I think the mixed reviews are from HN where people are complaining about their security posture (for good reason).
I believe they did something like force cloud-login with some software update a few years back.
They also apparently were downplaying a major security incident, and sued Brian Krebs for reporting on it: https://arstechnica.com/tech-policy/2022/03/ubiquiti-sues-jo....
I have some Ubiquiti stuff, and it works fine, but I've been meaning to look deeper into all this, but I just haven't had the time. I just stopped updating the controller software (none of their gear is external-facing, and IIRC it's only needed for configuration/management) because cloud login is an absolute dealbreaker for me.
No, what they did was update the software to prefer cloud-login and push you to set it up during onboarding for new products because they use cloud-login for remote management and anti-theft/device tracking.
It's always been entirely optional. I just set up a new network because I moved and gifted my previous network to the buyer's of my prior home. I'm still using local accounts only with no remote management, and it works perfectly fine on the latest generation of Ubiquiti gear with the latest firmwares. The only thing I login to my UI account for is to use the store and buy hardware.
The other thing with Brian Krebs was a faked security incident by an insider who was trying to extort money from Ubiquiti and Brian Krebs played the fool by assisting them.
Granted, there are /many/ issues I have with Ubiquiti, but generally speaking if you use local accounts and keep the firmware updated it is no worse than any other edge networking device exposed to the Internet.
Was that all? Did they add telemetry or something else? I had read that I'd need to edit some text config file or something to opt-out of something I didn't want, because they provided no option in the UI.
I believe this might be what I was thinking of: https://www.reddit.com/r/Ubiquiti/comments/fhlowt/where_is_t....
I took a wait and see before I sorted it all out (since none of their stuff is external facing on my network), and haven't gotten around to it.
Even the local login, from a device on the network, can be set up to require two-factor auth. That alone makes it more secure than a lot of consumer-grade stuff which only requires a password, which is often never changed from the default.
I'm happy with my Unifi Dream Machine as a one-device home network. I thought about getting rid of it a while back when some bad press about Unifi security was published, but it turns out it was fake news and Brian Krebs has lost all credibility in my eyes for continuing to promote it even after it was debunked.
Yeah. Updates used to be a nightmare. I had to worry about Windows updates, Java updates, and of course Unifi updates.
Then I started to use the Docker container at https://github.com/jacobalberty/unifi-docker No worries about cloud login...
I have 21 APs all controlled by the container on a Raspberry Pi 4. It's not even breaking a sweat. When I want to upgrade the Unifi application, I stop the container, and re-run the command to use the newer Unifi version. Three minutes later, it's back on the air.
> the attacker(s) had access to privileged credentials that were previously stored in the LastPass account of a Ubiquiti IT employee, and gained root administrator access to all Ubiquiti AWS accounts, including all S3 data buckets, all application logs, all databases, all user database credentials, and secrets required to forge single sign-on (SSO) cookies.
It has shaken a lot of people's confidence in Ubiquiti's internal security practices.
Then, a few years in a firmware upgrade to the switch (their 250W PoE switch) caused it to start isolating my Google WiFi APs because it would do some loop detection. An hour on the phone with their support (which in that instance was really good) resulted in a a prognosis of "This particular loop detection can't be turned off." So I had to drop a dumb switch in front of the Ubiquiti for the Google APs. I was considering replacing them with Ubiquiti, but needed to run some more wire throughout the house to get what I needed.
Then I ran into a firmware upgrade that bricked 3 of my 4 cameras. After going back and forth with their support and getting nowhere, I just gave up. I had replaced the controller with the CloudKey G2 at one point because the old one was no longer supported, and it seemed to help with but not totally resolve the days of rebooting cameras situation.
Honestly, having the cameras bricked was a relief, because of all the consternation that the firmware updates had been causing. I just couldn't bring myself to buy new Ubiquiti cameras.
I ended up pulling out all the Ubiquiti hardware, replacing it with $200 4K very low light cameras that are just amazing (rebranded HIK Vision, "Montavue"). I'm using BlueIris for the camera controller, which is fine. Still using the Google WiFi, which continues to work great. I have 4 APs (one in router role, 3 spread around the house).
Security wise it is not great, but I don't think it is worse than other consumer products (tplink, netgear...etc). At least ubiquiti patches vulnerabilities reasonably fast.
Their cloud infra sucks and the whole data breach / lawsuit drama people constantly bring up was all because (I think?) a former employee had a static AWS access key with admin level access. Small companies are usually not good at dealing with internal threats. I don't use the cloud service anyways and self-host the network controller.
Now my biggest complain is that I have to manage a mongodb 3.x cluster for the controller...
I need it to be an external cluster with some redundancy, so that I can easily backup the database, fix file corruption, and deal with other database errors.
I picked up a couple of Grandstream Wifi 6 APs to try and other than the gawdawful update process (that has thankfully improved - but you still have to get past the ridiculous initial firmware) they are wicked fast and so far a lot more stable/consistent than the Unifi counterparts. The unifi controller is indeed very slick/pretty to look at, but over the years I've come to realize that the "stats" it reports aren't very accurate so I'm back to librenms to gather/report on my network statistics.
I still think Ubiquity rots from the head and whether they mismanage teams in one country or another should not reflect on the country the people are working from.
Me and some other colleagues worked for a US based company from Hungary. The company payed us well according to Hungarian standards, but wee where cheap according to US standards. (The payed US junior salaries for senior people). The people in the team were very knowledgeable, efficient and we delivered a lot of great stuff. It worked well for a couple of years, but then the company got greedy. They hired people from another outsourcing company from Ukraine (I think) and this time they went for the cheapest. The people we got only had little work experience and they paid by the delivered story point. The code quality suffered as they wanted to merge everything ASAP. I left shortly after for a different reason, but as I heard from previous colleagues the company went downhill after that.
So outsourcing can be a turning point, but for a different reason than you think.
I even said so by pointing out that I think they rot from the head and do mismanagement as you described too.
So in that light I would ask how did you understood me thinking something different?
If you have questions where you think I can help, drop me an email.