3 ms·
I know we're still pretty close to the Ubiquiti breach, but since then, they've added 2FA. Is your opinion of their products the same?
by cced 5y ago
I know we're still pretty close to the Ubiquiti breach, but since then, they've added 2FA.
Is your opinion of their products the same?
- aj3 5y agoUbiquity introduced new vulns while fixing that fiasco from last year: https://www.zerodayinitiative.com/blog/2021/5/24/cve-2021-22909-digging-into-a-ubiquiti-firmware-update-bug https://www.zerodayinitiative.com/blog/2021/5/24/cve-2021-22... On the other hand, all of the other networking HW sucks just as much. E.g. here are Netgear vulnerabilities published just this week: https://www.microsoft.com/security/blog/2021/06/30/microsoft-finds-new-netgear-firmware-vulnerabilities-that-could-lead-to-identity-theft-and-full-system-compromise/ https://www.microsoft.com/security/blog/2021/06/30/microsoft...
- beermonster 5y agoSome things, like updating firmware automatically, are ahead of their competitors. IMHO, the worrying things about Ubiquiti at the moment are: 1. Their handling of the security breach/downplaying/whistle blowing fiasco which came to light some months ago. Check our Troy Hunts podcast from around that time. 2. Requiring a cloud account to manage your local device. Everyone seems to do that these days. It's not impossible to remove the cloud account management but it is an extra post install PITA step to work-around. And has some consequences if you do. I'd like to see if they've learnt their lesson from at least the first point and become less opaque security-wise going forwards. Not sure their security is passing the smell test at the moment.