One week ago 3 guys broke into my shop while I was traveling. They had sense enough to power down the starlink that was providing internet which would have taken out all of the remote camera options.
They did not realize that almost everything they were doing was being recorded via the unifi system. In the end about the only thing of value left in the building was the hard drive with all of their pictures on it.
The police have used the footage to identify all of them and it will be pretty open and shut when they see a court room. Offline and air gapped the whole time they were there but did exactly what it was installed to do.
I'm guessing with such an obvious endpoint for the camera storage it never occurred to anyone there was a second box. I had something like this in mind when I wired the building. It seemed like a good idea to make onsite security footage much harder to find given the cameras were obvious and anyone breaking in would probably look to damage or destroy the system.
I really thought the cameras themselves were the deterrent, but these guys gave it a shot anyway. Cutting the cable to the starlink and walking off with the NAS drives seemed to be the plan.
In the future I'm going to add a local battery backed alarm connected to external siren and strobe that is immediate on opening the office door to draw attention. I was driving down to WWDC when the starlink went offline and saw the notice on my phone but wrote it off to equipment failure which gave them enough time to clean the place out pretty well.
The hole in my strategy was thinking nothing could happen without notification, but being in a car in the middle of Norther CA with spotty cell coverage and lots of distractions blew that up pretty hard. I'm also thinking one of ubiquiti's cellular backups is in my future. Starlink offline is annoying but not the attention grabber that a still of a guy walking in the door would have been. Cellular backup would have gotten me that.
But, re: alarms, I'd like to add a suggestion: Indoor sirens. They can be intolerably, painfully loud for not very much money (because piezos are cheap and square waves are easy). Using a small, random mixture of them can let them beat at different frequencies and periods, which can make them very unpleasant to behold even with hearing protection.
If you feel like being clever, you can even run them with a local battery that activates when they're disconnected. If you feel like being extra-clever, you can make them activate when they don't have the correct termination resistance at the far end of the line, or exactly the correct voltage: This way, whether the wire goes open or short, the sirens activate.
Super-extra bonus points for using a combination of methods. Any time that a thief spends figuring this out is time they aren't carrying stuff out.
And if that still seems incomplete, then: Fill the shop with smoke. They can't function when they can't even see their hand in front of their face. https://www.youtube.com/watch?v=RPgcysyFUiI
And the system should not be armed when desirable people are inside, so that problem seems like it is for the birds.
When employees forget their codes and trip the alarm when they're the first ones into the shop at whatever time, they can just go outside to escape the hellish indoor torment. Not perfect, but not so bad either when the goal is to keep people out. :)
Perhaps the smoke should have a harder trigger than the noise, though, if for no other reason than it's a consumable that eventually needs to be fed more money every time it is activated.
If they can't see, they're not going to hang about and if they've tooled up with NV then that's a whole different threat model.
We have one of those at our vacation home (well it's more than a vacation home: I used to live there but it's now house we use for vacation, several times a year but anyways...).
We've got that system connected to the alarm. It's amazing and the system did evolve: in the early days the fog had to be projected in the middle of the room or it'd leave traces on the walls. Now it's a fog that doesn't leave any trace anymore.
The reason it works so well it's that it means: "Now you cannot see jack shit and in a few minutes the police is going to be there".
It kicked in once: the bad people quickly left.
> If they can't see, they're not going to hang about ...
No indeed...
> and if they've tooled up with NV then that's a whole different threat model.
In my case the alarm is still there and if the company monitoring the alarm system tells the police "there are people dressed up like it's war with night-vision system", then they'll take it even more seriously.
I've had a house without my alarm on (because kid had a medical emergency and was between life and death: I left in a hurry and forgot to turn the alarm on) visited by burglars and it ain't a fun thing.
I highly recommend alarm systems that generate a fog. It's a wonderful thing.
And that fog doesn't last too long: by the time your back at your home, it's like the would-be-thieves: gone.
The fog&dog&log never fails.
fog, dog, log, jog, hog, bog, pog, nog
Enveloping fog
Dogs and wild pigs set loose
Log launches at you off a treadmill
Trap door drops you into a flooded basement
Barrage of paper disks
Eggnog super soakers
Wait, you have an office full of expensive equipment but decided to half-ass DIY the security? No wonder you were targeted.
A proper monitored alarm system would have prevented this. They pretty much all have built-in cellular backup now. Do yourself a favor next time and call a professional.
Don't blow your entire budget on cameras then wonder if you need an alarm system because the only good the cameras will serve is to watch your stuff disappear. You mentioned California so expect these guys to be roaming free in short order if they see any jail time at all. Good luck with seeing any restitution or getting your stuff back.
Your statement that "a proper monitored alarm system would have prevented this" is optimistic. I never had any particular expectation that if somewhat intelligent criminals decided to break in when no one was there that I wasn't going to lose whatever they could get at. The cameras let me document what happened and when and what was taken. If the imagery ends up having any other value that's a bonus rather than the point.
Chances are, the thieves were monitoring the local dispatch over the radio (rural departments are not usually doing anything fancy) and knew exactly how long they had.
Do not under-estimate the number of thieves on the left-hand side of the bell curve: if you can deal with those that's half the population that's less of a problem.
(The thieves on the right-hand side of the bell curve generally work on Wall Street and generally don't do break-and-enters.)
I've got this setup running on a Raspberry Pi near my front door and it collects all sorts of useful data, even from people walking by on the sidewalk, 30 feet and two walls away.
At some point, I'd love to explore vehicle emissions more, too.
It never occurs to router makers a static base could see a million Wi-Fi networks come and go every week.
That is why they need WiFi info for ‘fine location’.
I have MAC addresses!
M-A-C...
Yes, I sniff them out the air with equipment I built!
Uh no I'm not on drugs why do you ask?
[0] https://community.ui.com/questions/e3d50641-5c00-4607-9723-4...
But if you don't trust it, the fix is easy: just deny the Ubiquiti cameras and controller all internet access. That way no trust is required.
No.
Very happy customer here.
As much as I wish Ubnt are using BSD in their product, which they are not. I am understanding how FreeBSD relates here.
https://www.freshports.org/net-mgmt/unifi10/
https://ports.to/path/net/unifi/main.html
I guess not officially supported but I use them, they work well.
In the long run, after investing some time into learning actual BSDs I find editing a few config files much more convenient than clicking around in web interfaces.
OpenBSD is great for a router.
So what ? It's not possible to be reliable, open and have many features.
It's like being apple-everything. Freedom until you bump into the walls of your cell.
Unifi APs are a sweet spot of price/performance, and I have no difficulty recommending them. Ruckus hardware is better at five times the price.
UISP gear has worked very very well for me for ptp and ptmp. But that's a completely different line.
Worth noting most of the time the Corals sit idle in many setups, as Frigate only wakes them up if it detects motion with simpler algorithms on the CPU first. You gain capacity for a further 100 detections/sec for every Coral you add essentially. The corals are not sitting watching every single frame from every camera, which I think is a common misconception about Frigate.
It's worthwhile to spend some time with the docs - the mistake I always see made is folks passing a full fat 4k stream for detection at some silly FPS, which generally doesn't make the detection work any better and greatly increases processing costs.
If your six cameras really are generating enough events (100 a second) to saturate a coral, I'd be looking at what else I screwed up!
> https://docs.frigate.video/frigate/camera_setup/#choosing-a-...
Wireless cameras can also cause their own set of issues, but I can understand using them if you have to.
Open-source NVR software like Frigate can do things like the object-detection/license plate/face recognition game on local hardware, with the cheapest available IP cameras. It's just a program that runs on a computer with a network and some storage and some processing ability like a GPU.
Those cheap cameras don't have to be trusted; with things like VLANs, they can hang out on the Group W bench where they have no access to anything important or the outside world. :)
(But yeah, it does represent much more of a DIY effort than something from UBNT does.)
(Seemingly rolled back recently, but a roll back can be easily rolled back itself. I don't trust them enough to count on that not happening.)
I'm guessing you're thinking Reolink or other Chinese ultra-commodity cam. It's fine, it's just in a different product class and ecosystem - and that's where enterprises fit in, they want that support+ecosystem and not DIYing.
Reolink CX820 8MP $129 https://reolink.com/product/cx820/
Unifi G6 8MP ~$300 https://techspecs.ui.com/unifi/physical-security/uvc-g6-dome...
Avigilon H6A 8MP ~$1200 https://www.avigilon.com/security-cameras/h6a-dome
I do that with my Unifi Protect doorbell. RTSP streams. Google Coral. Frigate. Scales very well. Do ML on low quality stream. Look/save the high quality stream. You do it all centralized, and you can put the camera(s) on a seperate VLAN. They don't even need internet access. If you run them over PoE twisted pair, the attacker would need physical access to perform MITM. Wireless, one should assume the camera is insecure (e.g. KRACK).
The purpose of my comment had only been pointing out those features don't come onboard a $100 cam.
I have the same popular setup (Frigate) although I just use ONNX on an 11th-gen Intel CPU instead of a Coral (unless you are trying to do something fundamentally goofy like use a Raspberry Pi as an NVR, Coral doesn't really perform better than even a several-generations-old iGPU or iNPU).
This is the typical OSS story: you can duct tape a giant leaning tower of janky stuff (Frigate + go2rtc + HomeAssistant + various connectors + some kind of VPN/proxy solution for away-from-home access) together and get something that's fairly close to the commercial solution, where you click a button. The open source solution is fun and more customizable in highly niche ways (you can bring your own image recognition models and tagging, adjust the resolution and encoding for everything in infinite detail, and so on) and the commercial solution is easy and works. Chose your path.
I will say I've liked the Frigate stack, though. I'm making some recognition tweaks for recognizing animals on my property, the software works well enough, and I do like having a really, truly on-prem solution for this specific thing.
It works similar, but requires some effort to get working (if you already self-host its peanuts think Frigate plus reverse proxy and I also use Wireguard to have it available from outside). My home connection is fiber 1 gbit, but with DSL (only 30 mbit upload) it worked fine, too.
Since I want to decrease my reliance on US cloud, I like to self-host. I also still rely on Unifi APs and the doorbell. Right now I wouldn't spend money on building a self-hosted server, given prices.
I should mention I use iGPU via SR-IOV on a VM. The Google Coral sits in the device unused.
I also immediately copy the stream to an offsite backup. This way, if I get coerced to destroy my doorbell feed, I will happily oblige.
I think they're definitely not Avigilon, Genetec, Verkada, but we run a few hundred UI cams in some edge areas. It works, esp if you don't demand orchestration.
As others have pointed out they are supported for a long time. I have some earlier generations cameras that are going on 7 years of updates. Not only are you barely getting maybe a year of firmware updates at the $50-100 range but there's no comparison on the quality of the optics, sensor and overall hardware at that price differential.
Ubiquiti has done some shitty things over the years but Ubiquiti isn't competing against the $50-100 market. They're competing against the Axis and Panasonic quality builds. You've definitely got it backwards here.
And while, yes, you can get a decent camera from Reolink and the like at a good price it isn't surrounded by an exceptionally mature and well supported ecosystem that has yet to nickel and dime its customers with half ass SaaS and paid for features.
This comment couldn't be further from the reality of Ubiquiti's lineup in comparison.
What's the comparison at $50-100?