I’ve been looking to improve the home network in my home lab. It seems that Ubiquiti has everything I could want in their various products.

However, it seems too good to be true. How much snooping does the router/firewall/APs do on my traffic? If you have a similar case, what has been your experience with Ubiquiti?

  • greyfox@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    8 hours ago

    All of the “snooping” is self contained. You run the network controller either locally on a PC, or on one of their dedicated pieces of hardware (dream machine/cloud key).

    All of the devices connect directly to your network controller, no cloud connections. You can have devices outside of your network connected to your network controller (layer 3 adoption), but that requires port forwarding so again it is a direct connection to you.

    You can enable cloud access to your network controller’s admin interface which appears to be some sort of reverse tunnel (no port forwarding needed), but it is not required. It does come in handy though.

    As far as what “snooping” there is, there is basic client tracking (what IP/mac/hostnames) to show what is connected to your network. The firewall can track basics like bandwidth/throughout, and you can enable deep packet inspection which classifies internet destinations (streaming/Amazon/Netflix sort of categories). I don’t think that classification reaches out to the internet but that probably needs to be confirmed.

    All of their devices have an SSH service which you can login to and you have pretty wide access to look around the system. Who knows what the binaries are doing though.

    I know some of their WISP (AirMAX) hardware for long distance links has automatic crash reporting built in which is opt out. There is a pop up to let you know when you first login. No mention of that on the normal Unifi hardware, but they might have it running in the background.

    I really like their APs and having your entire network in the network controller is really nice for visibility but my preference is to build my own firewall that I have more control over and then Unifi APs for wireless. If I were concerned about the APs giving out data, I know I could cut that off at the firewall easily.

    A lot of the Unifi APs can have OpenWRT flashed on them, but the latest Wifi7 APs might be too locked down.

  • lemonuri@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    15 hours ago

    If you are looking for a future proof, snooping free and secure solution for home routers, there is most likely no way around installing open source firmware like openwrt. I would just pick a device with good openwrt support, some ubiquity models have that, if I remember correctly. But there are many alternatives by different manufacturers. I would just chose one with good hardware specs in your price range, install openwrt and call it a day.

  • online@programming.dev
    link
    fedilink
    arrow-up
    4
    ·
    15 hours ago

    Ubiquiti is business oriented, not consumer. It’d be very foolish for them to snoop on the traffic of their business customers.

    Ubiquiti is also a traded company. Their stock would crater in lieu of such news.

    As a consumer, besides reliability, privacy is another main reason to paying extra for enterprise gear.