Ubiquiti Networks Breach
mailchi.mp
mailchi.mp
The saddest part is that we had many good engineers who could have continued to do amazing things with the UniFi momentum. So much time was wasted on dead end products like FrontRow. Most everyone I know left for jobs where we were treated better and paid more.
That said I don't hear the best about the company (long working hours, not the highest pay) and have declined a job offer there myself.
As someone who lives in a low cost country: rubbish. There's a reason we're a lower cost.
1. We have a lower standard of education
2. We have a higher cost of technology (relative to average income)
3. We have a lower need for the luxury market where most technology resides
You can also look at the proportion of field leaders. Are more from the developed nations or the developing ones?
The developed nations had a headstart on technology, do you think the developing ones have overcome that, despite most of us going backwards in terms of access to education and the wealth gap?
Don't take it personally, I'm not trying to tell you that you're a bad developer. What I'm saying is we have to work harder to uplift our country's fields and not fall into the trap of "well I'm the biggest fish in this tiny pond so therefore I'm an equally big fish in the ocean". It does not work that way.
I'd like to also add that from my own perspective Ubiquiti gear and software is/was _exceptionally_ good. So converting to "just another network gear company" level of quality is going to have a much greater impact on my perception of the company compared to if this news of off-shoring came from say cisco.
Almost forgot, but just last month my wife started complaining about the WiFi, turned out the latest firmware that was pushed to my UAP's is horrible. You have to turn off auto update and check reddit before upgrading firmware, what a joke!
> I hope it's not "the company is declining because the company moved talent to countries where developers are cheaper"
We probably agree the cost of developers varies considerably in different locations.
Companies operating in markets where local developers are expensive (I work near London for example) sometimes decide to outsource development to locations where it is much cheaper (e.g. India).
What I have seen (admittedly just anecdotally, not carefully studied and subject to bias) is a correlation between companies that don't value high quality software development and companies that are happy to dump a substantial part of their development efforts on cheap developers overseas.
Such companies don't care about their existing team - developers who are expensive but have built the software and understand it, and are to some extent understanding the end customer (often filling gaps left by product managers in smaller organisations). They just see their development team as a huge cost that needs to be reduced. Or they have trouble hiring locally.
When the daily rate of developers overseas is substantially lower, the company also doesn't care about those developers. They will want to outsource the least creative and satisfying work to them. They want to just fire and forget: "here's the spec, go and build it". Lower productivity is less of an issue if the "resources" are cheap. I'm over simplifying and I'm sure some companies try to work more in equal partnership but you get the picture.
Also, the move to outsourcing is often done suddenly; it's more like wielding an axe than an organic growth or shift in development model. Companies don't tend to invest in overseas developers as individuals.
In my view it's not great for either set of developers, or for the customers of that company. Perhaps when done right it can be more beneficial and I hope things will improve overall.
You cut my quote short of the important part which was "and employees complained less about constant crunch mode". It is easier to "trap" engineers in countries where average salaries are lower by offering them 20% over market rate and then threatening to fire them if they don't work constant crunch hours. We were promised very large bonuses that never arrived.
> That said I don't hear the best about the company (long working hours, not the highest pay)
It is a sad situation. The pay was very good and the working hours were reasonable when I started, but that changed for the worse. That is why all of my peers left the company.
My company started doing the same and erosion of knowledge is really bad.
You are saying the same as the parent. Expecting “short” hours is seen as “feeling entitled”... There are countries where people are not willing to work in those conditions.
Bottom-of-the-barrel developers bring even greater savings, and paying peanuts has always been a great way to get monkeys.
Are there any other "prosumer"-type devices on the market that could replace a Dream Machine? If Unifi is going downhill it doesn't seem like I'll be going with them for a replacement.
Opnsense forums have lots of recommendation for hardware, which is the path I went recently. I went with https://protectli.com/, which are just some rebranded hardware sold on Alibaba, but they provide support ontop of the hardware.
The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.
Data leaks happen! It shouldn't but that's just how the world is. UI has been honest about it, and informed every customer as a precaution. (I assume they're still investigating).
I can't be sure, but since UniFi Video went offline at the same time the breach was announced, a week earlier than it was scheduled to, that might have been the entry point.
In any case, the UDM (despite all the negative talk) is a fine machine, and does what it promises to do. If you want similar performance you're either looking at building something yourself, or paying twice of what you paid for a firewall appliance. The Netgate SG-3100 has less performance at twice the cost.
You need a UI account to set it up, but that doesn't mean you have to allow managing it from the cloud. Disable the cloud controller access and any access to your firewall configuration will have to happen from your local network. I'm unsure if you can disable the UI account, but i have a spare UDM sitting around so i will test it.
I used to have several Ubiquit USG devices as well as their EdgeRouter.
I moved to pfSense as it's open-source, more stable, and gives you much better control/configurability on your hardware. There's a great ecosystem of packages on pfSense, that you can install via the web UI - making it a really feature-packed for a homelab.
However, recently I've been moving to VyOS to pfSense, which is basically a stripped-down Linux distro, with a heavily tuned FRR routing stack built on top of it.
VyOS is an open-source fork of Vyatta, which was previously owned/released by Brocade networks.
It operates with a CLI, like many enterprise/commercial routing products. It takes a bit of getting used to, but it's really great to use in practice, and makes it easy to diff configurations, or rollback changes, or copy the same configuration across multiple devices.
And of course, it implements with config-management software like SaltStack/Ansible (via Napalm), which is something that pfSense. If you have multiple pfSense devices, you basically need to point/click via the web UI on each one.
For APs - Ruckus is great, as is HPE/Aruba (they have a new low-cost line that's targeting the Prosumer market) - they have both been leaders in the wifi field for ages, and have things like AP handover, RF tuning/optimisation, adaptive antennas etc down pat.
The wiki is good and the community is really friendly. If you have networking experience or want to something to tinker with it’s a nice deal. If you want something you can set and forget I’d look elsewhere though as the UI is not friendly at all.
Their WiFi APs are behind the curve (no mu-mimo even afaik), but you can just hook up some other wAP if you need the newer protocol features.
What I do is keep a Mikrotik router that does all the heavy stuff and hang wAPs off of it as needed. I especially love capsman for wAP management. They do have all-in-ones of course, just not my cup of tea.
It is on the expensive side, but the hardware is beefy and you get vendor's support for OpenWRT out of the box.
I’m a big fan of the ecosystem and I’ve recommended it to many people but I’m constantly astonished by the slow pace of hardware updates.
Not sure where to go next, but it probably won’t be Ubiquiti.
Robert Pera (the CEO) got his start in the industry in San Jose.
Here's a review: https://seabits.com/teltonika-rutx11-lte-router/
I once worked for a company, there were some "grievances" between the programmers and CEO (nothing major) but enough to elicited a "meeting" between all the devs and the CEO to "smooth" things over and build a better path forward, we will all in high spirits for the meeting and optimistic.
The very FIRST opening line from the CEO in the meeting was:
"How extremely lucky we(programmers) are to be working there..."
It all kinda just went downhill from there... 6 Months most of the programmers quit.
It's not traditional networking gear, sure, but I can certainly see the play they're making, so I wouldn't call this a scatter-shot approach.
openwrt is based on Linux
I hope things are better now.
He's not wrong
In this case, the cleaned URL that should have been posted is https://mailchi.mp/ubnt/account-notification
I'd argue that this feature is not worth the privacy invasion, but for it to work, you do need a secret in the URL that is always personal.
> The networking company quickly followed its email with a post on its community pages confirming that the email was authentic, after several complained that the email sent to customers included typos.
Indeed: How am I supposed to know whether this email is really from Ubiquiti?
* There was apparently no official press release.
* All links in the email, including the "Change password" button, are to e.g. `https://ui.us8.list-manage.com/track/click?u=somehexnumber&i...`.
* The delivering server is `mail42.atl11.rsgsv.net`, which the TLD of which doesn't seem to resolve in my browser to provide hints.
* Various news sites that reported this either just referred to "emails people got", screenshots random people got via Twitter, or link to the Mailchimp site, for which I'm not sure how to verify whether the "ubnt" account actually belongs to Ubiquiti.
Given this, how shall the normal affected user figure out that this isn't well-executed phishing?
It seems companies could do a much better job making it obvious that their emails are legit. Especially if they were just breached, and "Change password" buttons are involved.
I'm still quite annoyed by the fact that I was forced to migrate from Unifi Video to Unifi Protect - due to vendor lock in and the fact that the remote interface for Unifi Video was switched off this month.
I guess on the plus side - no one who is still using Unifi Video has to worry all that much.....
Hopefully it is just a case of resetting passwords and enabling 2FA if you haven't done it already - not entirely sure how much damage could be done otherwise, unless there is an undocumented backdoor into Ubiquiti products ?
Basically they are alienating their existing customer base (who have already paid a premium price for the prosumer product upfront and expect things to Just Work for the price) in favour of convincing the next idiot to fund their OPEX with shiny new features and toys that are a quick sell. Not realising (or unwilling to realise) that this strategy is completely in contradiction with their reputation and brand image as trustworthy prosumer hardware vendor, and just adds to the underlying issue.
I predict that it won’t be long before they run out of cash or investor confidence and have to sell out to a large consumer hardware vendor with deep pockets that will try to capture the Ubiquiti premium margins by selling their lower-value existing consumer gear under the Ubiquiti brand. I applaud them for having come this far while maintaining most of their integrity and reputation, but I’m afraid their strategy is doomed to fail and it’s starting to show.
Yeah, this has been really baffling. Their settings UI has been in a transition state between "Classic Settings" and "New Settings" for years. Neither is complete. Some settings are only in New Settings (e.g. WiFi AI), while many more are only in the Classic Settings (e.g. allow multicast from Ethernet to WiFi).
More the old guard leaves, the more of the old guard that leaves. Then who is left to train the new people?
"Do not choose the skip option when running the Migrate Site wizard. If you do your devices may end up in a weird state."
https://unifi-forum.nl/index.php?threads/unifi-sdn-controlle...
For me, that’s a good outcome because I won’t be bothered by their updates for my currently-working unifi video setup anymore.
Alternatively, you can use their hardware with an alternative serf-hosted NVR like zoneminder.
The cameras work just fine in standalone mode as RTSP sources.
One of the great things about ubnt was the ability to self-host their management software on a Ubuntu VM or container.
Why does every company, after demonstrating a lack of security, like to say this exact line? I can just imagine the PR person hovering over the shoulder of whoever authored the post yelling "make sure you tell the victims of this breach that we care!"
[0] Maybe not technically a franchise. Not sure. There are a bunch in California.
> .. never had any safety issue so far
It's the 'so far' which really tickles me.
So they can take your security seriously, but they will be hacked, or they have already.
It was a light-hearted jest at the fact that this exact line is in every single breach notification I have read for the past few years.
The more serious point I was alluding at was not "just don't get breached", it was that the "we care" line rings hollow after the 250th time reading it.
They could have not done that. The users were probably unaware that their data was even placed on the cloud servers of some third party.
Ubiquiti used to be cool. They've taken a nose dive in recent years in several ways: Firmware upgrade suddenly including telemetry by default, forcing people to use their NVR appliance instead of installing their software on their private servers, etc.
Had Ubiquiti not moved people to "cloud solutions" an attacker would have to attack millions of peoples equipment. Now he only had to attack one providers network.
When did they stop allowing people to use a private server for central management? I see Unifi still has a network controller.
I'm thinking of "Unifi Video" that is going out (EOL announced six months ago), where you could either buy their appliance OR download an official .deb package and install the NVR software on your own server.
They replace that with "Unifi Protect" that comes ONLY as an NVR appliance. No more .deb packages. It also requires you to buy one of their other products (Cloud Key 2), IIRC.
I think it's expensive, but possible.
Do you have data to back up your claim that no one, ever has ever successfully remained secure?
That will be the new norm in these kinds of annoucements, I'm sure.
Just like SolarWinds dropping "Team City", saying "no evidence" of a breach of it. So why mention it at all?
‘We know they breached but don’t know what they did’ is an interesting statement. One POV is that they didn’t have sufficient logging and segregation to determine how widespread the breach was, the other is that they’re not arrogant enough to think their SIEM adequately captures everything.
Aren't they based in California which, if I remember correctly, as a law requiring them to notify the victims of a data breach?
Would they still have chosen to in the absence of such a law? We'll never know, I guess.
No, that is not what I'm saying. I'm saying don't put platitudes in a breach notification.
HAHA ! Too True !
Reminds me of getting "punished" as a child...
Parent: "Now remember this will hurt me more than it will hurt you"
PS. No child were abused in the making of the above comment. My parents were/is excellent !
WHAT? I bought this stuff so I could self-host and _not_ rely on other services. I guess I didn't do enough research when investing in new hardware. I didn't see anything in their spec. sheets or descriptions about needing cloud for Protect access.
I really like ubiquiti hardware but I got fed up with their software BS. Now I use either Mikrotik or TP-Link’s industrial offerings. Both are way easier to work with than ubiquiti and the hardware is usually in the same tier.
Do not get me wrong, I love Mikrotik, but easier would not the word I would be using. This image (https://www.reddit.com/r/mikrotik/comments/jyjgnc/mikrotik_v...) sums it up neatly.
Also, Mikrotik is not directly comparable, you cannot replace Unifi Controller with Capsman.
So in the end, for APs, I'm using Unifi.
The big problem with the Ubiquti thing is that it takes a long time to start, so if your usage model is to start it whenever you want to make a change it's rather piggish. If you start it once and leave it running forever on a dedicated device it's not nearly as bad.
Also it usually works fine, but when it breaks, it breaks HARD
After the initial installation and configuration was done, I've probably only logged into it a handful of times.
(With the exception of their APs and said controller, I avoid Ubiquiti as much as possible, though.)
Is there a better alternative? When I tested multiple routers mostly regarding low latency, network stability and reliability a few years ago nothing came close, especially when having multiple access points.
My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G switch. Their RB-4011 was a perfect fit, without any of the Ubiquiti SSO/controller stuff to worry about.
I haven’t explored their WiFi products yet (still using an old router as an AP) but their product range is pretty broad. Might look into it this year though.
Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?
Because there are so many features the setup is not as easy as some alternatives I'm sure. But the value proposition is great.
Their "RouterOS" is standardised over pretty much all of their kit. So after you have worked it out once you should be set for anything else.
> RB-4011 was a perfect fit
Huh, isn't RB4011 the one with the very weird "you can't use a DAC in the SFP+ port" limitation?
> haven’t explored their WiFi products yet
They seem extremely underwhelming, especially in terms of software support :(
https://help.mikrotik.com/docs/display/ROS/WifiWave2 — they're finally barely rolling out WPA3, MU-MIMO/beamforming, 802.11w — in an optional beta package for a beta version of the OS, currently on 4 devices, breaking 2.4ghz on one of them, and breaking CAPsMAN (centralized management).
Also RouterOS does not seem open source.
Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet).
Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras.
Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment my Google WiFi. I'm happy with the Google WiFi, and in particular it has good tools for managing kids access to WiFi. But the Ruckus APs are quite good and so I may move parent and IoT access over to Ruckus, separate out IoT devices to their own network.
This is the end of phase 1. Then I plan to go on to:
Add an OPN-Sense router. Currently not using Ubiquiti for routing, the Google WiFi is our main router. Would like to gain additional capabilities like insight into what the kids are doing.
Replace the Ubiquiti Dome G3 with one of the less expensive 4K cameras if they seem to provide similar or better functionality. Also trying out the Wyse Cam v3, which seems ok and the price sure is right, but is more of an augment camera than a main camera, I prefer wired and PoE.
I've been doing some research and those are the options that seem attractive. In particular, going with old enterprise gear looks to be a huge win. You do lose that handy "single pane of glass" management. But considering the problems I'm having with Ubiquiti, and the upgrades I've already done to try to get past them, with only some success, I can't bring myself to go further in on Ubiquiti.
Can you get free firmware updates from Aruba or do you need a support contract?
Similarly for the Ruckus R610 AP I mentioned: Those APs were a grand new, but you can get them for a bit over $100 on ebay. Linus Tech Tips did a comparison of it with other consumer units, doing heavy multi-device streaming, and Ruckus was the clear winner.
Yes, Ubiquiti looks like a good value and they make some very interesting products. I've used some of them to great effect over the years. But my experience with the NVR and cameras and switch and Cloud Key has been relatively bumpy. Enough so that I'm ready to ditch the convenience for up-front loading and hopefully day-to-day more realible.
I don't usually run any services since I prefer to dedicate boxes to things, but I have in the past run a number of services, including minecraft and minetest on it and it flies. Really pleased with it.
There's Xeoma and Blue Cherry, neither of which I know very much about. Never heard anyone mention either of them. So I figured BlueIris was what I'd try. Seems to be what everyone on YouTube is using...
The other reason I decided to 'roll my own' was an in-line IDS. There seem to be 'hacky' ways to get Snort installed on the RouterOS platform, but the CPUs aren't really powerful enough to run DPI with a sufficiently large ruleset.
I also like the ability to use Ansible to manage my router/firewall. There are modules available to do this with RouterOS, but they don't seem nearly as robust and mature as the built-in Linux utilities.
I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CPU is a must.
Outside that, wifi part is hard to get right and smart switches are nice to have, but they are PITA if the firmware is never updated and there's no single place to nicely manage it all.
https://www.raspberrypi.org/products/compute-module-4/?varia...
https://www.zahradnik.io/raspberry-pi-as-a-home-router
Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/ThomasKaiser/sbc-bench/blob/master/Result...
You were probably thinking of OpenVPN? Wireguard is not based on AES and thus has no use for AES-NI.
The cons are that everything has one or more "mikrotik" way of doing things, and it may not be intuitive to the new user. Also, although everything is included, you have to set it all up yourself.
They’re still sending out the email. Mail chip will be rate-limiting the send rate to prevent email providers from block listing them.
Give it a couple of hours and no doubt you’ll have an email as well.
You do need a Ubiquiti account to setup the hardware in the first place, but you can turn off cloud access and login locally after that. And you should.
When it comes to software, I'm conflicted. I like pfsense, but Netgate has gone a bit sour with the FLOSS community. I'd also consider OpenWRT, FreeBSD, OpenBSD.
I had to do some work to get it to boot properly, and it worked great for a year or so, but then it just died one day, and I could never figure out what its problem was.
Out of warranty by the dead date, never bought another.
Been using a $100 HP 8300 SFF with an i7 since, it's a bit overkill, but the price was right.
Just purchased a Lenovo M90n iot when it was on sale for $215, will see how it works out once I get it.
I haven't kept up with pfsense. Any chance for a tl;dr?
I think for some use cases this setup could be a nice alternative (and cheaper) to ubiquiti.
This is not a common use case, I was not interested in high bandwidth. I did try to disable beamforming and all other fireworks when testing though (but did tests with default settings too)
Honestly, unifi is great for what it is. What kind of IPS do you expect for $100?
If you want less risk, you need to move up the $ ladder.
The only issue I have with Netgate is pricing!
We are just as susceptible to the stuff haha.
So basically all you need to do is plug a laptop into a non-Unifi switch on someone's Unifi network and are able to breach the firewall.
Needless to say I was flabbergasted at the vendor lock-in strategy worse than Apple, and asked for a refund. Thankfully they complied.
I now have a hand-rolled OPNsense router that does everything I need, and with MUCH more configurability.
As another comment said, your strategy about breaching the firewall is confusing but it sounds like a configuration issue. If your aim is to default deny outbound traffic, or traffic from or across the LANs except for approved devices, that’s an achievable aim regardless of what switches are in the mix. If you’re trying to do port level security, you’d need a managed switch, Ubiquiti or no.
You had unmanaged switches on your network, and were trying to manage thier downstream connections?
What exactly do you mean by 'breach the firewall'?
Could you elaborate a bit more about your previous network setup? This sounds awful.
Another company's network products I work with technically has a self-hosted version of their management service, but it doesn't scale down well (it expects dozens of GBs of RAM and to be running on SSD storage or it's not supported). I've regularly felt pressured to move to the cloud just to avoid the jankiness.
The difference is, their potential for bad behavior, risks and attack surface is far, far greater.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
I do have over 100 devices on the Dream machine + 4 AP-HDs network, but Unifi promised to make my network rock solid, and it's been anything but.
https://old.reddit.com/r/Ubiquiti/comments/kbx6ki/unifi_sono...
No products are perfect, but for the use case of "more technical than average user" looking for better quality than your typical home-grade gear, I have not found anything better or more polished.
Of course, if you want a locally managed device and have a relatively simple topology there are plenty of other brands and products out there. I personally love the cloud sign in &. remote provisioning.
Critique about it on their forums is removed by moderators.
The "dream machine" thing I don't get. I do like their Unifi AP line, though.
I purchased several pieces and was planning to purchase more until I found out about their vendor lock-in aspects, and returned it all. It's really stupid because they don't have to compensate for anything with lock-in considering their high quality at their price point.
Assuming it does everything it says it will on the tin, of course.
Can't comment on issues have been getting, but I only have good things to say about mine. It's not perfect and the learning curve can be steep, but it's miles ahead of any other routers I've used before. The only thing that came close was when I flashed dd-wrt on my old Linksys.
If I was renting again, I’d consider using tp-links gear.
Password change went fine. I expected existing sessions to my controller login would be terminated upon a password change. I suppose that's not mandatory but it sure wouldn't be surprising behaviour for security software IMO. It's the conservative thing to do, no?
Nope. Already logged-in sessions (web and iOS app) remained functional when I changed the underlying password. No need to re-authenticate.
Before I received their breach email today, the past two days I have been unable to log into my controller at all. This was being reported by others through unofficial channels at the same time (Twitter, Reddit). Ubiquiti was silent until this morning. Maybe it's just a bad coincidence.
I'm a new Ubiquiti customer. My gear is < 30 days old. Their UniFi Dream Machine seemed to be my "dream" for a home network (AP, VPN, notifications, guests, pretty dashboard). It's probably better than the alternatives. But I'm forming a less than stellar first impression of them after this. Honeymoon over.
Bought one Access point "PRO".
It is a hacked version of openWRT. No GPL sources anywhere on their site.
Downloaded the unifi controller to run on a debian 10 image.... a closed source java app. And it requires java8 from sun. pain to install on debian but fine.
Next, it requires an old version of mongodb. Sigh. no package available for debian 10. Compile from source, this is a nightmare on itself, but done.
A bunch more /fun/ with decades old software dependencies later, i have a unifi controller running.
Now, I learn that despite them advertising (and showing screen shots) that i can setup VLANs with that product (and the product page advertise support for N vlans) i learn it is just a dumb unmanaged AP. I write that off as a $150 lesson.
The UI says that if i buy another piece of the hype puzzle it will enable the feature i bought the "pro" AP for. But at this point, i know i will also learn i will need a something-key, and then something else. ...thanks. Fool me once, shame on you, fool me twice shame on me.
I will just save the dumb unmanaged "pro" AP to use with a setup from someone else. Probably pfsense based. Heck, the time i wasted to simply satisfy the anciently deprecated dependencies for their controller, I could have send tons of patches to pfsense so the UI looked just as good as theirs :) ...which i think is their only selling point.
I can post a screenshot or something if necessary.
This is the email users directly received.
At least as far as I can tell, this means your local controller account requires an internet connection to reach your UI.com account, so there is no local isolation of administrative accounts anymore.
Come to think of it, how many times have they changed their URL/how many are there? feels like im being trained to do something stupid.
https://www.reddit.com/r/Ubiquiti/comments/kv9fc8/ubiquiti_e...
Is this an attempt to shift blame? Using wording that implies it was someone else's fault is not confidence inspiring.
Their support isn't very good (they point you to a forum), their hardware replacement is spotty (sorry, out of stock, you'll have to wait!), and their hardware/software is buggy. We had 48 port switches that would randomly reboot, for example.
They can be a decent solution for SMB wifi, but that's as far as I would go. Nothing mission-critical unless you are willing to make compromises you wouldn't have to with a bigger vendor.
That's the interesting question though. How much does that bigger vendor cost relative to UBNT? For example. I needed about 20 48-port gigabit switches for a new building. Aruba 2530s run about $2k each, so $40k total. The UBNT equivalent is under $400 each. I can buy 5 UBNT switches for the cost of 1 Aruba. Even assuming that I buy 50% extra switches as spares to UBNT, I'm still only spending $12k for UBNT, a savings of over 65%.
edit: I have since received the email
For now I've renamed the username and put in a fake email address (sadly the username `deletemyaccount` was taken).
You can't check via a login page whether you have an account...
It's so bad, they have disabled pinch to zoom, so I just horizontally scroll.
https://help.ui.com/hc/en-us/articles/115012240067-UniFi-How...
Would be good to know which provider this is and whether it was the fault of the provider itself.
Is UNMS ok?
1: https://community.ui.com/questions/How-do-I-get-my-account-a...
It doesn't inspire one iota of confidence. Quite the opposite.
Details can some later, once the threat is fully evaluated.
If it waited until all the facts are in to put out a full fact sheet, the HN griefers would be jumping ugly that it took too long and was covering things up.