• 0 Posts
  • 179 Comments
Joined 11 months ago
cake
Cake day: August 8th, 2023

help-circle




  • A lot of negativity around Ubiquity in here, which is surprising to me, honestly. I had their USG for years and loved it, recently swapped it out for the Dream Machine and love it. Really don’t understand the complaints about linking it to the cloud. I just didn’t bother, everything works fine. Additionally, I managed to get a Debian container running on it and installed ntopng, it’s been awesome for getting realtime visibility into my network traffic.

    E. I should add I have 6 of their switches and 3 access points, one of which is at least 7 years old and still receiving updates.








  • You aren’t wrong, per se, I think you just don’t fully grasp the attack vector. This is related to DHCP option 121, which allows routes to be fed to the client when issuing the ip address required for VPN connectivity. Using this option, they can send you a preferred default route as part of the DHCP response that causes the client to route traffic out of the tunnel without them knowing.

    E. It would likely only be select traffic routing out of the tunnel. I could, for example, send you routes so that all traffic destined for Chase Bank ip addresses comes back to me instead of traversing the tunnel. Much harder to detect.








  • They’re not detached, they’re playing a different game. The game of the greedy little piggies.

    If I give you a raise, well, it just might get out that we give raises around here! Suddenly, I got all these, lazy, do nothing greedy little piggies asking for more money! That 5k becomes 20k, then 50k, etc.! My hard earned slop is drying up quick!

    But if I hire someone new, I send the exact opposite message. We don’t do raises here, and if you don’t like it, we have no trouble replacing you, greedy little piggie!