[HN Gopher] Security Issue: Cloud Site Manager presented me your...
       ___________________________________________________________________
        
       Security Issue: Cloud Site Manager presented me your consoles, not
       mine
        
       Author : amaccuish
       Score  : 262 points
       Date   : 2023-12-14 16:42 UTC (6 hours ago)
        
 (HTM) web link (community.ui.com)
 (TXT) w3m dump (community.ui.com)
        
       | js2 wrote:
       | Also on r/Ubiquiti:
       | 
       | https://old.reddit.com/r/Ubiquiti/comments/18hgpw1/security_...
       | 
       | https://old.reddit.com/r/Ubiquiti/comments/18hs684/no_offici...
        
         | NelsonMinar wrote:
         | These are really bad, and both very recent. One post is a
         | Reddit user who is seeing camera images from other Ubiquiti
         | installations. The other is a general discussion about the lack
         | of response from Ubiquiti so far.
        
       | teamspirit wrote:
       | So the guy makes the initial post, within an hour UI team reaches
       | out to him to gather more info and the next post is a criticism
       | of their handling!
       | 
       | What's wrong with people? I think 1 hour response to a forum post
       | isn't unreasonable or am I wrong?
        
         | jbverschoor wrote:
         | And nothing for 16hrs. So probably there is something wrong.
         | And it's seems pretty critical. Status page doesn't show
         | anything
        
           | WesolyKubeczek wrote:
           | I don't know if it's expected of status pages to signal
           | security incidents and bugs if you technically can still use
           | your (and other people's) console.
           | 
           | (Putting on buck teeth and fidgeting with something) But but
           | but akchyually, it's not an outage, you see.
        
             | PeterisP wrote:
             | If other people can access your console, then this feels
             | like a case where it's negligent not to have an intentional
             | outage, shutting down all remote access to all cloud
             | consoles until this is fixed.
        
           | Petersipoi wrote:
           | Why would users want them to advertise a vulnerability on the
           | status page before the issue is fixed? I would want them to
           | keep this as quiet as possible until the issue is resolved.
        
             | x0x0 wrote:
             | To enable workarounds and/or stop the bleeding.
             | 
             | There's many places where no network is strongly preferable
             | to network that could be open to hackers.
        
               | JAlexoid wrote:
               | I mean... It's not even "no network". Once the management
               | connection is severed the network equipment doesn't stop
               | operating at all.
        
             | Ekaros wrote:
             | All users should be informed so they can decide if to pull
             | the plug or not on their devices...
        
         | alsodumb wrote:
         | Nothing's wrong with people angry about this. What's wrong with
         | the company letting it happen in the first place?
        
         | bastardoperator wrote:
         | If someone was actively stealing your car, and 911 told you
         | they're an hour out, would that be acceptable? Having carte
         | blanche access to someone else's network equipment seems like
         | the highest emergency a company like Ubiquity could have.
         | 
         | I don't know if the time frame is acceptable, but I know I
         | would have reached out to the customer versus waiting around
         | for a DM once the alarm was rung.
        
           | wannacboatmovie wrote:
           | > If someone was actively stealing your car, and 911 told you
           | they're an hour out, would that be acceptable?
           | 
           | In Seattle they don't even show up anymore, they tell you to
           | fill out a form online...
        
             | simfree wrote:
             | You have to search the streets yourself and be your own
             | advocate if you want to recover your stolen car.
             | 
             | In the last 8 years SPD has become completely unmotivated
             | to do their job despite never having their budget cut.
             | Adjacent police departments like Kirkland and Lake Forest
             | Park are much more willing to do their job, but they fire
             | officers who don't do their job, while SPD retains these
             | caustic, non-performing officers.
             | 
             | So long as we let our officers in Seattle getaway with
             | billing fraudulent hours that weren't worked, ignoring core
             | job duties, and slow rolling the duties that they do do, we
             | will be stuck with an ineffective police force.
        
               | ImJamal wrote:
               | >In the last 8 years SPD has become completely
               | unmotivated to do their job despite never having their
               | budget cut
               | 
               | The budget was absolutely cut.
               | 
               | https://apnews.com/article/business-police-
               | seattle-6730ec66e...
        
               | Arnavion wrote:
               | >The Seattle City Council has approved a 2022 budget that
               | cuts police department spending from previous years [...]
               | 
               | 2022 was not 8 years ago.
        
               | ImJamal wrote:
               | I do not read "In the last 8 years" as 8 years ago, but
               | within in the last 8 years. Do you read it differently?
        
               | Arnavion wrote:
               | In your interpretation the number 8 has no significance
               | in that sentence, since "In the last 1000 years" would
               | have the same meaning.
        
               | ImJamal wrote:
               | I could say the exact same thing for your interpretation.
               | Why not just say 1000 years ago the budget wasn't cut? It
               | would have the same meaning. Oh wait, it wouldn't have
               | the same meaning because 8 and 1000 years are quite a bit
               | different.
               | 
               | 8 years is probably not meaningless for the poster. He
               | probably moved there 8 years ago or had his car stolen
               | back then and is saying nothing has improved since then
               | despite there being no budget cuts.
               | 
               | It makes no sense to say in the last X years if the poser
               | just mean X years ago. It would cause unnecessary
               | confusion.
        
               | Arnavion wrote:
               | >I could say the exact same thing for your
               | interpretation. Why not just say 1000 years ago the
               | budget wasn't cut? It would have the same meaning.
               | 
               | Because it would not have the same meaning. The point of
               | the phrasing is that the time the Seattle PD stopped
               | being motivated to do their job was close to eight years
               | ago, and they have continued to be unmotivated since
               | then.
               | 
               | "1000 years ago the budget wasn't cut" does not convey
               | that information.
        
               | ImJamal wrote:
               | If the poster meant 8 years ago they stopped being
               | motivated he would have just said that. The post didn't
               | say that. You are just tangling yourself in word play to
               | try to get the post to mean something different than it
               | does.
        
               | djohnston wrote:
               | You're parsing this incorrectly mate. "In the last 8
               | years" means in any of the last 8 years, which is
               | different than in the last 1000 years.
        
               | hobotime wrote:
               | The SPD has lost hundreds of officers and hasn't recouped
               | them.
               | 
               | "Defund the Police" has consequences.
        
               | fwip wrote:
               | The SPD has lost officers, yes, despite offering hiring
               | bonuses higher than ever. This is not because they don't
               | have enough money, but because the prestige of being a
               | police officer in Seattle has declined.
        
               | enumjorge wrote:
               | While defund the police was ill-though out, let's
               | remember that it was a response to the continued use of
               | excessive use of force by police. As one of the parent
               | commenters said, SPD has a poor track record of
               | disciplining misconduct of their officers. People will
               | take increasingly desperate measures if they feel like
               | they're not being heard. The idea that you'd do away with
               | police was short sighted and didn't make sense since the
               | beginning, but the situation SPD finds itself in is
               | partially a self-inflicted wound.
        
               | ImJamal wrote:
               | The police chief is appointed by the mayor. If people
               | feel like they are not being listened to or there is too
               | much abuse maybe they should elect a mayor that will deal
               | with it?
        
               | fwip wrote:
               | Yes and no. Traffic enforcement and dispatch positions
               | were moved to another funding line item outside of the
               | SPD. This was the city council attempting satisfy calls
               | to "defund the police", while not actually reducing the
               | amount of money allocated to policing.
               | 
               | https://southseattleemerald.com/2023/09/14/opinion-
               | debunking...
        
               | myko wrote:
               | "The new budget includes funds for 1,357 officers and SPD
               | says right now, there are 1,120 officers on the force--
               | which leaves 237 open jobs."
        
             | globular-toast wrote:
             | 20 years ago in school our English teacher had us read a
             | science fiction short story about a robbery. I wish I could
             | remember the name of it. The essential idea was that
             | robbery was at some point legalised and nobody really cared
             | because they just claimed on insurance. With more and more
             | of our possessions being basic commodities (cars,
             | electronics, IKEA furniture etc.) and everything of
             | importance being digital, this seems to be coming true now.
        
               | bell-cot wrote:
               | From very dim memory:
               | https://en.wikipedia.org/wiki/Flatlander_(short_story)
        
             | olyjohn wrote:
             | Anymore? They've never shown up for this kind of stuff as
             | long as I can remember.
        
           | chrisandchris wrote:
           | That's not a good comparison.
           | 
           | 911 is paid by taxes for being 24/7 available. It is also a
           | public service. Ubi is free (at least I don't pay for any of
           | my Unifi consoles, besides the initial cost). It is also a
           | private company, free (as in beer) to do as they like.
        
           | bentruyman wrote:
           | Do you think Ubiquiti has hundreds of people on staff to
           | watch their forums to triage every issue within seconds of it
           | being posted? I'm curious what level of support would be
           | satisfactory to you, in this instance.
        
             | lbotos wrote:
             | Not OP but you don't need 100s of staff monitoring the
             | forum. You need a webhook that filters on "security" in the
             | title and post it in the relevant slack channel. I do
             | expect UI have a 24/7 paid support/security team and I'm
             | sure _someone_ could say  "uh, this looks real what's going
             | on?"
        
               | bentruyman wrote:
               | Ah yes the typical engineer response of "just <insert
               | system>".
        
               | tw04 wrote:
               | Yes, damn those engineers for coming up with solutions to
               | problems I personally believe are unsolvable based on
               | nothing but personal feelings.
               | 
               | Ignoring the fact that flagging when certain keywords are
               | posted is probably built into the forum software
               | itself... I had that with phpbb back in 2001.
        
               | bentruyman wrote:
               | I just find it funny when engineers trivialize solutions
               | that they themselves wouldn't employ. Like yeah, I'm sure
               | your phpbb solution was a proper vulnerability reporting
               | and triaging system.
        
           | paxys wrote:
           | You must not have had any dealings with the police in any US
           | city if you think that they will come running in minutes if
           | someone is stealing your car.
           | 
           | There is an escalation path for security tickets at most
           | large companies, and a community forum post is not it.
        
             | bastardoperator wrote:
             | You sure about that?
             | 
             | Chicago: 3.46 minutes
             | 
             | Los Angeles: 5.7 minutes
             | 
             | Seattle: 7 minutes
             | 
             | Dallas: 8 minutes
             | 
             | Miami: 8 minutes
             | 
             | New York City: 9.1 minutes
             | 
             | Atlanta: 9.5 minutes
             | 
             | Houston: 10 minutes
             | 
             | Detroit: 12 minutes
             | 
             | Denver: 13 minutes
        
               | cyral wrote:
               | Go on any of those city subreddits and read the stories
               | of 911 not picking up or refusing to come out because
               | "you can file a report online".
        
               | bastardoperator wrote:
               | That's called anecdotal evidence. I've had police come
               | slow and come fast. 911 also prioritizes calls, so it's
               | possible you're being rate limited by them and not the
               | actual police. The data from their apps tells a different
               | story, maybe they're fudging it, I just don't think
               | making blanket statements about timing based on someone
               | else's story gives me an accurate picture.
        
               | cyral wrote:
               | The problem is calls that are never picked up, and calls
               | that are "resolved" by telling the caller that a stolen
               | car is no biggie, ruin these "stats".
        
           | SV_BubbleTime wrote:
           | This is pretty simple, if you cannot be down for an hour...
           | don't buy Ubiquity.
           | 
           | Enterprise sucks a lot of the time, but this is what you are
           | supposed to be paying for.
        
         | bdcravens wrote:
         | Update the status, and discuss it more in the open. Obviously
         | with any security issue there's reasons to keep some
         | discussions private, but it feels like they're attempting to
         | minimize it, the same way a restaurant doesn't want their
         | customers to hear about the mice in the kitchen.
         | 
         | https://status.ui.com/#past-incidents still says "no incidents
         | reported today"
        
         | alt227 wrote:
         | I think you are missing the point. the point is this should
         | never ever happen in whats considered to be SMB enterprise
         | products. Peoples businesses and livelihoods are at stake. The
         | fact that it did happen is bad enough, the rest is just the
         | icing on the cake. you made the point about a 1 hour response,
         | howewver 18 hours after that response there is still no update
         | anywhere for lots of worried customers.
         | 
         | If Ubiquiti was my company and this post was posted on my
         | forum, I would be having status messages/emails out to all my
         | customers, updates on status pages, warnings on website logins
         | etc. Hiding this in a private DM with a single customer is
         | terrible, and they even told the world thats what they were
         | doing which was a kick in the nuts.
        
         | tw04 wrote:
         | If I reported to a vendor that I had unfettered access to other
         | people's cloud console, and it was the fourth such report, I'd
         | expect them to shut down access to the console until they
         | figure out what's going wrong.
         | 
         | Instead, they're "looking into it" or something?
         | 
         | I guess they'll just hope nobody does anything nefarious like
         | change the passwords on every switch/router/AP they have access
         | to then get remote access?
        
           | emilyst wrote:
           | Imagine being able to shut off all Ubiquiti console access in
           | the world instantly, by posting about a grave security issue
           | (real or not) and having a few compatriots to do the same in
           | a short amount of time. You could trivially block a
           | business's access to its own security cameras on a moment's
           | notice, among other things.
           | 
           | If the response to an unverified issue were "just shut
           | everything down" you effectively have implemented an
           | exploitable DoS in your own incident policy.
        
             | cyral wrote:
             | I was typing exactly this when I saw your comment. This
             | could very well be a real issue, but could also be a
             | nefarious attack or even just incompetence. I've done
             | support before and there are always users convinced that
             | they are "hacked" or that we are doing something shady
             | because they forgot their friend logged in on their device
             | or forgot that they actually made two accounts in the past.
        
             | tw04 wrote:
             | This was posted 18 hours ago. If you can't either verify
             | the user has actual access to other people's consoles (at
             | which point you should be immediately turning access off)
             | in 18 hours, then you should probably just close up shop
             | because you have no business providing remote access to a
             | can of soup much less someone's firewall.
             | 
             | If the user in question was making it up, you should also
             | have posted within minutes of discovery that the user in
             | question (and multiple other people) were making false
             | claims.
             | 
             | Again, they've chosen the "we're looking into it" route
             | which is always reassuring.
        
               | kevincox wrote:
               | > If you can't either verify the user has actual access
               | to other people's consoles [...] in 18 hours, then you
               | should probably just close up shop
               | 
               | It's impossible to prove a negative. Maybe they believe
               | that this was user error/malice but are doing more
               | research to confirm this and find evidence of a
               | vulnerability.
        
               | tw04 wrote:
               | >It's impossible to prove a negative. Maybe they believe
               | that this was user error/malice but are doing more
               | research to confirm this and find evidence of a
               | vulnerability.
               | 
               | So it's impossible for me to prove that nobody has walked
               | through my front door today? I'm quite confident it
               | isn't. I'm also confident if they have sane logging in
               | place, they can prove accounts weren't being accessed by
               | unauthorized users.
               | 
               | You're also talking in vagaries like they're hunting a
               | ghost. They've been interacting with a willing end-user
               | who originally reported the error.
        
           | judge2020 wrote:
           | For what it's worth, all reports and screenshots of this
           | seemed to have happened within the same hour, so it might've
           | been fixed quickly. I definitely would expect this to get a
           | public postmortem within 48 hours, though (maybe Cloudflare
           | has ruined my postmortem timeline expectations).
        
       | meltyness wrote:
       | This place has quite a rap sheet.
       | 
       | https://news.ycombinator.com/item?id=29411775
       | https://news.ycombinator.com/item?id=9331512
       | https://www.reddit.com/r/Ubiquiti/comments/t7br4a/since_the_...
        
       | magicmicah85 wrote:
       | Do they by any chance use a CDN for their cloud console? This has
       | burned organizations so many times before where they cache the
       | dynamic data and not static data.
        
         | twisteriffic wrote:
         | I wouldn't expect to be able to administer the resources if
         | this was just a caching issue. Seeing them yes, administer them
         | no. Unless their authx design is tragically bad.
        
           | bink wrote:
           | "Full Access" could mean a lot of things. I don't see
           | anything suggesting they could make changes (though I haven't
           | read the entire thread). The user could just assume they have
           | full access because they can see everything.
        
             | fotta wrote:
             | there was a comment in one of the reddit threads that
             | someone was able to create a vlan on someone else's network
        
               | BHSPitMonkey wrote:
               | It's hard to be certain while we're just speculation, but
               | a view caching bug could make it _look_ like you're
               | making changes to the other user's console even if
               | they're actually going to your own console.
        
               | EE84M3i wrote:
               | It could also be caching something that contains a token
               | that can perform other actions. The disparate reports of
               | different pages and being able to navigate make it sound
               | like this is at some API level, not literally caching the
               | console page view.
        
               | twisteriffic wrote:
               | This is my line of thinking. It's bonkers if that's the
               | case - sign of a completely broken mindset towards auth.
        
           | kevincox wrote:
           | If your login/access token request is cached this could
           | happen. But that may qualify as "tragically bad".
        
         | pixl97 wrote:
         | Yep, this would be my guess. Something like "UserID" gets
         | cached per node and suddenly you're seeing the wrong persons
         | data.
        
         | larvaetron wrote:
         | That was my first thought, it sounds similar to what happened
         | with Klarna[1] a few years ago.
         | 
         | [1] https://news.ycombinator.com/item?id=27301219
        
       | cooljacob204 wrote:
       | I really wish they weren't forcing everything to their cloud
       | services for exactly things like this.
        
         | snom380 wrote:
         | Are they forcing people to the cloud services? (I'm still
         | running without cloud enabled.)
        
       | jbverschoor wrote:
       | Remote access anything should be banned. Just use a
       | VPN/wireguard.
       | 
       | Reverse control is such a mess and the application is not the
       | place to handle this
        
         | bradyd wrote:
         | A VPN is remote access.
        
           | jbverschoor wrote:
           | Of course, but it's at a different layer and it works
           | differently. It's also something that can be swapped.
        
         | chunkyks wrote:
         | The hilarity that goes with this is that their VPN has been
         | broken for years - android and iPhone both deprecated protocols
         | that were considered insecure, but ubiquiti hasn't seen fit to
         | add any others. It has been _years_.
         | 
         | Their security posture is trash, which is unfortunate for a
         | company that plays a central role in security
        
           | SparkyMcUnicorn wrote:
           | Yeah, I use Tailscale instead:
           | https://github.com/SierraSoftworks/tailscale-udm
        
             | cmsj wrote:
             | I love Tailscale, but you are really then just substituting
             | one company's remote access for another's. I'm quite
             | certain that TS are more capable of creating a secure
             | system than Ubiquiti are, but still, the principle of not
             | trusting others with access to your network, is violated by
             | TS.
        
               | SparkyMcUnicorn wrote:
               | It works with Headscale.
               | 
               | https://github.com/juanfont/headscale
        
               | michaelnoguera wrote:
               | I agree that enabling any form of remote access
               | controlled by a third party increases attack surface, but
               | I also feel like Tailscale has earned more of my trust
               | than other vendors with the quality of their past
               | security responses.
               | 
               | https://news.ycombinator.com/item?id=33695886
               | 
               | (If anyone has examples of Tailscale incidents ending
               | badly please share and I'll update my trust accordingly,
               | but to date I haven't heard any.)
        
               | fragmede wrote:
               | That incident ended badly for anyone that had a Windows
               | box and got 0wned. Tailscale's response was good, but my
               | trust in the software they produce was damaged by that
               | incident. I'm a current Tailscale user (esp with their
               | AppleTV app), but that incident wasn't good.
        
           | WillPostForFood wrote:
           | https://help.ui.com/hc/en-us/articles/7951513517079-UniFi-
           | Ga...
           | 
           | They do now support Wireguard and OpenVPN in addition to
           | L2TP. OpenVPN looks like it is only available on newer
           | hardware though.
        
           | InTheArena wrote:
           | Just stop.
           | 
           | OpenVPN and Wireguard work fine. I am using it right now.
        
         | bink wrote:
         | AFAIK you can disable remote access via their cloud. I do think
         | they still force you to use the cloud credentials for internal
         | access, however.
        
           | cmsj wrote:
           | I think you need at least one ui.com user, but you can also
           | add local users. I control my unifi stuff through a local
           | admin user.
        
           | InTheArena wrote:
           | no. you can use a local account.
        
       | ubiquitithrow wrote:
       | Ex Ubiquiti employee here. I barely recognize the company any
       | more. The company always had problems but we had a lot of smart
       | and hard working peopl in the early days. People are always
       | amazed when I tell them how small the company was when we made
       | Ubiquiti and UniFi into household names among nerds.
       | 
       | Some of those people remain. UI-Marcus in that link is a good
       | person. The company went into a steady decline after the CEO
       | started centering the company around the offices in Portland and
       | China. Portland was home to the UX designers who wanted to
       | redesign everything to look nicer but didn't understand how
       | customers used our products. Portland was also home to Nick
       | Sharp, the cloud lead who tried to extort the company and lied to
       | the press about hacks. The favorite office in China made the
       | FrontRow product, which failed so badly that I doubt anyone has
       | heard of it. These people were supposed to be the future leaders
       | of the company, but everything they did was a disaster. We could
       | all see the writing on the wall and left. Well, almost everyone.
       | 
       | I don't even know which Ubiquiti office owns the cloud any more
       | because everyone working on cloud at Ubiquiti either quit or was
       | laid off after the cloud lead went to prison for extorting the
       | company.
       | 
       | I hope the company can get back on track some day. It's sad to
       | see all of our old work decay like this.
        
         | 12345hn6789 wrote:
         | >We could all see the writing on the wall and left. Well,
         | almost everyone.
         | 
         | >It's sad to see all of our old work decay like this.
         | 
         | This is very common. Happened at my old company. Your last 2
         | paragraphs are 1-1 the experience of many of my coworkers and
         | I. Very, very sad.
        
         | aurareturn wrote:
         | I hooked my home up with 3 Unifi AC Pros + ERPOE5 in 2015/2016.
         | They've been running for 8 straight years without ever
         | restarting. Never had a problem.
         | 
         | Granted, I never updated the firmware in the 8 years. Heck, I'm
         | not even sure how I can get back to the web UI to control them.
        
           | wil421 wrote:
           | Use the Unifi phone app to manage them. You can manage the
           | APs themselves without logging into anything. I'd recommend
           | updating the firmware after 8 years, you can always do a hard
           | reset to get the original back.
        
             | SparkyMcUnicorn wrote:
             | Hard reset will not automatically downgrade the firmware.
             | 
             | And I don't think it's a good idea to manage multiple APs
             | using the app instead of from the controller. Managing a
             | single AP from the app is ok, but I think you'll run into
             | problems when you have multiple in a network.
        
               | aaronax wrote:
               | It is unlikely that a home user has network functions in
               | use that rely on the controller.
        
               | SparkyMcUnicorn wrote:
               | My point still stands for multiple APs.
               | 
               | For example, you can't set up meshing from the mobile
               | app. Best you can do is give them all the same
               | SSID/password, and they also have to be wired in that
               | scenario.
        
               | TheNewsIsHere wrote:
               | Hard agree. Especially if you have something like the
               | UDM/UDM-P and are managing VLAN-specific SSIDs and so
               | forth.
        
           | sonicanatidae wrote:
           | Its fine to use at home, but I see a lot of people pretend
           | these are Enterprise devices and use them as such. They are
           | upgraded consumer gear, at best, imo.
           | 
           | Source: I've been working with unifi gear for the past 4+
           | years and use a basic unifi setup at home, since it was free
           | to me. I wouldn't have bought it.
           | 
           | Like all things, YMMV. I'm glad to hear its working like you
           | need it to.
        
             | notyourwork wrote:
             | What would you have a bought instead? In my experience
             | there isn't anything comparable in the consumer space. I'd
             | love to be shown I'm wrong. I use both their network gear
             | and security setup (door bells, cameras).
             | 
             | I'm not sure there is another company offering the same
             | solution with ease of setup and low overhead to manage. Is
             | there?
        
         | gene91 wrote:
         | That sound like a terrible workplace.
         | 
         | For your own home, if not Ubiquiti, what do you use nowadays?
        
           | lotsofpulp wrote:
           | Not the person you replied to, but I like Aruba Instant On.
           | 
           | https://www.arubainstanton.com/
        
             | aetherspawn wrote:
             | Looks good but lacks layer 3 and fiber aggregation switches
             | which we use in our SMB.
        
             | mook wrote:
             | Hmm, that looks like it must be centrally managed from the
             | internet? Not saying it's not an appropriate replacement
             | for Ubiquiti, but that seems like an opportunity for the
             | same issues to show up... something that isn't remotely
             | managed might be better instead.
        
               | lotsofpulp wrote:
               | I think the "InstantOn" functionality requires internet
               | for setting up, but it seems like there is a way to
               | manage it locally without the use of the "InstantOn"
               | functionality:
               | 
               | https://www.arubainstanton.com/techdocs/en/content/get-
               | start...
               | 
               | Some more discussion here from years ago:
               | 
               | https://community.arubainstanton.com/communities/communit
               | y-h...
               | 
               | Although, I imagine this type of stuff may not be made to
               | work well without internet.
        
           | hughesjj wrote:
           | Tplink for aps and mini PCs for routers
        
             | dixie_land wrote:
             | TP links are cheap and well made for its price, if you
             | don't care that the CCP has a backdoor to every device
        
               | sgerenser wrote:
               | I use TP link access points with my own cloud controller
               | (running in docker container on my LAN) and a separate
               | wired router. I don't think there's any concern with
               | access points "phoning home" in this configuration.
        
               | depingus wrote:
               | > the CCP has a backdoor to every device
               | 
               | This is huge! Please link me to the evidence to back this
               | up.
        
               | mike_d wrote:
               | China deploys plausibly deniable backdoors into
               | internationally shipped network devices. Bugs that are
               | remotely exploitable if you know they exist, but not
               | obvious enough that they provide justification for the
               | devices to be banned from import. These consumer devices
               | are not exploited for intelligence gathering, but rather
               | deployed as proxies that fall into one of two common
               | buckets: acting as SOCKS proxies to relay attacks, and
               | allowing a remote operator to scan for nearby wireless
               | networks and bridge into them.
               | 
               | The NDAA blacklist was a happy compromise by the US
               | government of banning the most egregious vendors that
               | might find their way into sensitive facilities (Huawei,
               | Hikvision, etc) while letting consumer focused brands
               | that do the same (TPLink, Jetstream, Wavlink, etc) slip
               | by so it didn't appear at face value to be a blockade of
               | all Chinese made networking gear.
               | 
               | Taiwan on the other hand is less concerned about how
               | China perceives their relations and bans all these
               | vendors. They also ban Zoom.
        
               | jstarfish wrote:
               | It'd be easier to just Google it.
               | 
               | Grievances start with "made in China" and end with
               | firmware hacks from May of this year.
               | 
               | https://blog.checkpoint.com/security/check-point-
               | research-re...
        
               | depingus wrote:
               | "We are unsure how the attackers managed to infect the
               | router devices with their malicious implant. It is likely
               | that they gained access to these devices by either
               | scanning them for known vulnerabilities or targeting
               | devices that used default or weak and easily guessable
               | passwords for authentication"
               | 
               | This implies the opposite of "the CCP has a backdoor to
               | every device". Vulnerable devices from all manufacturers
               | get exploited like this all the time.
        
             | jandrese wrote:
             | I've had pretty bad luck with TPLink APs temporarily
             | dropping connections and being just generally unstable.
             | Even when you can put OpenWRT on them the hardware is just
             | kinda buggy.
        
               | depingus wrote:
               | I think OP means the Omada EAP's, which are dedicated
               | access points and not the routers. I have 2 EAP225's that
               | have been better than the Ubiquiti it replaced.
        
           | scrlk wrote:
           | I've been considering MikroTik recently (specifically the
           | RB5009 series). Main downside I've read about so far is that
           | the UI/UX is a bit rough.
        
             | bastard_op wrote:
             | You think the UI is rough, try the cli.
        
               | carlhjerpe wrote:
               | There's a learning curve indeed, but it's also
               | essentially just a thin wrapper around nftables (read
               | iptables) so you learn about Linux networking by using
               | them
        
               | bastard_op wrote:
               | I've been using unix and linux since the 90's and linux
               | full-time on every system of mine, and Tik's still seemed
               | entirely counterintuitive to me. I'd rather just deal
               | with iptables and linux directly without the wonky cli.
        
               | sonicanatidae wrote:
               | I prefer the cli for Mikrotik, but that's true for most
               | firewall, routers, etc.
               | 
               | YMMV.
        
               | doubled112 wrote:
               | I actually found the Mikrotik CLI easy to learn because
               | it and the GUI are basically 1:1.
               | 
               | For example:
               | 
               | /ip/firewall/filter add
               | 
               | is in the UI under the sidebar IP -> Firewall, then the
               | Filter tab, then click add. The parameters are named the
               | same in both too.
        
             | lbotos wrote:
             | I have a mikrotik https://mikrotik.com/product/hap_ac3 that
             | I bought as a sort of test and it's been working fine for
             | my needs. the webUI isn't the best, but wiki docs were
             | pretty straightforward and I've been decently happy.
        
             | cyberax wrote:
             | I don't get all the Mikrotik UI hate. It's not winning any
             | beauty contests, but it's straightforward and it works
             | well.
             | 
             | I've been using their devices for years, and I haven't had
             | any problems setting them up.
        
               | favorited wrote:
               | There are some really terrible UI choices in SwOS, like
               | not labeling rows of checkboxes so users need to hover
               | over each one with their mouse to see a tooltip.
        
           | deep_origins wrote:
           | Anyone using Mikrotik these days? Been Mikro-curious for
           | awhile and always see them thrown around as a Unifi
           | alternative. Yet to hear of any firsthand implementations
           | though.
           | 
           | [0] https://mikrotik.com/
        
             | sam_lowry_ wrote:
             | I have half a dozen Mikrotik hAP AC and wAP AC devices with
             | Openwrt used in various places for work and for home.
             | 
             | Rock-solid hardware and muuuch better UX that RouterOS.
             | 
             | Don't remember when I setup those, but probably well before
             | Covid. Really fire-and-forget devices.
        
             | bastard_op wrote:
             | As a network engineer, I've considered them for my house,
             | the price is right, but:
             | 
             | 1) Their main push seems to use a thick client for admin
             | which is a big no to me, otherwise the web ui in theory
             | looks ok-ish. 2) Looking at their cli guide, it was cryptic
             | as hell to me, and I deal with everything from cisco,
             | arista, aruba, juniper, fortinet, pan, whatever from a cli
             | or gui.
             | 
             | This was mostly confirmed a few weeks back, another old
             | network engineer friend of mine hit me up asking if I've
             | ever dealt with Mikrotik, and said no, but I knew where he
             | was going. He'd screwed with it for a day or so supposedly
             | just trying to make some L3 vlans, and finally a day or so
             | later told me he'd made it work, but has never dealt with
             | anything so terrible to configure from either gui or cli
             | after having tried both, and he's another 20yr+ network
             | engineer like me I trust not to be stupid.
             | 
             | That was all I needed to hear for future consideration.
        
               | snuxoll wrote:
               | Mikrotik has had WinBox for as long as they've been
               | around and there's a lot of inertia around using it, but
               | WebFig and the CLI are the only things I use (though I do
               | have The Dude running through Crossover because it's
               | useful).
               | 
               | Where you run into problems with 'tik gear is the
               | differences that L3HW acceleration introduced into the
               | mix. They didn't do what every other switch vendor does
               | and limit features to what the switch chip supports and
               | hide everything that the CPU can't handle away, so you
               | have multiple ways of approaching most issues which threw
               | me for a look as somebody who had been running JunOS gear
               | in his lab for a while.
               | 
               | Once you get a feel for it then it's pretty
               | straightforward to work with everything, though somebody
               | used to an older generation of NOS like classic IOS (and
               | associated clones) would have an easier time than me.
               | 
               | For reference, here's the config for my CRS317 acting as
               | my "core" switch: https://gist.github.com/snuxoll/d63a155
               | aa2155f53736a99d1cb27...
        
               | qmarchi wrote:
               | Their "thick client" (aka Winbox) is effectively
               | replicated in the web UI at this point.
               | 
               | Yeah, the CLI is a bit weird, but it's built on the same
               | API calls that the web UI makes. So they're oddly
               | consistent.
        
               | ahoka wrote:
               | What does "L3 VLAN" even mean?
        
               | radiowave wrote:
               | For sure, VLAN config is one of the most extremely "How
               | and why did anyone end up designing it this way?"
               | thought-inducing areas of Mikrotik config.
               | 
               | But I will say that the boxes of theirs that I bought
               | about ten years ago are still going strong, never had a
               | device fail on me, still receiving OS updates, still able
               | to export and re-import my config to any of a wide
               | variety of newer devices when the time comes.
               | 
               | Clearly they're not the right choice for everybody, but
               | there are certainly up sides, if you're willing to
               | grapple with the config.
        
           | seany wrote:
           | Ruckus 730/750/850 with unleashed firmware
        
           | tekla wrote:
           | Aruba. Some jank in the software, but the gear has been rock
           | solid
        
             | sl360 wrote:
             | The Instant-On gear is physically almost identical to the
             | professional line, but with heavy software limitations.
             | 
             | Best built hardware I've used, and I'd still be using their
             | PoE at home if they didn't patch out SSH/REST access a few
             | years ago.
        
           | allarm wrote:
           | Not sure if they sell it outside of EU, but Keenetic is
           | absolutely awesome. Been using their routers for a while,
           | have a wifi mesh configured in my home built on their
           | devices.
           | 
           | https://keenetic.com/en
        
           | alt227 wrote:
           | Draytek routers are not perfect, the UI lacks polish, but I
           | have never had one fail on me yet. Solid kit (even though you
           | do need to keep up with the firmware updates to keep them
           | secure)
        
         | sunbum wrote:
         | While I havn't been keeping up with what was going on, the
         | second I started seeing ads for ubiquti I knew something had
         | gone deeply wrong.
        
         | chewmieser wrote:
         | Hadn't heard of FrontRow (as you assumed) so went looking for
         | information about it and it looks like they may have repurposed
         | it for the Access Reader Pro? Haha that's a way to move them.
         | 
         | What a miss... And weird product category for them...
         | 
         | Also interesting, apparently Ubiquiti came out with a video
         | editor too around that time for FrontRow:
         | https://www.reddit.com/r/Ubiquiti/comments/t9jz2n/ubiquiti_l...
         | 
         | Curious - what was the size of Ubiquiti when "we [you and your
         | tean] made Ubiquiti and UniFi into household names among
         | nerds"?
        
           | callumjones wrote:
           | Wow, I always wondered why the Access Reader Pro had such a
           | weird design - it was just a repurposed product from a
           | completely different catagory.
        
           | teruakohatu wrote:
           | Here is the FrontRow website from 2017:
           | 
           | https://web.archive.org/web/20170929122826/https://www.front.
           | ..
        
         | qwertox wrote:
         | > Portland was home to the UX designers who wanted to redesign
         | everything to look nicer but didn't understand how customers
         | used our products.
         | 
         | MirkoTik has also been updating their UI this year and it's
         | only getting worse.
         | 
         | They are starting to put everything into auto-collapsed
         | sections so that instead of just scrolling down the page you
         | now must remember the section's title and open it in order to
         | access the controls. There are hundreds of sections.
        
           | cmsj wrote:
           | Mikrotik's UI was terrible to begin with, just a big 90s
           | smorgasboard in the style of My First Visual Basic App.
        
             | karolist wrote:
             | The Dude. edit: more context, that's the Win UI manager
             | with the 90s look for MikroTik. It's not pretty but I know
             | fairly large ISP admins swearing by it
             | https://mikrotik.com/thedude
        
             | dishsoap wrote:
             | I like it, it just works and everything in it makes sense.
             | Very refreshing compared to a lot of the things we have
             | today.
        
             | vetinari wrote:
             | Winbox UI might be not according to the latest UX fashion,
             | but is pretty effective.
        
             | lencastre wrote:
             | Some people like VB6 and its aesthetic.
        
           | bogantech wrote:
           | Webfig I presume?
           | 
           | The first rule of webfig is: don't use webfig
        
             | qwertox wrote:
             | There were no issues with Webfig.
             | 
             | These newly collapsed sections are tabbed sections in
             | WinBox, so there you've had the problem since the
             | beginning.
             | 
             | It's a matter of preference and I've always preferred
             | Webfig. I'm a MikroTik user since 2013 and have 9 devices
             | which I like a lot. I only used WinBox when I misconfigured
             | them a bit in order to access them via the MAC address.
        
             | sgt wrote:
             | Makes it useful for someone who doesn't really use Mikrotik
             | a lot to be able to browse through and explore.
        
           | jbverschoor wrote:
           | > Portland was home to the UX designers who wanted to
           | redesign everything to look nicer but didn't understand how
           | customers used our products.
           | 
           | That means they're not UX designers, but simply illustrators
           | without actual illustration skills
        
             | robertlagrant wrote:
             | Or they're UX designers without actual UX design skills?
        
         | LeoPanthera wrote:
         | I bought a FrontRow! I loved it! It still works, although the
         | battery doesn't hold much of a charge anymore.
         | 
         | It always seemed funny to me that the door access readers re-
         | used the case from it.
        
         | giobox wrote:
         | Is it true the failed FrontRow hardware was repurposed into the
         | Unifi door fob scanning thing/product ("Access Reader Pro")? I
         | recall reading this somewhere, and the hardware appears to be
         | identical:
         | 
         | >
         | https://www.theverge.com/circuitbreaker/2017/8/15/16146354/f...
         | 
         | > https://c3aero.com/products/ua-pro
         | 
         | I was absolutely floored when I saw the announcement of the
         | FrontRow device - what a bizarre thing to have brought to
         | market for a network hardware company. I can only imagine
         | someone somewhere got far too caught up in the "wearable" hype
         | a few years ago.
        
           | fest wrote:
           | I can't really go into details, but FrontRow wasn't the most
           | bizarre thing Ubiquiti was working on, just the one that got
           | reasonably close before being shelved.
           | 
           | IIRC Access reader isn't the only product the FrontRow R&D
           | cost/stock of parts was tried to be recouped, but at that
           | time I wasn't working there anymore.
        
         | sonicanatidae wrote:
         | How many years now has it been since Unifi implemented broken
         | VPN and won't fix it?
         | 
         | 5, by my count and still climbing.
        
         | adamjc wrote:
         | > Portland was home to the UX designers who wanted to redesign
         | everything to look nicer but didn't understand how customers
         | used our products
         | 
         | I think that's every single piece of modern software to date. I
         | call them "Dribbblrs", because it's like they take inspiriation
         | from these websites (e.g. Dribbble) that fetishize things that
         | look pretty but are dogshit to use. I really wish it would end
         | but I don't see it happening unless there's a revolution from
         | within the UX community (which I am not a part of).
        
         | jonathantf2 wrote:
         | It's a weird one because they had a decent product line and
         | just seem to be making really weird choices - I assume to
         | market to the home/"pro-sumer" crowd instead of actual
         | businesses? They just came out with a network switch with RGB
         | for damnsake.
         | 
         | A few of my IT clients have UniFi routers and they're quite
         | lackluster for the price - pretty UI but loads of broken
         | features and bugs galore, and you can't manage them centrally
         | like the rest of the UniFi kit.
        
           | hkchad wrote:
           | > a network switch with RGB for damnsake.
           | 
           | This actually my turn out to be VERY useful. As someone who
           | runs Unifi at home w/ a stupid amount of VLans, being able to
           | color code them at the switch will come in real handy when I
           | just go and start unplugging stuff and rearranging as does
           | happen. If they update it to flash VLan color while unplugged
           | using the LCD screen it will be even MORE useful. We can hate
           | on RGB all day just for RGB sake but when it has a use, more
           | the better.
        
         | dclowd9901 wrote:
         | Damn, I interviewed there a while back and turned down an
         | offer. Kinda glad I did now.
        
         | fest wrote:
         | Can you weigh in on the decision to require UniFi controller
         | instead of providing on device configuration interface as well?
        
           | AlexandrB wrote:
           | That was part of the UniFi product since day 1, no?
        
             | fest wrote:
             | Yes, but I always found it strange (though I lack any
             | exposure to "enterprise" networking equipment).
        
               | baby_souffle wrote:
               | It makes good sense for large distributed deployments.
               | 
               | One page to update everything rather than have to connect
               | to each device and push a config. The controller also
               | "back-ports" the configuration as appropriate for a given
               | device. Declare a vLan once, don't have to worry about
               | which cli version is running on a given switch and adjust
               | your command accordingly.
               | 
               | These things don't matter much when you only have one
               | physical location / few devices but if you're an IT guy
               | that manages networking across every physical building in
               | a school district...
               | 
               | Since the device tries to phone home, it's also a NAT
               | buster which is invaluable when you're drop-shipping
               | equipment to customers and have little control over your
               | environment but need to be able to promise some level of
               | functionality.
        
         | xoa wrote:
         | > _I hope the company can get back on track some day. It 's sad
         | to see all of our old work decay like this._
         | 
         | Agreed, and it really was amazing work. As someone who started
         | using and then deploying UniFi in maybe 2015-2016ish and found
         | it a revelation, it's been tremendously depressing see so much
         | potential and such a community utterly squandered. I can only
         | imagine what it's like for someone on the inside. Nevertheless,
         | thank you so much for your work and all the others who helped
         | make it happen. If nothing else it did at least really blaze a
         | trail and show what could be done, and contrary to this issue
         | without any cloud bullshit and subscription lock-in. Even were
         | Ubiquiti to truly implode, that showing of what could be done
         | would remain and by its nature the kit would remain useful for
         | a long time.
         | 
         | There have been some mildly positive signs recently though,
         | even if the UX churn remains shitty. There has been small
         | shoots of progress on actual core features, years and years and
         | years late granted, but not entirely too late. I wonder if the
         | emergence of TP-Link's Omada as a clear, direct same-niche
         | competitor has lit any fires there?
        
         | neilv wrote:
         | Why did Ubiquiti open product/engineering offices in China?
        
       | syntaxing wrote:
       | I really wish there was an open source equivalent that's user
       | friendly. I run OPNSense but the learning curve is steep and I
       | wouldn't recommend it to family because of it. I've been debating
       | Firewalla but this same issue can happen since the control panel
       | is cloud based.
        
         | Arnavion wrote:
         | Well, since we're talking about delays in security responses,
         | OPNsense is in the same boat.
         | https://news.ycombinator.com/item?id=34839161
        
           | ojfkwai wrote:
           | I have a lot of complaints about OpnSense. But how exactly is
           | that a similar security response?
           | 
           | That wasn't a security incident for OpnSense. It was a CVE
           | for an optional package most users probably don't have
           | installed. Sounds like not-an-emergency to me. That user is
           | completely unreasonable. Opnsense should refund their money
           | (if any lol) and tell them to pop off.
        
             | Arnavion wrote:
             | >That wasn't a security incident for OpnSense. It was a CVE
             | for an optional package most users probably don't have
             | installed.
             | 
             | First of all, the point is that the OS didn't release CVE
             | fixes for the packages in its repositories even though it
             | had already committed those fixes to version control.
             | Notice that my comment specifically talks about "delay in
             | security response", not that it was an "emergency".
             | 
             | >That user is completely unreasonable. Opnsense should
             | refund their money (if any lol)
             | 
             | Second, I recommend reading the comment you respond to
             | carefully before you rush to make an account to respond to
             | it. "That user" is me. The GH thread has a clear comment
             | from me that I did not pay them any money and do not have
             | any expectation of support.
             | 
             | Third, notice that the point of the GH thread was me asking
             | what their policy of releasing CVE fixes was. You seem to
             | think I was some Karen complaining that they hadn't
             | released the fix. All I asked was a confirmation that
             | they're aware that they're shipping a package with a CVE,
             | that they've already fixed the package but just not
             | published it, and what their policy is for releasing fixes
             | in general.
             | 
             | They could've responded with something like "We're aware of
             | the CVE but we don't plan to release the fix in 23.1. Our
             | policy is to only release bugfixes for non-critical
             | packages in the next stable release, and we consider os-
             | haproxy to be a non-critical package."
             | 
             | Instead they got weirdly defensive about it, tried to
             | lecture me about how OS releases generally work, called me
             | "rude" (ironic), and locked the issue.
             | 
             | The ultimate point is that OPNsense delays security fixes.
             | Maybe you think it's okay because you think some OS
             | packages are critical and this one wasn't. Maybe you think
             | if an OS can't articulate its security fixes release policy
             | without getting combative, then it's hard to take its
             | security seriously. The decision is yours.
        
         | radicality wrote:
         | If it was open source, would you recommend Unifi to your
         | family? I feel like family will either be technical enough to
         | understand OPNSense, or not technical at all at which point
         | even Unifi is not something they'll manage themselves.
         | 
         | I actually run OPNSense for myself at home, but for my parents
         | I deployed full Unifi. This way if there's any problem, I can
         | remotely look at the network in the cloud console and try and
         | see what's wrong.
        
           | kube-system wrote:
           | > I feel like family will either be technical enough to
           | understand OPNSense, or not technical at all at which point
           | even Unifi is not something they'll manage themselves.
           | 
           | Agreed. Major ISPs in the US (and I presume many other
           | places) offer routers that work well enough to satisfy the
           | requirements of any non-technical household and often come
           | with provisioning/troubleshooting features that enable the
           | ISP to provide technical support if necessary.
           | 
           | In the old days, ISP-provided devices often lagged behind
           | other consumer or prosumer network offerings, and it made
           | sense to swap them out... but that's not really the case
           | today. Today, swapping out the ISPs router is probably going
           | to make a non-technical user's life harder, unless they have
           | someone technical to manage it for them.
        
             | olyjohn wrote:
             | ISP gear is still trash. It's just better for the user,
             | because the ISP won't bitch and moan and tell you your
             | hardware is unsupported.
        
               | kube-system wrote:
               | "Trash" is subjective.
               | 
               | Satisfaction happens when a product or service meets the
               | user's requirements. A new Cisco catalyst setup may be
               | technologically superior to my mother's ISP provided
               | router, but it might not make it easier for her to play
               | Candy Crush on her iPhone if she forgets the wifi
               | password.
        
               | olyjohn wrote:
               | I suppose you're right. Just after seeing my family lose
               | internet a bunch of times due to the ISP supplied router
               | just straight up failing, I don't have much confidence in
               | the hardware. Also I don't think that rebooting the
               | router once a week because it's frozen makes it a quality
               | product that brings satisfaction. I've never seen an ISP
               | supplied router that isn't like this. But that could just
               | be my personal experience.
               | 
               | I mean, when the first thing you hear when you call your
               | ISP, is to "reboot your router" on a recorded message,
               | doesn't that throw a red flag to anybody else? I don't
               | use high end gear at home like Cisco, either, but it has
               | never needed a reboot.
        
             | x0x0 wrote:
             | No, AT&T is still shipping with a router that cannot hit
             | more than 50% bandwidth on any of 3 devices from under 5
             | feet. With one wood + pressboard wall between me and the
             | router, 25%.
             | 
             | This is symmetric gigabit product, but still.
        
               | kube-system wrote:
               | You've described a technical problem, not a non-technical
               | problem.
               | 
               | I'm not familiar with that device, but a non-technical
               | user might not care about that "problem", as long as
               | their device does the task they are intending to perform.
        
               | fragmede wrote:
               | The problem is being described technically, which is more
               | useful than the non-technical description of the problem,
               | which is "I don't know, the Zoom isn't working, and the
               | kids can't watch their Netflix at the same time".
        
               | kube-system wrote:
               | Yes, but Zoom and Netflix will work great on 50% or 25%
               | of 1gbps. Heck, they'll work great with 5% of 1gbps.
               | 
               | I am sure that AT&T's CPE equipment is lackluster, but
               | that doesn't mean it won't work to do basic tasks to the
               | satisfaction of a home user.
        
               | x0x0 wrote:
               | I dunno what to say, but it does not do basic tasks to
               | the satisfaction of people who buy 1gb internet
               | connections.
               | 
               | I can tell you from experience that large downloads and
               | uploads cause latency-sensitive applications to stutter
               | in a way that is fixed by using ubiquiti gear.
               | 
               | In your defense, you did say non-technical household, but
               | I dunno -- I don't think that wanting to use, eg,
               | backblaze for backup and not have that tank zoom makes
               | you a technical household.
        
           | syntaxing wrote:
           | I think UnifiOS is pretty straight forward (at least for my
           | generation). I don't think I would recommend it to my parents
           | but I did to a sibiling and they managed to setup their own
           | system with only a little bit of help from me. I also sent
           | them the awesome lazy admin VLAN guide which helped a ton.
        
         | bityard wrote:
         | I'm pretty bad at coming up with business ideas, but one that I
         | think would work, if I ever got the time to do it, is a user-
         | friendly x86 router firmware centered around the idea of making
         | it as easy as possible to set up and control your network and
         | its devices.
         | 
         | On my home network, what I really want is the ability to define
         | one or more networks (VLANs, if you will) and then place
         | devices in those networks. When you click on a device, you are
         | then able to do things like give it a static IP, look at the
         | traffic it's generating, shape its traffic, disallow traffic
         | from/to certain ports, kick it off the network at certain times
         | of day, allow it access to the local network but not the
         | Internet, change its DNS resolvers, etc.
         | 
         | In order to do these things on most routers, if they offer the
         | ability at all, you need to jump around to different places in
         | the UI and manage each service as its own thing. OPNSense is
         | great (and it's what I currently use) but it's UI is really
         | just multiple little windows into the various sub-services that
         | the firmware provides. Separate page for _all_ the firewall
         | rules, another for _all_ the DHCP leases, etc. It works, but it
         | 's kind of frustrating to use, especially when you're not
         | digging around in it every day.
         | 
         | The business model would be: everything open source, but three
         | "tiers" of releases: 1) free "beta" releases featuring new and
         | lightly-tested features for the adventurous. 2) "stable"
         | releases via subscription (paying customers have access to the
         | source code and build tools) 3) "freeloader" releases, the same
         | as "stable" but with a 6-9 month delay.
         | 
         | Devil is in the details of course, but if I had any
         | entrepreneurial bent at all, I think it would be a big
         | improvement over the current state of things.
        
       | stusmall wrote:
       | One possible explanation for this can be a mistake in caching.
       | While it is tempting to log in and see if you can see other
       | people's consoles... that just might put you in the cache for
       | someone else to see.
       | 
       | There is no way for us to know what is causing the bug and what
       | will help without official word for Ubiquiti but logging in can
       | only possibly hurt and won't help.
        
         | SigmundA wrote:
         | Yeah seems like a caching issue where the cache isn't properly
         | segmented by user.
        
       | tomkinstinch wrote:
       | For anyone with a UDMP looking to disable remote access via UniFi
       | servers, the setting isn't under the Network application, it's
       | part of the higher level console management:
       | 
       | Console Settings (menu on left) -> Advanced (heading) -> "Remote
       | Access (checkbox)"
       | 
       | Or via: https://$UDMP_IP/console-settings
       | 
       | (Hopefully the setting applies locally...)
        
         | cmsj wrote:
         | And note that to see the Remote Access checkbox, you need to be
         | logged into the console as a ui.com user, not a local user.
         | 
         | If you have disabled Remote Access and instead want to use the
         | phone app via a VPN, you may have to add it manually. There's a
         | (+) button for that, and then a "Need help?" option, which
         | contains a way to manually add by IP/user/password.
        
           | _rs wrote:
           | If only you could do this with the Protect app...
        
       | twisteriffic wrote:
       | Had a "is this actually your local console?" Prompt from protect
       | this morning. I'm getting a bad feeling about this.
        
       | awill wrote:
       | I have a few unifi things at home, and for the most part, they've
       | been good, and work well together. But this sort of stuff is very
       | concerning, and forcing the cloud account on everyone is really
       | stupid.
       | 
       | But what are the alternatives. Firewalla seems to be a good
       | alternative, but they don't do APs, leaving me with a mixed
       | system.
        
         | elteto wrote:
         | Using the cloud is not required, you can set everything up with
         | local access. Certain products, like Protect, do require cloud
         | access. But not the base networking stuff.
        
         | latentcall wrote:
         | I use a Firewalla with TP-Link Omada AP's, works great. Don't
         | really mind the mixed system aspect. Recommend!
        
           | awill wrote:
           | why not use an Omada gateway/router too?
        
         | apearson wrote:
         | From I remember Firewalla (app only) is more dependent on the
         | cloud than Unifi
        
         | miles wrote:
         | > Firewalla seems to be a good alternative
         | 
         | https://old.reddit.com/r/firewalla/comments/14gf1j1/major_se...
         | 
         | https://old.reddit.com/r/firewalla/comments/177egzl/summary_...
        
         | zzzeek wrote:
         | im running unifi here and I've never dealt with any of this
         | cloud stuff, there's a checkbox called "enable remote access"
         | that defaulted to false for mine and I'd never check that box,
         | so hopefully it's not actually "forced" ?
        
       | Macha wrote:
       | My decision to not enable remote access feels vindicated now.
        
       | throwaway202312 wrote:
       | If I had to take a guess they might be using a CDN like
       | Cloudflare and temporarily misconfigured a cache rule...
        
       | freedomben wrote:
       | When people ask me why I don't use Ubiquiti products, and I tell
       | them that I don't trust companies with closed/proprietary
       | offerings with something as critical as this, I get a lot of
       | skepticism and even eye-roll. Open source isn't a silver bullet,
       | but if I were self-hosting my own "cloud" controls I wouldn't be
       | worried about something like this.
        
         | luckydata wrote:
         | honest question, who do you trust that provides either high end
         | residential or SMB type networking gear that works well? The
         | average residential stuff is all garbage and I was looking into
         | unifi because seems to work better but I'm open to suggestions.
        
           | aftbit wrote:
           | I personally run a bunch of obsolete Aruba, Juniper, and
           | Ruckus gear at home. It works pretty well, doesn't cost very
           | much, generally doesn't require licenses or cloud, and
           | supports every feature under the sun. The only problem is
           | power consumption, but I don't mind burning ~200W on my whole
           | house's network infrastructure.
        
       | tokamak wrote:
       | Feels like the issue Steam had with caching
       | https://securityaffairs.com/43189/security/steam-users-data-...
        
       | cmsj wrote:
       | The real question here for me is: why is my data not flowing
       | through Ubiquiti's servers end-to-end encrypted?
       | 
       | They should be able to accidentally send my data to another user
       | and have it merely result in a decryption failure.
        
         | smcleod wrote:
         | I think you mean encrypted at rest (data) with you holding the
         | decryption key not e2e (https/tls) which is from your network
         | to their network.
        
         | rekoil wrote:
         | I have been hoping for them to go this route for a while now,
         | maybe eventually they will.
        
       | calamari4065 wrote:
       | I built a UniFi network 6 or 7 years ago. I was pretty excited,
       | as the hardware seemed properly solid. A touch expensive, but I
       | was expecting it to run forever, essentially.
       | 
       | The hardware was actually really good from what I could tell. Not
       | a single issue that wasn't caused by my own misconfiguration. But
       | the software, woof. The software was designed to do exactly one
       | thing: look impressive to execs in a board meeting. It was nearly
       | unusable for me. I don't recall any specifics, but all you really
       | need to know is that it took multiple days to get a simple home
       | network with a single AP and a single router set up. It was so
       | much effort just to log in to the damn thing.
       | 
       | I went into this project excited at the prospect of all the cool
       | monitoring and analytics I could do. Fancy security and remote
       | access and whatnot. After I finally got everything configured, I
       | never touched it again. There were a few times when I needed or
       | wanted to get into it, but I couldn't remember the specific
       | incantation and combination of software needed to access it, so I
       | just didn't.
       | 
       | I'd _love_ to have a solid system built on quality hardware.
       | UniFi is notionally exactly what I want, and exactly what a _lot_
       | of hackers and tinkerers want. But the quality of your hardware
       | is pretty much irrelevant if your software wasn 't designed to be
       | used by humans.
       | 
       | So I'm stuck using consumer routers with open firmware. It's fine
       | I guess.
        
         | riley_dog wrote:
         | I run OPNsense, but use UniFi hardware. I rarely ever have to
         | interact with the UniFi software as it's only there to
         | configure the hardware.
        
           | aftbit wrote:
           | OPNsense can target UniFi gear? Does it manage the switching
           | and APs too?
        
             | JAlexoid wrote:
             | You use OPNsense as the router, but the rest of the
             | equipment is managed separately.
             | 
             | I don't know of a system that works across multiple SDN
             | solutions.
        
             | teekert wrote:
             | I don't think riley_dog means they somehow controls Unify
             | APs with opnsense. I think he just configured the APs with
             | the Unify controller, the never touched them again and left
             | all routing to an opnsense box.
             | 
             | This seems to be a popular approach, as there are no
             | attractive routers from Unify, there was the Ubiquiti Unifi
             | Security Gateway (USG), which ran very hot but was
             | affordable and small (EdgeRouterX-like). Now they have the
             | Dreamrouter, which has everything in one, including Wifi.
             | It looks like an Alexa tube. There is a gap in their
             | offering if you ask me, I'm also looking for a nice simple
             | 2 nic opnsense box (preferably a nuc(-like)), after I blew
             | up my EdgeRouterX (used the wrong power supply).
        
         | letitbeirie wrote:
         | My situation is basically the other side of the same coin: I
         | built out my network 7 years ago using _Edge_ gear instead of
         | UniFi.
         | 
         | The hardware is solid and the software isn't flashy but it's
         | reliable. It's exactly what hackers and tinkerers want, so
         | naturally Ubiquiti has all but abandoned the entire product
         | line.
         | 
         | They haven't discontinued it (yet) so I could still replace any
         | piece of it if I needed to but their software version history
         | doesn't exactly paint a picture of a product that's cherished
         | or actively invested in:
         | 
         | 2019/03/28: v2.0.1
         | 
         | 2019/05/30: v2.0.3
         | 
         | 2019/06/25: v2.0.4
         | 
         | 2019/07/16: v2.0.6
         | 
         | 2019/12/04: v2.0.8
         | 
         | 2020/03/09: v2.0.8-hotfix1
         | 
         | 2020/11/18: v2.0.9
         | 
         | 2021/02/02: v2.0.9-hotfix1
         | 
         | 2021/06/13: v2.0.9-hotfix2
         | 
         | 2022/07/17: v2.0.9-hotfix4
         | 
         | 2022/12/20: v2.0.9-hotfix5
         | 
         | 2023/01/22: v2.0.9-hotfix6
         | 
         | 2023/07/31: v2.0.9-hotfix7
        
           | panopticon wrote:
           | My EdgeRouter finally bit the dust after over a decade of
           | service, and I decided to "upgraded" to a Dream Machine. I
           | was hesitant due to the security breaches and now I really
           | regret my decision.
        
             | favorited wrote:
             | UDMs are discounted right now for the holidays. I'm in the
             | process of migrating my home networking/server stuff into a
             | rack, and I was tempted to pick one up because my current
             | little PFSense box isn't particularly rack-friendly. This
             | thread is cooling my heels a bit.
        
             | snom380 wrote:
             | You can run your Dream Machine without cloud access,
             | though?
        
           | specto wrote:
           | Believe it or not, there's a 3.0 beta now
        
         | BitPirate wrote:
         | Ubiquitis Unifi controllers and the TP-Links clone called Omada
         | always remind me of the glory days of the NoSQL fad. Want to
         | install our software? Please add a third-party mongodb
         | repository to install an obsolete version. They can't handle
         | version upgrades of their own database properly, but hey! At
         | least it's web-scale.
        
           | smileybarry wrote:
           | They also need a _32-bit_ version. The actual, easiest
           | solution to appliance-ify Unifi OS was to take some  "run it
           | on your Raspberry Pi!" guide and convert the instructions to
           | Debian 32-bit.
        
             | bmicraft wrote:
             | The real easiest solution is to use a third party docker
             | container
        
               | smileybarry wrote:
               | True, but I don't actually trust it. And the last time I
               | tried manually building it, it didn't entirely work.
        
           | smcleod wrote:
           | But it's webscale!
        
         | cyode wrote:
         | > 6 or 7 years ago...it took multiple days to get a simple home
         | network with a single AP and a single router set up.
         | 
         | I just tried the same thing last week and it took an hour (half
         | of that was mounting it to my ceiling). I only set up a WAP
         | though, no controller.
        
         | tinix wrote:
         | pcengines apu platform is great if you're comfortable with
         | command line. they are EOL now (no new hardware updates) but
         | doing the same thing with any Linux box is trivial... plenty of
         | off the shelf options for modular hardware.
        
       | boeingUH60 wrote:
       | _Random fact_ : Ubiquiti is publicly traded, yet Pera owns 90%+
       | of it, meaning shareholders virtually have no power to push for
       | changes. You might as well call it a privately held company, lol.
        
       | barbazoo wrote:
       | Easy to host the console yourself: https://help.ui.com/hc/en-
       | us/articles/360012282453.
       | 
       | There's even a docker image for those who have trust:
       | https://github.com/linuxserver/docker-unifi-controller
        
         | jonathantf2 wrote:
         | Not if you use their "Dream Machine" line of products - you
         | have to use the controller that's self hosted on the box. I'm
         | currently trying to figure out how to disable the cloud
         | connection on these and go back to good ol' open ports to
         | manage the thing.
        
           | erupt7893 wrote:
           | I haven't tried yet but looks like this was posted above with
           | how to disable cloud connection
           | https://news.ycombinator.com/item?id=38644073
        
         | Rudism wrote:
         | It should be noted that the repo you linked is for a deprecated
         | image that's losing support at the end of this year:
         | https://info.linuxserver.io/issues/2023-09-06-unifi-controll...
         | 
         | The note I link above discusses its replacement and how to
         | upgrade.
        
           | Khaine wrote:
           | Thanks. I didn't know about this.
        
         | InTheArena wrote:
         | Eh. you don't need that for any of the hardware that appears to
         | be affected. Just turn off cloud access.
        
       | sschueller wrote:
       | Ah the beauty of cloud connected networks management. A hackers
       | delight...
       | 
       | And then I am the one that gets chastised for not wanting cloud
       | connected router/switches in my networks.
        
       | MenhirMike wrote:
       | Does anyone have a recommendation for a replacement? After the
       | requirement to create a cloud account on their so-called "Pro"
       | Dream Machine I already felt something is wrong, and after
       | "Please don't use shielded Ethernet cables with our so-called
       | "Professional" WiFi Access Points, they can randomly reboot"[1]
       | and now this nonsense, I'm just simply done with them.
       | 
       | But I really like the hardware of the Dream Machine Pro (Router,
       | Switch with 10G uplink) and the overall view of clients and
       | connected devices, so I don't just want to buy some random Router
       | and pair it with random WiFi APs - though I guess that's the best
       | choice?
       | 
       | [1] https://help.ui.com/hc/en-
       | us/articles/8823742725015-UniFi-6-...
        
         | InTheArena wrote:
         | There is no requirement to create a cloud account on the Pro
         | machine.
        
           | MenhirMike wrote:
           | There used to be a mandatory ui.com account when it came out.
           | If they finally got rid of that nonsense, that's great news.
           | 
           | And yeah, looks like the v1.1 update removed it
           | (https://community.ui.com/releases/UniFi-OS-Dream-
           | Machines-1-...): "Allow to set up a console without an SSO
           | account."
           | 
           | The fact that they decided to release a "Pro" product with
           | that requirement initially still counts heavily against them:
           | What were they thinking, and why should I trust them if they
           | are making such decisions?
        
       | xyst wrote:
       | UI just can't catch a break.
       | 
       | Earlier this year, some tech tabloid (krebsonsecurity?) reported
       | how bad security was at UI. I think it was ultimately determined
       | to be a bad story and UI sued for defamation.
       | 
       | Now we are here again with another possible leak.
        
         | InTheArena wrote:
         | This was multiple years ago at this point.
         | 
         | this is why smear attacks work. Someone on a different hacker
         | news thread today was stating that the car that blew up at the
         | Canadian border was a Tesla (It was a bently).
         | 
         | I've seen these types of bugs before. I think they introduced a
         | very bad credentials or session bug. The good news is you can
         | turn cloud off for all of these, and they work just fine.
        
           | fragmede wrote:
           | Or how the one fire in a Tesla in Florida following a
           | hurricane became a whole fleet of every EV in Florida
           | spontaneously combusting. A lie can travel halfway around the
           | world while the truth is putting on it's shoes.
        
       | op00to wrote:
       | It's unlikely that simply seeing things in the main console means
       | you'll be able to change things if this is a caching issue. It
       | can still expose passwords and other internal information you
       | don't want to get out.
        
       | cogogo wrote:
       | Odd coincidence in that I had the same problem with Ubiquity the
       | 401k provider several years ago. Could see most of my colleagues
       | 401k accounts. Never good.
        
       | arcza wrote:
       | Nice, yet another breach that doesn't affect me self hosting my
       | Unifi controller.
        
       | everdrive wrote:
       | I feel very vindicated for avoiding the cloud solution when
       | everyone was praising Ubiquiti back in 2016 or so.
        
       | hk1337 wrote:
       | I tried the AmpliFi mesh router several years ago and hated it.
       | It didn't seem any better than the Arris gateway that ATT sent
       | me.
       | 
       | Why would you have a central console that has the potential for
       | accessing all the routers with a single login though? Why
       | wouldn't this be just local to the network with remote access?
        
       | InTheArena wrote:
       | https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misc...
        
       | aetherspawn wrote:
       | So what's the alternative for SMB... Cisco? Where can we buy this
       | stuff cheap without going through an IT company..?
        
       ___________________________________________________________________
       (page generated 2023-12-14 23:01 UTC)