I’ve been looking into options for home networking as my needs expand, and Ubiquiti’s equipment has caught my eye. I love the idea of a single unified interface to control everything, and it all being under the same company for easy integration. There stuff seems decently priced and they have a wide range of products categories that can fulfill everything I want. They seem to be very friendly to self-hosting with their various statements about being license-free and cloud independent, which are both very important to me. They’re trusted by a lot of large businesses (As reported by them) and even Jake from LinusTechTips uses them, so I thought it would be perfect. I was about ready to order some gear when I saw the privacy policy at checkout. I read through a bit of it and did some light research, and found that they are not the friendly company I thought they were.
According to posts on tforum, any switch, AP, etc. you install phone’s home constantly with little bits of telemetry and usage info. The same posts also claim you can’t turn it off, and the most you can really do is anonymise it so it can’t be tied back to you. There are a few guides on other forums that show how to limit tracking, but they all rely on using tools in UniFi to block switches; but I think Ubiquiti has demonstrated their untrustworthiness, so I don’t have faith they won’t secretly ignore some settings. In addition to telemetry and usage statistics, Ubiquiti also has a “Remote Access” feature that lets you control your network from anywhere by using a reverse proxy through their servers. I’m worried this might give them access to the UniFi Protect portal, which would let them see through my cameras or unlock doors.
This seems a little out of whack for something targeting an enterprise deployment, so there is surely a way to disable it. I was wondering if anyone here uses Ubiquiti and would be willing to share their experience with me? Also, does anyone have any ideas on how to secure my privacy if I do decide to stick with them? My current thought is a something running OpenWRT and AdGuardHome/PiHole between the gateway and my modem. I love the idea of UniFi and having all my infrastructure under the same umbrella, and their cameras look really good quality for the price, but I don’t want my backbone phoning home about everything I do. If anyone has an alternative to UniFi, I’d also love to hear that. I’ve heard about MikroTik and Peplink, but I haven’t had the time to research them yet.
Edit:
After reading more articles online, I've decided that I'm willing to take the plunge. They have a fairly decent return policy (14 days, no damage, maybe a 15% loss), and I have the cash to spare. I'm just gonna get a gateway and a switch, and see what happens when I plug in a few dummy devices. The plan is to have something in between the gateway and the modem running AdGuardHome for domain name filter, and an iptables ruleset for catching slip-ups. I'll make a follow-up post after running the setup for a bit. If anyone has any tests they want me to run, feel free to ask.
Edit 2:
Follow-up: /post/8754e13c7a5c032b47cc
/post/ba14d9286c3dfc20822c
comments are good too
comments are good too
VLANs are for managing devices on a network, not necessarily the network devices themselves. I don't trust that Ubiquiti devices will follow those rules and enforce them for each other. I have no doubt that end devices after the network layer would be managed perfectly, but I'm more concerned about the network hardware right now. The comments were interesting, but they did not really provide much information related to my question. DD-WRT, OpenWRT, and pfSense are all firmware for the devices, and not a management engine like UniFi.