFi gear? Does it manage the switching
| and APs too?
| JAlexoid wrote:
| You use OPNsense as the router, but the rest of the
| equipment is managed separately.
|
| I don't know of a system that works across multiple SDN
| solutions.
| teekert wrote:
| I don't think riley_dog means they somehow controls Unify
| APs with opnsense. I think he just configured the APs with
| the Unify controller, the never touched them again and left
| all routing to an opnsense box.
|
| This seems to be a popular approach, as there are no
| attractive routers from Unify, there was the Ubiquiti Unifi
| Security Gateway (USG), which ran very hot but was
| affordable and small (EdgeRouterX-like). Now they have the
| Dreamrouter, which has everything in one, including Wifi.
| It looks like an Alexa tube. There is a gap in their
| offering if you ask me, I'm also looking for a nice simple
| 2 nic opnsense box (preferably a nuc(-like)), after I blew
| up my EdgeRouterX (used the wrong power supply).
| letitbeirie wrote:
| My situation is basically the other side of the same coin: I
| built out my network 7 years ago using _Edge_ gear instead of
| UniFi.
|
| The hardware is solid and the software isn't flashy but it's
| reliable. It's exactly what hackers and tinkerers want, so
| naturally Ubiquiti has all but abandoned the entire product
| line.
|
| They haven't discontinued it (yet) so I could still replace any
| piece of it if I needed to but their software version history
| doesn't exactly paint a picture of a product that's cherished
| or actively invested in:
|
| 2019/03/28: v2.0.1
|
| 2019/05/30: v2.0.3
|
| 2019/06/25: v2.0.4
|
| 2019/07/16: v2.0.6
|
| 2019/12/04: v2.0.8
|
| 2020/03/09: v2.0.8-hotfix1
|
| 2020/11/18: v2.0.9
|
| 2021/02/02: v2.0.9-hotfix1
|
| 2021/06/13: v2.0.9-hotfix2
|
| 2022/07/17: v2.0.9-hotfix4
|
| 2022/12/20: v2.0.9-hotfix5
|
| 2023/01/22: v2.0.9-hotfix6
|
| 2023/07/31: v2.0.9-hotfix7
| panopticon wrote:
| My EdgeRouter finally bit the dust after over a decade of
| service, and I decided to "upgraded" to a Dream Machine. I
| was hesitant due to the security breaches and now I really
| regret my decision.
| favorited wrote:
| UDMs are discounted right now for the holidays. I'm in the
| process of migrating my home networking/server stuff into a
| rack, and I was tempted to pick one up because my current
| little PFSense box isn't particularly rack-friendly. This
| thread is cooling my heels a bit.
| snom380 wrote:
| You can run your Dream Machine without cloud access,
| though?
| specto wrote:
| Believe it or not, there's a 3.0 beta now
| BitPirate wrote:
| Ubiquitis Unifi controllers and the TP-Links clone called Omada
| always remind me of the glory days of the NoSQL fad. Want to
| install our software? Please add a third-party mongodb
| repository to install an obsolete version. They can't handle
| version upgrades of their own database properly, but hey! At
| least it's web-scale.
| smileybarry wrote:
| They also need a _32-bit_ version. The actual, easiest
| solution to appliance-ify Unifi OS was to take some "run it
| on your Raspberry Pi!" guide and convert the instructions to
| Debian 32-bit.
| bmicraft wrote:
| The real easiest solution is to use a third party docker
| container
| smileybarry wrote:
| True, but I don't actually trust it. And the last time I
| tried manually building it, it didn't entirely work.
| smcleod wrote:
| But it's webscale!
| cyode wrote:
| > 6 or 7 years ago...it took multiple days to get a simple home
| network with a single AP and a single router set up.
|
| I just tried the same thing last week and it took an hour (half
| of that was mounting it to my ceiling). I only set up a WAP
| though, no controller.
| tinix wrote:
| pcengines apu platform is great if you're comfortable with
| command line. they are EOL now (no new hardware updates) but
| doing the same thing with any Linux box is trivial... plenty of
| off the shelf options for modular hardware.
| boeingUH60 wrote:
| _Random fact_ : Ubiquiti is publicly traded, yet Pera owns 90%+
| of it, meaning shareholders virtually have no power to push for
| changes. You might as well call it a privately held company, lol.
| barbazoo wrote:
| Easy to host the console yourself: https://help.ui.com/hc/en-
| us/articles/360012282453.
|
| There's even a docker image for those who have trust:
| https://github.com/linuxserver/docker-unifi-controller
| jonathantf2 wrote:
| Not if you use their "Dream Machine" line of products - you
| have to use the controller that's self hosted on the box. I'm
| currently trying to figure out how to disable the cloud
| connection on these and go back to good ol' open ports to
| manage the thing.
| erupt7893 wrote:
| I haven't tried yet but looks like this was posted above with
| how to disable cloud connection
| https://news.ycombinator.com/item?id=38644073
| Rudism wrote:
| It should be noted that the repo you linked is for a deprecated
| image that's losing support at the end of this year:
| https://info.linuxserver.io/issues/2023-09-06-unifi-controll...
|
| The note I link above discusses its replacement and how to
| upgrade.
| Khaine wrote:
| Thanks. I didn't know about this.
| InTheArena wrote:
| Eh. you don't need that for any of the hardware that appears to
| be affected. Just turn off cloud access.
| sschueller wrote:
| Ah the beauty of cloud connected networks management. A hackers
| delight...
|
| And then I am the one that gets chastised for not wanting cloud
| connected router/switches in my networks.
| MenhirMike wrote:
| Does anyone have a recommendation for a replacement? After the
| requirement to create a cloud account on their so-called "Pro"
| Dream Machine I already felt something is wrong, and after
| "Please don't use shielded Ethernet cables with our so-called
| "Professional" WiFi Access Points, they can randomly reboot"[1]
| and now this nonsense, I'm just simply done with them.
|
| But I really like the hardware of the Dream Machine Pro (Router,
| Switch with 10G uplink) and the overall view of clients and
| connected devices, so I don't just want to buy some random Router
| and pair it with random WiFi APs - though I guess that's the best
| choice?
|
| [1] https://help.ui.com/hc/en-
| us/articles/8823742725015-UniFi-6-...
| InTheArena wrote:
| There is no requirement to create a cloud account on the Pro
| machine.
| MenhirMike wrote:
| There used to be a mandatory ui.com account when it came out.
| If they finally got rid of that nonsense, that's great news.
|
| And yeah, looks like the v1.1 update removed it
| (https://community.ui.com/releases/UniFi-OS-Dream-
| Machines-1-...): "Allow to set up a console without an SSO
| account."
|
| The fact that they decided to release a "Pro" product with
| that requirement initially still counts heavily against them:
| What were they thinking, and why should I trust them if they
| are making such decisions?
| xyst wrote:
| UI just can't catch a break.
|
| Earlier this year, some tech tabloid (krebsonsecurity?) reported
| how bad security was at UI. I think it was ultimately determined
| to be a bad story and UI sued for defamation.
|
| Now we are here again with another possible leak.
| InTheArena wrote:
| This was multiple years ago at this point.
|
| this is why smear attacks work. Someone on a different hacker
| news thread today was stating that the car that blew up at the
| Canadian border was a Tesla (It was a bently).
|
| I've seen these types of bugs before. I think they introduced a
| very bad credentials or session bug. The good news is you can
| turn cloud off for all of these, and they work just fine.
| fragmede wrote:
| Or how the one fire in a Tesla in Florida following a
| hurricane became a whole fleet of every EV in Florida
| spontaneously combusting. A lie can travel halfway around the
| world while the truth is putting on it's shoes.
| op00to wrote:
| It's unlikely that simply seeing things in the main console means
| you'll be able to change things if this is a caching issue. It
| can still expose passwords and other internal information you
| don't want to get out.
| cogogo wrote:
| Odd coincidence in that I had the same problem with Ubiquity the
| 401k provider several years ago. Could see most of my colleagues
| 401k accounts. Never good.
| arcza wrote:
| Nice, yet another breach that doesn't affect me self hosting my
| Unifi controller.
| everdrive wrote:
| I feel very vindicated for avoiding the cloud solution when
| everyone was praising Ubiquiti back in 2016 or so.
| hk1337 wrote:
| I tried the AmpliFi mesh router several years ago and hated it.
| It didn't seem any better than the Arris gateway that ATT sent
| me.
|
| Why would you have a central console that has the potential for
| accessing all the routers with a single login though? Why
| wouldn't this be just local to the network with remote access?
| InTheArena wrote:
| https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misc...
| aetherspawn wrote:
| So what's the alternative for SMB... Cisco? Where can we buy this
| stuff cheap without going through an IT company..?
___________________________________________________________________
(page generated 2023-12-14 23:01 UTC)