It's disappointing to see a breach like this and even more disappointing to see what (at least on the surface) appears to be a lackadaisical response.
At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewhat pricey; but, not totally unreasonable option for the home.
For me it's one of the few options available because my ISP forces me to use a transitional IPv6 technology called "MAP-E," which the UniFi products don't support. I switched ISPs after purchasing my equipment and ended up with $700 of dead weight.
I can at least verify a portion of the second claim of this reviewer's post. A section of the EULA does dictate that Synology grants itself the right to conduct an audit to protect their intellectual property.
"Section 7. Audit.Synology will have the right to audit your compliance with the terms of this EULA. You agree to grant Synology a right to access to your facilities, equipment, books, records and documents and to otherwise reasonably cooperate with Synology in order to facilitate any such audit by Synology or its agent authorized by Synology."
I can't verify the claims about "Peoples' Republic of China PRC" being allowed to enter a non-Chinese citizen's home (US citizen) to protect IP. Might be applicable to Taiwan or Chinese citizens.
I am not a lawyer so I cant determine whether this EULA is enforceable in the US or EU. Regardless of enforceability, I would be hesitant to buy Synology products as well. Who knows what backdoors they have implemented in order to satisfy the Chinese government.
Given synology is owned and operated out of Taiwan, it’s rather silly to make claims about the prc.
As far as I know that clause was created years ago when people were using key generators to make keys for surveillance station licenses. I don’t know of anyone who has ever actually been audited.
Fwiw, i have 2 synology routers, and did not have to create a cloud account or use the cloud to setup. Its there, and an option, and you can get other plugins if u have the cloud account, but by no means is it required for setup or use.
Thank you for that link, I had not realized Synology had moved into the router space, and I've been running Synology NASes for almost a decade! Generally I've been happy with them, and on the few occasions I need tech support, it was surprisingly good (going on with zero expectations based on other companies' support in the past).
I recently went with two 2200acs. Been mostly pleased, but there were some settings i had to play with to get the right router to use some of the more distant devices.. without custom settings it trys to load balance devices over choosing based on signal strength, thus a far device from the main router had an unusable connection..
Unifi's router isn't all that great. I would go with other software (like opnsense), which is the recommendation of some others out there.
Their switches and APs are still really good. For alternatives, it depends on your goals. How many configuration options do you need? Is cloud management bad? Any more.
For consumer: Google, Eero, Orbi and some of the others are good. If you want more control, you need to venture into the SMB and Enterprise space.
Unifi, Engenius, Aruba Instant On, Tp-link Omada, Mikrotik, Ruckus and maybe some others. It really depends on your desired feature set.
Last time I looked into this (admittedly several years ago), TP-Link had a really poor reputation for not patching known security issues in their firmware.
Not sure how much I’d trust their products unless they’ve really done a 180 in terms of security in the last year or two.
It's pretty hard to deny that Chinese US relations are heating up. Supporting your own supply chain is becoming a matter of national security, both in terms of potential attacks (what if they load state software on Chinese devices, especially as a response to military action), and in terms of supporting your own industry.
30 years ago, my, then-Representative, Mike Pence was going around supporting tariffs on Chinese steel. I thought tariffs were a Bad Idea, prima facie. Pence explained that if we allowed China to decimate our steel industry, we wouldn't be able to make tanks, domestically. Cogito ergo sum, it was a _literal_ national defense issue.
I don't know where the steel issue stands any more, but we've already been at war with China over intellectual property for 20 years. It would make a great deal of sense to subsidize domestic silicon fabs and computer hardware manufacturing, and tariff foreign versions, for the same reason.
It's no secret why Facebook is not allowed in China. They know exactly what it really does, and what its true value is, and they're not willing to allow that leverage to the US, and it's disturbing that their lack of reciprocity doesn't seem to cause much concern.
It's kind of disgusting that we've outsourced so much of our infrastructure to a country which, in another generation, is going to become the world's most powerful. China is playing the long game. We're willingly giving up our lead because we've built our post-70's society on the almighty stock option, and our myopic focus on only the next quarter.
I don’t deny any of that. But where is most of the hardware for just about any network and computing equipment manufactured? Questioning if tplink is made in China is pretty low effort and pointless.
A thoughtful analysis would ask why an onshore supplier would fundamentally be any less vulnerable to political adversaries.
Much like Cisco being exposed to US supply chains leaves them vulnerable to tampering by US intelligence through physical interception, merely being made in China is a security risk.
I dumped their gateway/security appliance in favor of Opnsense box. Never looked back or regretted it. Their security appliance is not as granular as I would want and the Opnsense was a learning opportunity for me.
context: former pfsense, unifi dream machine, unifi ap user
I'm running openwrt on a rpi4-2gb (usb ethernet dongle for WAN, onboard ethernet for LAN) and and a TP-LINK EAP245 access point and have been extremely happy. For reference, my connection to my ISP is 940 down / 840 up, and the pi4 handles SQM/QoS on this line without breaking a sweat
I do plan to flash openwrt on to the eap245 as soon as the 5ghz drivers become usable, I like the hardware and the stock firmware isn't bad, but just not nearly as good as openwrt. there's a port of openwrt to the eap right now but 5ghz speed is limited to 2.4ghz speed for some reason at the moment.
I’m not aware of any alternatives that are designed as well, and if you switch the new option could just as easily be hacked or if so it on it could also be hacked but you may never realize. Though it’s good for all these people to pretend to threaten to leave since maybe that will get the company to be a little more forth right which is all we can really ask for these days.
At someone who runs a UniFi network in my home with just 4 pieces of hardware (gateway, wired switch, and 2 PoE WAPs) I'm really curious if there are solid alternatives for a managed home network. UniFi really hit a sweet spot of price/performance that made it a somewhat pricey; but, not totally unreasonable option for the home.
Any suggestions from the HN crowd?