How do we know we can trust e.g. Unify, Reolink, etc?

Yeah, I am using VPN all the time for that reason and never using torrents. Also we picked one that is homelab friendly, I think they even allowed some people to use completely their own router and just connecting via modem. We didn’t try this yet though.

Right now, I mainly need one outside camera to protect our bikes. I am not sure I ever want to have indoor cameras, that would be too unpleasant for me anyway.

This isn’t a good practice, firmware updates often fix security issues and add enhancements. They aren’t sending anything to state actors or anything. I’ve had some fixes that were great for the APs.

They have been caught sending telemetry about LANs with those packages, so no, I don’t agree with you.

I also don’t agree with this modern mindset that we should thank our corporate overlords for taking care of our security for us. I don’t want their enhancements that consist of disabling functionality and putting things behind paywalls and subscriptions. I bought it as is, I want it as is. I do not trust corporate vendors not to change their terms of service to benefit them at any time - they do so often, and they try to break perfectly good products. Louis Rossmann has a whole wiki about their games.

I am responsible for my own security. I will decide when to update my devices, and there’s zero reason for anyone to be on my LAN generating traffic other than me. Automation and convenience not driven by my explicit requests is not helpful: it’s a trap where I give away my autonomy and then I’m a digital slave. No thanks.

Good practice is ensuring that those devices are blocked from internet access. No in, no out. The only way they get traffic is when I give it to them. They cannot be exploited if they have no pathway to the internet.

I do not trust corporate vendors, and I consider them to be a higher risk than random attackers because I am not a target for nation states or digital gangsters - I am merely a target for corporate data mining.

You must physically access my premises to have a chance of exploiting these kinds of devices because I have them locked down. There is no better security than that.

1 Like

I was specifically pointing to ubiquit’s unifi: ubiquiti is subscription free and what functionality have they taken away? all I’ve seen was them adding stuff, not taking stuff away.

I agree with the first parts of the 2nd paragraph, but we should also recognize the good things that companies like ubiquiti do, and need to recommend companies that are still pro-consumer at the same time.

other vendors might not be the case and may do anti-consumer crap, however I do not think spreading fud all over when we need to individualize things.

Companies pivot, change business strategy, shift culture, or get acquired all the time.

Reputable community driven FLOSS projects I find to be much more consistent, for instance for a prospective router I have much more confidence in no big surprises happening in the next decade with Debian, FreeBSD, OpenBSD, etc than I have with any proprietary vendors.

Ubiquiti is a business. They are slowly realizing that subscriptions are more profitable than low margin hardware, and they’ve already saturated the niche of technical users who recognize their ease of use and reasonable pricing. They’ve built a reputation. The next logical step is to forsake that niche base and to expand outward into main stream products and pivot revenue toward higher margin opex. This is a simple business pivot, and there’s case studies everywhere to support them.

It’s only a matter of time until they start changing their products. If you have your eyes open you can already see it as they increase their telemetry gathering and the dark patterning toward cloud services is beginning. Install their new network controller and it gives you endless popups about their cloud services now to try to push you to them and get you to subscribe and give them more data. It will become more slippery and more obtrusive as time goes on and they capture more opex customers - they’re nearing critical mass.

Call it enshittification if you want, but I call it good business. It’s the value of reputation being exchanged for a pivot into a more lucrative economic space. If it was my business, this is exactly what I’d be doing.

Which is why I recognize it, and I take steps to ensure that maturing corporate vendors are locked down and locked out.

Why is it that you want to give them the benefit of the doubt? What do you gain from that, exactly? Perhaps some features, perhaps a prettier UI than what they had a few years ago. I read the changelogs, and I don’t see anything of value in there for me. So I don’t update, because I don’t want or need anything they’re offering. And I see the trap, so I won’t spring it.

Corporate vendors do not deserve my loyalty nor my data. There’s no reason for me to give them anything other than my money in exchange for the product. As I said earlier in the thread, I think the key importance here is in being aware and making decisions accordingly.

If you see something specific in the changelog that you want or need - some specific security patch or feature you’ve been waiting for - then by all means. I won’t judge you for getting what you need or even what you want. I have no qualms with you taking their convenience factor either. As long as you’ve done that understanding the trade-offs, then all the power to you.

I only take pause when you refer to some blanket requirement that I update firmware because of “modern norms and standards” and that I should give them my loyalty to be “safe”/”secure” or get the “convenience” they’re offering because “they deserve it”. Then calling it FUD when I point out that a business does business things?

That’s bizarre to me. Confusing.

I… don’t know what you’re talking about when you say that. It makes no sense and looks only like a lack of self-determination to me. That, I’ll judge. Then I’ll wish you a good evening and go walk the dog.

1 Like

any evidence that ubiquiti is going to do that?

Sure, my MBA and 30 years in the industry. If you won’t take that, then I have nothing else to give. I’m not interested in crawling the internet for links to prove something to a forum user. All I’ve got for you is what I’ve said.

As I said, you make the decisions that you feel best align with your objectives. Sounds like you’re already doing that so you’re good to go.

look, I told you to show examples that ubiquiti is pivoting to subscritions. not your life story.

1 Like

Reminds me of The Parable Of The Turkey

1 Like

this isn’t a philosophy class, this is a discussion of “phoning home” and subscriptions.

which UI does neither.