Security Issue: Cloud Site Manager presented me your consoles, not mine
community.ui.com
community.ui.com
Some of those people remain. UI-Marcus in that link is a good person. The company went into a steady decline after the CEO started centering the company around the offices in Portland and China. Portland was home to the UX designers who wanted to redesign everything to look nicer but didn't understand how customers used our products. Portland was also home to Nick Sharp, the cloud lead who tried to extort the company and lied to the press about hacks. The favorite office in China made the FrontRow product, which failed so badly that I doubt anyone has heard of it. These people were supposed to be the future leaders of the company, but everything they did was a disaster. We could all see the writing on the wall and left. Well, almost everyone.
I don't even know which Ubiquiti office owns the cloud any more because everyone working on cloud at Ubiquiti either quit or was laid off after the cloud lead went to prison for extorting the company.
I hope the company can get back on track some day. It's sad to see all of our old work decay like this.
>It's sad to see all of our old work decay like this.
This is very common. Happened at my old company. Your last 2 paragraphs are 1-1 the experience of many of my coworkers and I. Very, very sad.
Granted, I never updated the firmware in the 8 years. Heck, I'm not even sure how I can get back to the web UI to control them.
And I don't think it's a good idea to manage multiple APs using the app instead of from the controller. Managing a single AP from the app is ok, but I think you'll run into problems when you have multiple in a network.
For example, you can't set up meshing from the mobile app. Best you can do is give them all the same SSID/password, and they also have to be wired in that scenario.
Source: I've been working with unifi gear for the past 4+ years and use a basic unifi setup at home, since it was free to me. I wouldn't have bought it.
Like all things, YMMV. I'm glad to hear its working like you need it to.
I’m not sure there is another company offering the same solution with ease of setup and low overhead to manage. Is there?
If someone doesn't know networking well enough, then the UI isn't helpful really since they don't know the why of things.
It's a great niche, but Unifi has issues and they seem more focused on selling more of them, than fixing issues present for 5+ years.
Here's an example: Unifi uses Strongswan for VPN. There is a bug in that 2 people cannot connect to the VPN site from the same IP. Site2Site between 2 unifi devices has been unreliable.
As far as what I would have bought, it's moot, since I'm not the common use case. At one point, I used an ASA 5510 as a home router. ;)
For your own home, if not Ubiquiti, what do you use nowadays?
https://www.arubainstanton.com/techdocs/en/content/get-start...
Some more discussion here from years ago:
https://community.arubainstanton.com/communities/community-h...
Although, I imagine this type of stuff may not be made to work well without internet.
I notice that the linked docs article doesn't get listed if you go up the breadcrumb and try to go back down…
This is huge! Please link me to the evidence to back this up.
The NDAA blacklist was a happy compromise by the US government of banning the most egregious vendors that might find their way into sensitive facilities (Huawei, Hikvision, etc) while letting consumer focused brands that do the same (TPLink, Jetstream, Wavlink, etc) slip by so it didn't appear at face value to be a blockade of all Chinese made networking gear.
Taiwan on the other hand is less concerned about how China perceives their relations and bans all these vendors. They also ban Zoom.
Second, you seem knowledgeable about concerns w.r.t some supply chain attacks, at least from foreign actors, so do you have an alternative suggestion that isn't impacted by such concerns?
Ubiquiti is a non starter imo given their recent posture
Grievances start with "made in China" and end with firmware hacks from May of this year.
https://blog.checkpoint.com/security/check-point-research-re...
This implies the opposite of "the CCP has a backdoor to every device". Vulnerable devices from all manufacturers get exploited like this all the time.
YMMV.
For example:
/ip/firewall/filter add
is in the UI under the sidebar IP -> Firewall, then the Filter tab, then click add. The parameters are named the same in both too.
I've been using their devices for years, and I haven't had any problems setting them up.
Rock-solid hardware and muuuch better UX that RouterOS.
Don't remember when I setup those, but probably well before Covid. Really fire-and-forget devices.
1) Their main push seems to use a thick client for admin which is a big no to me, otherwise the web ui in theory looks ok-ish. 2) Looking at their cli guide, it was cryptic as hell to me, and I deal with everything from cisco, arista, aruba, juniper, fortinet, pan, whatever from a cli or gui.
This was mostly confirmed a few weeks back, another old network engineer friend of mine hit me up asking if I've ever dealt with Mikrotik, and said no, but I knew where he was going. He'd screwed with it for a day or so supposedly just trying to make some L3 vlans, and finally a day or so later told me he'd made it work, but has never dealt with anything so terrible to configure from either gui or cli after having tried both, and he's another 20yr+ network engineer like me I trust not to be stupid.
That was all I needed to hear for future consideration.
Where you run into problems with 'tik gear is the differences that L3HW acceleration introduced into the mix. They didn't do what every other switch vendor does and limit features to what the switch chip supports and hide everything that the CPU can't handle away, so you have multiple ways of approaching most issues which threw me for a look as somebody who had been running JunOS gear in his lab for a while.
Once you get a feel for it then it's pretty straightforward to work with everything, though somebody used to an older generation of NOS like classic IOS (and associated clones) would have an easier time than me.
For reference, here's the config for my CRS317 acting as my "core" switch: https://gist.github.com/snuxoll/d63a155aa2155f53736a99d1cb27...
Yeah, the CLI is a bit weird, but it's built on the same API calls that the web UI makes. So they're oddly consistent.
But I will say that the boxes of theirs that I bought about ten years ago are still going strong, never had a device fail on me, still receiving OS updates, still able to export and re-import my config to any of a wide variety of newer devices when the time comes.
Clearly they're not the right choice for everybody, but there are certainly up sides, if you're willing to grapple with the config.
Best built hardware I've used, and I'd still be using their PoE at home if they didn't patch out SSH/REST access a few years ago.
What a miss… And weird product category for them…
Also interesting, apparently Ubiquiti came out with a video editor too around that time for FrontRow: https://www.reddit.com/r/Ubiquiti/comments/t9jz2n/ubiquiti_l...
Curious - what was the size of Ubiquiti when “we [you and your tean] made Ubiquiti and UniFi into household names among nerds”?
https://web.archive.org/web/20170929122826/https://www.front...
MirkoTik has also been updating their UI this year and it's only getting worse.
They are starting to put everything into auto-collapsed sections so that instead of just scrolling down the page you now must remember the section's title and open it in order to access the controls. There are hundreds of sections.
For probably the past 10 to 15 years there has not been a moment that I haven’t had at least two winbox sessions open/running on my daily desktop 24/7. (Network/Wi-Fi admin , responsible for thousands of devices)
The first rule of webfig is: don't use webfig
These newly collapsed sections are tabbed sections in WinBox, so there you've had the problem since the beginning.
It's a matter of preference and I've always preferred Webfig. I'm a MikroTik user since 2013 and have 9 devices which I like a lot. I only used WinBox when I misconfigured them a bit in order to access them via the MAC address.
Of course then, the second rule of webfig is: you can’t even use webfig bc both web services have already been disabled
That means they're not UX designers, but simply illustrators without actual illustration skills
It always seemed funny to me that the door access readers re-used the case from it.
> https://www.theverge.com/circuitbreaker/2017/8/15/16146354/f...
> https://c3aero.com/products/ua-pro
I was absolutely floored when I saw the announcement of the FrontRow device - what a bizarre thing to have brought to market for a network hardware company. I can only imagine someone somewhere got far too caught up in the "wearable" hype a few years ago.
IIRC Access reader isn't the only product the FrontRow R&D cost/stock of parts was tried to be recouped, but at that time I wasn't working there anymore.
5, by my count and still climbing.
I think that's every single piece of modern software to date. I call them "Dribbblrs", because it's like they take inspiriation from these websites (e.g. Dribbble) that fetishize things that look pretty but are dogshit to use. I really wish it would end but I don't see it happening unless there's a revolution from within the UX community (which I am not a part of).
A few of my IT clients have UniFi routers and they're quite lackluster for the price - pretty UI but loads of broken features and bugs galore, and you can't manage them centrally like the rest of the UniFi kit.
This actually my turn out to be VERY useful. As someone who runs Unifi at home w/ a stupid amount of VLans, being able to color code them at the switch will come in real handy when I just go and start unplugging stuff and rearranging as does happen. If they update it to flash VLan color while unplugged using the LCD screen it will be even MORE useful. We can hate on RGB all day just for RGB sake but when it has a use, more the better.
One page to update everything rather than have to connect to each device and push a config. The controller also "back-ports" the configuration as appropriate for a given device. Declare a vLan once, don't have to worry about which cli version is running on a given switch and adjust your command accordingly.
These things don't matter much when you only have one physical location / few devices but if you're an IT guy that manages networking across every physical building in a school district...
Since the device tries to phone home, it's also a NAT buster which is invaluable when you're drop-shipping equipment to customers and have little control over your environment but need to be able to promise some level of functionality.
Agreed, and it really was amazing work. As someone who started using and then deploying UniFi in maybe 2015-2016ish and found it a revelation, it's been tremendously depressing see so much potential and such a community utterly squandered. I can only imagine what it's like for someone on the inside. Nevertheless, thank you so much for your work and all the others who helped make it happen. If nothing else it did at least really blaze a trail and show what could be done, and contrary to this issue without any cloud bullshit and subscription lock-in. Even were Ubiquiti to truly implode, that showing of what could be done would remain and by its nature the kit would remain useful for a long time.
There have been some mildly positive signs recently though, even if the UX churn remains shitty. There has been small shoots of progress on actual core features, years and years and years late granted, but not entirely too late. I wonder if the emergence of TP-Link's Omada as a clear, direct same-niche competitor has lit any fires there?
The hardware was actually really good from what I could tell. Not a single issue that wasn't caused by my own misconfiguration. But the software, woof. The software was designed to do exactly one thing: look impressive to execs in a board meeting. It was nearly unusable for me. I don't recall any specifics, but all you really need to know is that it took multiple days to get a simple home network with a single AP and a single router set up. It was so much effort just to log in to the damn thing.
I went into this project excited at the prospect of all the cool monitoring and analytics I could do. Fancy security and remote access and whatnot. After I finally got everything configured, I never touched it again. There were a few times when I needed or wanted to get into it, but I couldn't remember the specific incantation and combination of software needed to access it, so I just didn't.
I'd love to have a solid system built on quality hardware. UniFi is notionally exactly what I want, and exactly what a lot of hackers and tinkerers want. But the quality of your hardware is pretty much irrelevant if your software wasn't designed to be used by humans.
So I'm stuck using consumer routers with open firmware. It's fine I guess.
I don't know of a system that works across multiple SDN solutions.
This seems to be a popular approach, as there are no attractive routers from Unify, there was the Ubiquiti Unifi Security Gateway (USG), which ran very hot but was affordable and small (EdgeRouterX-like). Now they have the Dreamrouter, which has everything in one, including Wifi. It looks like an Alexa tube. There is a gap in their offering if you ask me, I'm also looking for a nice simple 2 nic opnsense box (preferably a nuc(-like)), after I blew up my EdgeRouterX (used the wrong power supply).
The hardware is solid and the software isn't flashy but it's reliable. It's exactly what hackers and tinkerers want, so naturally Ubiquiti has all but abandoned the entire product line.
They haven't discontinued it (yet) so I could still replace any piece of it if I needed to but their software version history doesn't exactly paint a picture of a product that's cherished or actively invested in:
2019/03/28: v2.0.1
2019/05/30: v2.0.3
2019/06/25: v2.0.4
2019/07/16: v2.0.6
2019/12/04: v2.0.8
2020/03/09: v2.0.8-hotfix1
2020/11/18: v2.0.9
2021/02/02: v2.0.9-hotfix1
2021/06/13: v2.0.9-hotfix2
2022/07/17: v2.0.9-hotfix4
2022/12/20: v2.0.9-hotfix5
2023/01/22: v2.0.9-hotfix6
2023/07/31: v2.0.9-hotfix7
I'm going to try to replicate notifications and stuff using Home Assistant and shut off the remote access completely, but I might as well have purchased a cheaper and better NVR + camera setup if I need to set up all of this stuff myself anyway...
We were using Nest before and these would be huge UX downgrades for my not-tech-savvy spouse.
Do you still have it?
You might just have one with an on-board USB stick which is user-replaceable. Literally a USB stick in a USB type A port.
It seems that was the only part they cheaped out on, since it failed for multiple people I know that have models with the USB stick.
Source: erlite-3 wouldn't boot up, changed usb stick (with their downloadable OS image of course), good as new.
Bonus: quadrupled the available storage.
At least with a VM I can shut it down, snapshot it, block incoming network access for everything but a canary deployment, update it, wait for my canary to come up properly, and then let everything else hit it. That gives the option of a rollback which is much harder with Docker.
I say that as someone using 'linuxserver.io/unifi-controller' which was a mistake I guess.
1. https://hub.docker.com/r/linuxserver/unifi-network-applicati...
I'm still running with a Turris Omnia as router, which served me very well for >7y, added a small legacy SSD, managed to setup everything and worked for a while, but TO is armhf architecture, which mongodb quit packaging for with version 3.x. LXC containers for armhf (Debian/Ubuntu) stopped being released too by official channels. But the latest shiny Unifi app requires MongoDB >= 4.x (Unifi app >=7.5).
"Ok, I'll just buy one of those small embedded boxes": purchase Odroid H3+ (x86_64), install stuff, add docker, start up mongodb5 container annnnddd... illegal instruction! Turns out with MongoDB 5 they decided that with pre-built packages everybody has AVX instructions anyway, and packages are built with the expectation AVX instructions are present... which is not always true for low-power devices or even servers (the Intel Jasper Lake CPU of the Odroid H3+ was released in Q1'21).
Want to run this in a VM? Your host CPU better support AVX, too. https://jira.mongodb.org/browse/SERVER-59482
I guess someday I'll just have to build my own docker image of MongoDB...
I just tried the same thing last week and it took an hour (half of that was mounting it to my ceiling). I only set up a WAP though, no controller.
I did have something weird the other day in AWS. I was accessing a K8S hosted website in my clients tenant, and I got an SSL handshake issue. Turns out the certificate served wasn't of my clients website, but of some dev-xxxx.polar.com. That environment wasn't externally accessible as the domain cannot be resolved in public DNS and I assume that the environment itself is also shielded. After refreshed, the issue was gone and I could access the client site again.
Console Settings (menu on left) -> Advanced (heading) -> "Remote Access (checkbox)"
Or via: https://$UDMP_IP/console-settings
(Hopefully the setting applies locally...)
If you have disabled Remote Access and instead want to use the phone app via a VPN, you may have to add it manually. There's a (+) button for that, and then a "Need help?" option, which contains a way to manually add by IP/user/password.
They should be able to accidentally send my data to another user and have it merely result in a decryption failure.
That wasn’t a security incident for OpnSense. It was a CVE for an optional package most users probably don’t have installed. Sounds like not-an-emergency to me. That user is completely unreasonable. Opnsense should refund their money (if any lol) and tell them to pop off.
First of all, the point is that the OS didn't release CVE fixes for the packages in its repositories even though it had already committed those fixes to version control. Notice that my comment specifically talks about "delay in security response", not that it was an "emergency".
>That user is completely unreasonable. Opnsense should refund their money (if any lol)
Second, I recommend reading the comment you respond to carefully before you rush to make an account to respond to it. "That user" is me. The GH thread has a clear comment from me that I did not pay them any money and do not have any expectation of support.
Third, notice that the point of the GH thread was me asking what their policy of releasing CVE fixes was. You seem to think I was some Karen complaining that they hadn't released the fix. All I asked was a confirmation that they're aware that they're shipping a package with a CVE, that they've already fixed the package but just not published it, and what their policy is for releasing fixes in general.
They could've responded with something like "We're aware of the CVE but we don't plan to release the fix in 23.1. Our policy is to only release bugfixes for non-critical packages in the next stable release, and we consider os-haproxy to be a non-critical package."
Instead they got weirdly defensive about it, tried to lecture me about how OS releases generally work, called me "rude" (ironic), and locked the issue.
The ultimate point is that OPNsense delays security fixes. Maybe you think it's okay because you think some OS packages are critical and this one wasn't. Maybe you think if an OS can't articulate its security fixes release policy without getting combative, then it's hard to take its security seriously. The decision is yours.
I think that everyone is entitled their own intentions, but they are also responsible to communicate those intentions effectively. If the intention was to not be "some Karen complaining" it wasn't clearly communicated that way.
I actually run OPNSense for myself at home, but for my parents I deployed full Unifi. This way if there's any problem, I can remotely look at the network in the cloud console and try and see what's wrong.
Agreed. Major ISPs in the US (and I presume many other places) offer routers that work well enough to satisfy the requirements of any non-technical household and often come with provisioning/troubleshooting features that enable the ISP to provide technical support if necessary.
In the old days, ISP-provided devices often lagged behind other consumer or prosumer network offerings, and it made sense to swap them out... but that's not really the case today. Today, swapping out the ISPs router is probably going to make a non-technical user's life harder, unless they have someone technical to manage it for them.
Satisfaction happens when a product or service meets the user's requirements. A new Cisco catalyst setup may be technologically superior to my mother's ISP provided router, but it might not make it easier for her to play Candy Crush on her iPhone if she forgets the wifi password.
I mean, when the first thing you hear when you call your ISP, is to "reboot your router" on a recorded message, doesn't that throw a red flag to anybody else? I don't use high end gear at home like Cisco, either, but it has never needed a reboot.
This is symmetric gigabit product, but still.
I'm not familiar with that device, but a non-technical user might not care about that "problem", as long as their device does the task they are intending to perform.
I am sure that AT&T's CPE equipment is lackluster, but that doesn't mean it won't work to do basic tasks to the satisfaction of a home user.
I can tell you from experience that large downloads and uploads cause latency-sensitive applications to stutter in a way that is fixed by using ubiquiti gear.
In your defense, you did say non-technical household, but I dunno -- I don't think that wanting to use, eg, backblaze for backup and not have that tank zoom makes you a technical household.
On my home network, what I really want is the ability to define one or more networks (VLANs, if you will) and then place devices in those networks. When you click on a device, you are then able to do things like give it a static IP, look at the traffic it's generating, shape its traffic, disallow traffic from/to certain ports, kick it off the network at certain times of day, allow it access to the local network but not the Internet, change its DNS resolvers, etc.
In order to do these things on most routers, if they offer the ability at all, you need to jump around to different places in the UI and manage each service as its own thing. OPNSense is great (and it's what I currently use) but it's UI is really just multiple little windows into the various sub-services that the firmware provides. Separate page for all the firewall rules, another for all the DHCP leases, etc. It works, but it's kind of frustrating to use, especially when you're not digging around in it every day.
The business model would be: everything open source, but three "tiers" of releases: 1) free "beta" releases featuring new and lightly-tested features for the adventurous. 2) "stable" releases via subscription (paying customers have access to the source code and build tools) 3) "freeloader" releases, the same as "stable" but with a 6-9 month delay.
Devil is in the details of course, but if I had any entrepreneurial bent at all, I think it would be a big improvement over the current state of things.
Correct me if I'm wrong, but that still looks to be largely true. Except that there are multiple to choose from: https://openwrt.org/docs/guide-user/luci/webinterface.overvi... I had a look at a few, and they all seem to be "managing the router"-centric, not "managing your network"-centric.
Reminds me of that time someone at Dropbox pushed a change onto production that ignored your password, so you could login as anyone with any password...
DDG and Google were useless and mostly returned pages from dropbox.com, I had to exclude results from there: https://www.google.com/search?q=dropbox+security+issue+passw...
My current system is a Protectli 4-port firewall appliance that is running AlmaLinux. It gets CGNATed by my ISP (Starlink) but I set up Tailscale (Headscale) and don't really have any issues now from CGNAT. Cockpit plus plugins provides me a good GUI, although I prefer to just SSH and use the CLI. I have two "wireless access points", one is a Linksys WRT3200ACM: AC3200 (open source edition). It's good, not great. The other is a (swallow) Google wifi. The Google wifi adds a layer of NAT in order to provide mesh. You can avoid that by putting it in hub mode but you lose wireless handoff if you use that. I've been pretty happy with that system for several years, but I'm still on the lookout for something more open that isn't a major downgrade on speed/reliability. I can more or less hot swap any WAP into place since most of the brains/config is in my Almalinux router.
https://i.imgur.com/RzXpT6Q.png
After doing that, you can't access your router remotely from The Cloud, (well, you can log in over the VPN, remote into a computer on-site, and access the router from that computer) but you're secure against a whole class of bugs and errors in Someone Else's Computer.
Unifi’s firewall blocks a ton of IPs whenever I open a port for plex or whatever. I’ve tried to fight back against US providers letting anyone with a VM run port scans but they only care about getting paid.
Unifi is one of the companies with awesome potential but they just seem to whiff it constantly on security and software.
If you just don't even care enough, then you'll never get it right. Not saying that Ubiquiti is that way, but there's a reason why some companies never seem to have significant security concerns and others have an unrelenting stream of them.
Possibly even proxy the traffic via something able to do SSL strip/re-encrypt and monitor that traffic with an IDS.
However speaking to some people at work who have had experience in the past, seems most malware (and that includes IOT devices) doesn't bother validating certificates or things like ESNI and (validated) DOH, so there's a lot you can find out without breaking TLS, due to the lazineess/incompetence of the malware writers.
There should be changes to their release process to test and ensure this won’t happen. Also, I’d like to see a real root cause analysis of some sort.
Have they seen the light and made their devices usable without ever logging into their servers? Last time I asked this question the 'cloud' was unavoidable during the initial set up but could be turned off later. This doesn't look like enough to me. I want a damn access point that doesn't talk to anything outside my network.
'Log in to the UniFi Mobile App (iOS / Android)' ?
Log in to what? If they moved the 'cloud' requirement from the AP to the management app it doesn't mean they got rid of it.
I run the management software in a VM and don't even have an account on ui.com. My firewall doesn't let the management software talk to the internet (I allow NTP and the couple of pings it wants to do, reject phone home; I temporarily allow phone home when I want to check for firmware updates).
For network equipment, I have a fair bit of experience with datacentre grade equipment, but none in the consumer space. I think I want this, 1. Good quality. 2. Fanless 3. Drives multi-node wifi APs 4. Control cameras 5. Web interface that parents can use. 6. Cisco-like CLI that I can use. 7. No cloud.
The unifi equipment seems to fit all criteria above except the last two points. Seems you cannot make permanent changes from the console, and their offering is oriented towards cloud configuration. Would someone who knows the segment be happy to offer advice? (thanks in advance)
For no cloud, it’s quite easy to avoid. The middleware can be spun up in a container or installed on any Linux VM and have no access to Ubiquiti’s servers at all and it’ll work fine (you’ll have to upload updates yourself). However, the product will be full of little nagging notices coaxing you into going to the cloud, or as in my case, getting mad you aren’t using a UDM for your router/firewall and turn off a bunch of the L3 features. The software is meme-level in how many bad patterns and form-over-function decisions are in it. Cloud or no, it’s frankly kinda crap.
The APs are solid, but I’ll likely not buy another switch from them if I can help it. Depending on your needs, there is plenty of used enterprise gear to be had for quite cheap on eBay. But, I’m in the market for a fat 48-port switch with a huge PoE budget and they have one that’s all 2.5G. I don’t know that anyone else makes one, and if they do, it’s three times the price, or I have to call some sales person to talk about it, or the actual existence of the product is impossible to surmise through thick marketing wank datasheets.
For the camera side, Reolink or Amcrest POE cameras (or WiFi if you must) paired with a PVR like Blue Iris if you're a Windows guy or Frigate on the Linux side
There is no way for us to know what is causing the bug and what will help without official word for Ubiquiti but logging in can only possibly hurt and won't help.
Reverse control is such a mess and the application is not the place to handle this
Their security posture is trash, which is unfortunate for a company that plays a central role in security
https://news.ycombinator.com/item?id=33695886
(If anyone has examples of Tailscale incidents ending badly please share and I’ll update my trust accordingly, but to date I haven’t heard any.)
They do now support Wireguard and OpenVPN in addition to L2TP. OpenVPN looks like it is only available on newer hardware though.
OpenVPN and Wireguard work fine. I am using it right now.
Release notes history is here: https://www.ui.com/download/software/usg-pro-4
The wireguard of which you speak is only available on their "next gen" gateways, ie, not the full set of gateways currently "supported": https://help.ui.com/hc/en-us/articles/12594825307927-UniFi-G...
It's now been three years since at least some of the forum threads started expressing concern: https://community.ui.com/questions/L2TP-unsecure-update-to-I...
From my perspective, they have failed catastrophically to do what I perceive as the pivotally important parts of their job, without which the rest of it is pointless. So, while you say "Just stop", I say "Why the hell should this company be trusted with anything network-related, if they can't do bare-minimum-required security stuff?"
There's even a docker image for those who have trust: https://github.com/linuxserver/docker-unifi-controller
The note I link above discusses its replacement and how to upgrade.
But what are the alternatives. Firewalla seems to be a good alternative, but they don't do APs, leaving me with a mixed system.
https://old.reddit.com/r/firewalla/comments/14gf1j1/major_se...
https://old.reddit.com/r/firewalla/comments/177egzl/summary_...
There are tons of dark pattern in the Protect app that prevents you from using a local account. And when you finally learned to workaround all of them, you realized that there's no push notification without remote access. (I understand the difficulty to push message straight from console to mobile device, but many selfhostable software offer a centralized, managed push notification relay over internet. I am not sure if this is too much to ask for)
And then I am the one that gets chastised for not wanting cloud connected router/switches in my networks.
Why would you have a central console that has the potential for accessing all the routers with a single login though? Why wouldn't this be just local to the network with remote access?
Earlier this year, some tech tabloid (krebsonsecurity?) reported how bad security was at UI. I think it was ultimately determined to be a bad story and UI sued for defamation.
Now we are here again with another possible leak.
this is why smear attacks work. Someone on a different hacker news thread today was stating that the car that blew up at the Canadian border was a Tesla (It was a bently).
I've seen these types of bugs before. I think they introduced a very bad credentials or session bug. The good news is you can turn cloud off for all of these, and they work just fine.
But I really like the hardware of the Dream Machine Pro (Router, Switch with 10G uplink) and the overall view of clients and connected devices, so I don't just want to buy some random Router and pair it with random WiFi APs - though I guess that's the best choice?
[1] https://help.ui.com/hc/en-us/articles/8823742725015-UniFi-6-...
And yeah, looks like the v1.1 update removed it (https://community.ui.com/releases/UniFi-OS-Dream-Machines-1-...): "Allow to set up a console without an SSO account."
The fact that they decided to release a "Pro" product with that requirement initially still counts heavily against them: What were they thinking, and why should I trust them if they are making such decisions?
What’s wrong with people? I think 1 hour response to a forum post isn’t unreasonable or am I wrong?
(Putting on buck teeth and fidgeting with something) But but but akchyually, it's not an outage, you see.
There's many places where no network is strongly preferable to network that could be open to hackers.
I don't know if the time frame is acceptable, but I know I would have reached out to the customer versus waiting around for a DM once the alarm was rung.
In Seattle they don't even show up anymore, they tell you to fill out a form online...
In the last 8 years SPD has become completely unmotivated to do their job despite never having their budget cut. Adjacent police departments like Kirkland and Lake Forest Park are much more willing to do their job, but they fire officers who don't do their job, while SPD retains these caustic, non-performing officers.
So long as we let our officers in Seattle getaway with billing fraudulent hours that weren't worked, ignoring core job duties, and slow rolling the duties that they do do, we will be stuck with an ineffective police force.
The budget was absolutely cut.
https://apnews.com/article/business-police-seattle-6730ec66e...
2022 was not 8 years ago.
8 years is probably not meaningless for the poster. He probably moved there 8 years ago or had his car stolen back then and is saying nothing has improved since then despite there being no budget cuts.
It makes no sense to say in the last X years if the poser just mean X years ago. It would cause unnecessary confusion.
Because it would not have the same meaning. The point of the phrasing is that the time the Seattle PD stopped being motivated to do their job was close to eight years ago, and they have continued to be unmotivated since then.
"1000 years ago the budget wasn't cut" does not convey that information.
"Defund the Police" has consequences.
https://southseattleemerald.com/2023/09/14/opinion-debunking...
911 is paid by taxes for being 24/7 available. It is also a public service. Ubi is free (at least I don't pay for any of my Unifi consoles, besides the initial cost). It is also a private company, free (as in beer) to do as they like.
Ignoring the fact that flagging when certain keywords are posted is probably built into the forum software itself... I had that with phpbb back in 2001.
There is an escalation path for security tickets at most large companies, and a community forum post is not it.
Chicago: 3.46 minutes
Los Angeles: 5.7 minutes
Seattle: 7 minutes
Dallas: 8 minutes
Miami: 8 minutes
New York City: 9.1 minutes
Atlanta: 9.5 minutes
Houston: 10 minutes
Detroit: 12 minutes
Denver: 13 minutes
Even crime stats are bogus in NYC, I speak from experience as cops literally tell you to fuck off if you want to file a police report. You can be stabbed, bleeding out and walk into a police precient, and they'll drag you outside so they don't have to write a report
Enterprise sucks a lot of the time, but this is what you are supposed to be paying for.
https://status.ui.com/#past-incidents still says "no incidents reported today"
If Ubiquiti was my company and this post was posted on my forum, I would be having status messages/emails out to all my customers, updates on status pages, warnings on website logins etc. Hiding this in a private DM with a single customer is terrible, and they even told the world thats what they were doing which was a kick in the nuts.
Instead, they're "looking into it" or something?
I guess they'll just hope nobody does anything nefarious like change the passwords on every switch/router/AP they have access to then get remote access?
If the response to an unverified issue were "just shut everything down" you effectively have implemented an exploitable DoS in your own incident policy.
If the user in question was making it up, you should also have posted within minutes of discovery that the user in question (and multiple other people) were making false claims.
Again, they've chosen the "we're looking into it" route which is always reassuring.
It's impossible to prove a negative. Maybe they believe that this was user error/malice but are doing more research to confirm this and find evidence of a vulnerability.
So it's impossible for me to prove that nobody has walked through my front door today? I'm quite confident it isn't. I'm also confident if they have sane logging in place, they can prove accounts weren't being accessed by unauthorized users.
You're also talking in vagaries like they're hunting a ghost. They've been interacting with a willing end-user who originally reported the error.