Hacker News new | ask | show | jobs
by beala 241 days ago
All the complaints about Ubiquiti in this thread from a few months ago dissuaded me from investing in their gear: https://news.ycombinator.com/item?id=44746603

I ended up going with TP-Link Omada and have been happy so far (a managed switch and wifi 6 WAPs). I am a bit concerned about their security track record given how bad their soho products are, so I ended up sticking with my opnsense router at the perimeter as the first line of defense.

I’m curious to hear what you think you’re missing out on with Omada.

3 comments

>I am a bit concerned about their security track record given how bad their soho products are, so I ended up sticking with my opnsense router at the perimeter as the first line of defense.

Ubiquiti has had plenty of bad security issues as well I'm afraid, but fundamentally one of the advantages of both is that with a self-hostable controller and VLAN isolation you should be able to minimize your attack area pretty well from both the LAN and WAN. No remote dependencies at all. But like you I run OPNsense at the edge, you do at least have to trust their firewall and such if you want to go full single-pane.

The two biggest complaints in that thread (Edgerouter support abandoned, and VLAN issue unacknowledged and unfixed) were both wrong. Overall, it is a great, easy, inexpensive set of products.
> Edgerouter support abandoned...

Well, [0] mentions that they left the ER firmware alone for two years. They also don't sell the ER hardware anymore.

Looking at the changelog in combination with the comments on the news item about the new release, it looks like there are many bugs left unfixed. If this analysis is correct [2], nearly nothing was changed.

That smells an awful lot like abandonment.

> ...VLAN issue unacknowledged and unfixed... were both wrong.

This subthread [3] disagrees with you. As someone who has suffered through multi-quarter "struggle sessions" [4] with UBNT engineering staff about broken basic functionality, I can totally believe a report that UBNT claims something has been fixed when it's very much not fixed.

[0] <https://news.ycombinator.com/item?id=44794857>

[1] <https://community.ui.com/releases/EdgeRouter-3-0-0/33ee3852-...>

[2] <https://community.ui.com/releases/EdgeRouter-3-0-0/33ee3852-...>

[3] <https://news.ycombinator.com/item?id=44756915>

[4] Complete with round after round of them saying "Hey, we fixed it! Try the latest beta!", and me replying "No, you didn't. Did you run my 100% reliable reproducer that I've given you? It sure looks like you haven't because that reproducer still reproduces the problem.".

I made the same conclusions but got burned with Omada. Cheaper, yes, but fewer features and buggier than Unifi (and that’s a pretty low bar). I migrated back to Unifi.
I don't think I've run into any bugs, but there are also entire sections of the controller I haven't explored yet. I have a pretty typical homelab style setup with multiple wifi SSIDs for trusted devices and untrusted devices, and several VLANs to isolate them. I guess it's good to know rumors of Ubiquiti's death have been greatly exaggerated in case my Omada hardware starts acting up.