Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.
Ubiquiti had a secured backend - their screw-up was not doing MFA on their admin accounts. I would still like if there was an option for a local-only control panel.
The work flow we used was AWS Vault -> Okta -> short lived AWS creds.
It briefly pops you out to a browser to authenticate and caches a short lived token locally
There's tools like aws-okta that can advantage of that to supply short lived credentials which require 2FA
You could also write a service that requires whatever authentication you want and returns the results of STS AssumeRole
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_p...
Having your local network depend on an external network makes my old school sysadmin bones tingle for some reason.
They have a good UI, good hardware but the software seems half baked.
Originally with the switch to the "new settings", the schedules were switched between the AP's and the UDM, not sure about a dedicated cloud controller.
Great product, poor QA I think.
I couldn’t see an option on setup.
I might try block it from internet and see what happens.
I am deeply saddened by Ubiquiti’s fall from grace... they were so good.
If I wanted to run it all the time, I’d try putting it in a docker container on my synology.
Instead, I have an sd card for my raspberry pi that has nothing but the controller installed. The main downsides to this are that it is easy to lose the sd card, and that the controller gathers bandwidth/usage/wifi connection reliability stats, but only when it is running. I don’t get those unless I boot up the RPi to diagnose some network issue (this has never been an issue in practice).
One advantage of the RPi setup over a synology container is that it has both a ethernet jack and a wifi adaptor. This is surprisingly helpful when bootstrapping complicated mesh topologies.
https://lazyadmin.nl/home-network/unifi-controller-on-a-syno...
I too am disappointed in UniFi’s direction.
I used to recommend them. I don’t now.
I am still looking for alternatives when the time comes to replace mine. Which I'll be forced to replace once/if they completely nerf the self hosted on self hardware options.
From a couple years back, https://arstechnica.com/information-technology/2016/04/how-h... (the hackers got remote access to a sysadmins desktop then waited til he mounted TrueCrypt and stole the entire contents)
Even with hardware tokens, if someone gets access to your machine while you're using it they can wait til you authenticate then use the creds proxying requests through your machine so they look legit
So you're saying it was both not trustworthy and not adequately secured?
MFA is not a silver bullet. You can still login with stolen cookies and 'replay' the session without signing in.