• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Forced backup of configuration files onto cloud services - do you agree?

Firewalls and routers with OBLIGATORY requirement to backup the config files to the cloud!?

  • Forced cloud backup to unknown servers is OK - it's all legit, unhackable and secure

    Votes: 0 0.0%
  • Forced cloud backup to known servers is OK - we trust the vendor, and Intelligence Agencies

    Votes: 0 0.0%

  • Total voters
    25
  • Poll closed .
Joined
Aug 30, 2006
Messages
7,221 (1.09/day)
System Name ICE-QUAD // ICE-CRUNCH
Processor Q6600 // 2x Xeon 5472
Memory 2GB DDR // 8GB FB-DIMM
Video Card(s) HD3850-AGP // FireGL 3400
Display(s) 2 x Samsung 204Ts = 3200x1200
Audio Device(s) Audigy 2
Software Windows Server 2003 R2 as a Workstation now migrated to W10 with regrets.
This week my Ubiquiti Dream Machine Pro offered a firmware update. Great. Always happy to have bugs squashed and new features added.

But I noticed something new: There is a new forced use of ubnt's cloud service in order to update firmware. You have to opt in: Enable Cloud Config Backup and have your config files uploaded to some unknown cloud service, in an unknown country, with unknown data protection, or you can't update the firmware. What?! Our company has a strict policy: NO data in the cloud, especially data that contains security profiles (configurations, usernames, passwords) etc. It is a dismissible offence to let protected data leave the building.

This is quite a problem. Not just in my case, but all cases where on-site hardware or applications FORCE the admin/user to send data to the cloud. Not only is this not giving the admin/user choice, but it seems to me to be in breach of EU-GDPR laws. Moreover, it adds a new attack vector. Config and security profiles are now sitting around on a cloud server somewhere, where you have no idea where it is, how it is being secured, who "has eyes on it" etc.

What do you think?

Oh, and don't tell me Sophos, Synology, Ubiquiti have never had security or data breaches!

unifi.png
 
Last edited:

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
42,002 (6.62/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Joined
Aug 20, 2007
Messages
21,432 (3.40/day)
System Name Pioneer
Processor Ryzen R9 9950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage Intel 905p Optane 960GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64 / Windows 11 Enterprise IoT 2024
Forced is the key word here I take issue with. I'm fine with cloud backup if it isn't forced.
 
Joined
Feb 1, 2019
Messages
3,560 (1.68/day)
Location
UK, Midlands
System Name Main PC
Processor 13700k
Motherboard Asrock Z690 Steel Legend D4 - Bios 13.02
Cooling Noctua NH-D15S
Memory 32 Gig 3200CL14
Video Card(s) 4080 RTX SUPER FE 16G
Storage 1TB 980 PRO, 2TB SN850X, 2TB DC P4600, 1TB 860 EVO, 2x 3TB WD Red, 2x 4TB WD Red
Display(s) LG 27GL850
Case Fractal Define R4
Audio Device(s) Soundblaster AE-9
Power Supply Antec HCG 750 Gold
Software Windows 10 21H2 LTSC
I can only see this poll going one way. :)
 
Joined
Aug 4, 2020
Messages
1,612 (1.03/day)
Location
::1
Forced is the key word here I take issue with. I'm fine with cloud backup if it isn't forced.
and then all the idiots who are getting (chain-)pwned when, invariably the cloud server's getting pwnt will come crying

tbh, those guys just have to get pwnt once and then get sued out of the solar system for ensuing damages, but yea
 
Joined
Dec 14, 2019
Messages
1,187 (0.66/day)
Location
Loose in space
System Name "The black one in the dining room" / "The Latest One"
Processor Intel Xeon E5 2699 V4 22c/44t / i7 14700K @5.8GHz
Motherboard Asus X99 Deluxe / ASRock Z790 Steel Legend WiFi
Cooling Arctic Liquid Freezer II 240 w/4 Silverstone FM121 fans / Arctic LF II 280 w Silverstone FHP141's
Memory 64GB G.Skill Ripjaws V DDR4 2400 (8x8) / 96GB G.Skill Trident Z5 DDR5 6400
Video Card(s) EVGA RTX 1080 Ti FTW3 / Asus Tuff OC 4090 24GB
Storage Samsung 970 Evo Plus, 1TB Samsung 860, 4 Western Digital 2TB / 2TB Solidigm P44 Pro & more.
Display(s) 43" Samsung 8000 series 4K / 50" Vizio M-series 4K
Case Modded Corsair Carbide 500R / Modded Corsair Graphite 780 T
Audio Device(s) Asus Xonar Essence STX/ Asus Xonar Essence STX II
Power Supply Corsair AX1200i / Seasonic Prime GX-1300
Mouse Logitech Performance MX, Microsoft Intellimouse Optical 3.0
Keyboard Logitech K750 Solar, Logitech K800
Software Win 10 Enterprise LTSC 2021 IoT / Win 11 Enterprise IoT LTSC 24H2
Benchmark Scores https://www.passmark.com/baselines/V11/display.php?id=202122048229
I don't trust anything I can't put a hand on when I feel like it, especially vital backup data. For some things I use two or three separate or external drives for redundant safety assurance.
 
Joined
Aug 20, 2007
Messages
21,432 (3.40/day)
System Name Pioneer
Processor Ryzen R9 9950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage Intel 905p Optane 960GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64 / Windows 11 Enterprise IoT 2024
and then all the idiots who are getting (chain-)pwned when, invariably the cloud server's getting pwnt will come crying
Cost of entry.
 
Joined
Nov 11, 2010
Messages
310 (0.06/day)
System Name Uzuki Toune
Processor AMD RYZEN 7 7700X (ASUS PBO 90C Mode)
Motherboard Asus ROG Strix X670E-E Gaming WIFI
Cooling Thermalright Frostspirit 140 White V3 ARGB
Memory 32GB DDR6000 CL36 Kingston (EXPO)(16GBx2)
Video Card(s) Zotac GTX 1050TI
Storage 2TB Kingston KC3000 + 1TB Crucial P2 + 480GB Samsung Evo 850 + 480GB Kingston A400
Display(s) Dell U2723QE + Philips 221V8 (Portrait)
Case NZXT H510
Audio Device(s) Auzen X-FI Forte + Onboard Realtek 4080 -> Creative Gigaworks T40II
Power Supply EVGA G+ 650W
Mouse Logitech MX Master 3 (Work) & G103 (Play)
Keyboard iRocks K71M
Software Windows 11 Professional
This week my Ubiquiti Dream Machine Pro offered a firmware update. Great. Always happy to have bugs squashed and new features added.

But I noticed something new: There is a new forced use of ubnt's cloud service in order to update firmware. You have to opt in: Enable Cloud Config Backup and have your config files uploaded to some unknown cloud service, in an unknown country, with unknown data protection, or you can't update the firmware. What?! Our company has a strict policy: NO data in the cloud, especially data that contains security profiles (configurations, usernames, passwords) etc. It is a dismissible offence to let protected data leave the building.

This is quite a problem. Not just in my case, but all cases where on-site hardware or applications FORCE the admin/user to send data to the cloud. Not only is this not giving the admin/user choice, but it seems to me to be in breach of EU-GDPR laws. Moreover, it adds a new attack vector. Config and security profiles are now sitting around on a cloud server somewhere, where you have no idea where it is, how it is being secured, who "has eyes on it" etc.

What do you think?

Oh, and don't tell me Sophos, Synology, Ubiquiti have never had security or data breaches!
If you are concerned about GDPR compliance, you wouldve thrown out all of your Ubiquity stuff a long time ago. They have already proven that they are not GDPR compliant in their forums to their own users. The fact that you still have your Ubiquity stuff phoning home without a care in the world shows you actually do not care about privacy and GDPR. Don't be a hypocrite please.
 
Joined
Aug 30, 2006
Messages
7,221 (1.09/day)
System Name ICE-QUAD // ICE-CRUNCH
Processor Q6600 // 2x Xeon 5472
Memory 2GB DDR // 8GB FB-DIMM
Video Card(s) HD3850-AGP // FireGL 3400
Display(s) 2 x Samsung 204Ts = 3200x1200
Audio Device(s) Audigy 2
Software Windows Server 2003 R2 as a Workstation now migrated to W10 with regrets.
@thewan, hmmm, all diagnostics, logs, backups, error reporting, etc. are TURNED OFF. But you say this thing STILL PHONES HOME with user, password, config, data? That's bad news. No, I was not aware that with all cloud and phone-home settings turned off this thing was still doing it.
:shadedshu:
 

Frick

Fishfaced Nincompoop
Joined
Feb 27, 2006
Messages
19,503 (2.85/day)
Location
Piteå
System Name White DJ in Detroit
Processor Ryzen 5 5600
Motherboard Asrock B450M-HDV
Cooling Be Quiet! Pure Rock 2
Memory 2 x 16GB Kingston Fury 3400mhz
Video Card(s) XFX 6950XT Speedster MERC 319
Storage Kingston A400 240GB | WD Black SN750 2TB |WD Blue 1TB x 2 | Toshiba P300 2TB | Seagate Expansion 8TB
Display(s) Samsung U32J590U 4K + BenQ GL2450HT 1080p
Case Fractal Design Define R4
Audio Device(s) Line6 UX1 + Sony MDR-10RC, Nektar SE61 keyboard
Power Supply Corsair RM850x v3
Mouse Logitech G602
Keyboard Cherry MX Board 1.0 TKL Brown
Software Windows 10 Pro
Benchmark Scores Rimworld 4K ready!
If you are concerned about GDPR compliance, you wouldve thrown out all of your Ubiquity stuff a long time ago. They have already proven that they are not GDPR compliant in their forums to their own users. The fact that you still have your Ubiquity stuff phoning home without a care in the world shows you actually do not care about privacy and GDPR. Don't be a hypocrite please.

If it's true they are not GDPR compliant, you should report them.
 
Joined
Oct 24, 2020
Messages
466 (0.31/day)
Location
Belgium
System Name MSi Coffee Lake
Processor i7-8700k
Motherboard MSI Z370 GAMING PRO CARBON AC
Cooling NZXT something AIO loop
Memory 16GB Kingston HyperX 2133 C14 Fury Black
Video Card(s) TITAN Xp Jedi Order Edition
Storage Samsung 960 Evo NVMe
Display(s) Medion 23'
Case Cooler Master Stryker
Audio Device(s) onboard
Power Supply BeQuiet 600W
Mouse Logitech Trackman T-BB18
Keyboard Generic hp
Software Windows 10
These companies must think they can't be hacked.
Until they are hacked by someone smarter than them.
 
Joined
Aug 30, 2006
Messages
7,221 (1.09/day)
System Name ICE-QUAD // ICE-CRUNCH
Processor Q6600 // 2x Xeon 5472
Memory 2GB DDR // 8GB FB-DIMM
Video Card(s) HD3850-AGP // FireGL 3400
Display(s) 2 x Samsung 204Ts = 3200x1200
Audio Device(s) Audigy 2
Software Windows Server 2003 R2 as a Workstation now migrated to W10 with regrets.
On 11.01.21, I got this email from Ubiqiuti.


Dear Customer,

We recently became aware of unauthorized access to certain of our information technology systems hosted by a third party cloud provider. We have no indication that there has been unauthorized activity with respect to any user’s account.

We are not currently aware of evidence of access to any databases that host user data, but we cannot be certain that user data has not been exposed. This data may include your name, email address, and the one-way encrypted password to your account (in technical terms, the passwords are hashed and salted). The data may also include your address and phone number if you have provided that to us.

As a precaution, we encourage you to change your password. We recommend that you also change your password on any website where you use the same user ID or password. Finally, we recommend that you enable two-factor authentication on your Ubiquiti accounts if you have not already done so.

Change Password
Enable Two-Factor Authentication

We apologize for, and deeply regret, any inconvenience this may cause you. We take the security of your information very seriously and appreciate your continued trust.

Thank you,
Ubiquiti Team

What I read here is this: ME----UBIQUITI----3RD PARTY CLOUD PROVIDER

So Ubiquiti isnt even providing the cloud services directly, but through a 3rd party.

What I perceive is this: ME---Attack Vector---UBIQUITI---Attack Vector---3RD PARTY CLOUD PROVIDER---Attack Vector / Data Sharing---nefarious data collecting intelligence agency.
 
Last edited:
Joined
Aug 14, 2013
Messages
2,373 (0.58/day)
System Name boomer--->zoomer not your typical millenial build
Processor i5-760 @ 3.8ghz + turbo ~goes wayyyyyyyyy fast cuz turboooooz~
Motherboard P55-GD80 ~best motherboard ever designed~
Cooling NH-D15 ~double stack thot twerk all day~
Memory 16GB Crucial Ballistix LP ~memory gone AWOL~
Video Card(s) MSI GTX 970 ~*~GOLDEN EDITION~*~ RAWRRRRRR
Storage 500GB Samsung 850 Evo (OS X, *nix), 128GB Samsung 840 Pro (W10 Pro), 1TB SpinPoint F3 ~best in class
Display(s) ASUS VW246H ~best 24" you've seen *FULL HD* *1O80PP* *SLAPS*~
Case FT02-W ~the W stands for white but it's brushed aluminum except for the disgusting ODD bays; *cries*
Audio Device(s) A LOT
Power Supply 850W EVGA SuperNova G2 ~hot fire like champagne~
Mouse CM Spawn ~cmcz R c00l seth mcfarlane darawss~
Keyboard CM QF Rapid - Browns ~fastrrr kees for fstr teens~
Software integrated into the chassis
Benchmark Scores 9999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
Joined
Feb 20, 2020
Messages
9,340 (5.40/day)
Location
Louisiana
System Name Ghetto Rigs z490|x99|Acer 17 Nitro 7840hs/ 5600c40-2x16/ 4060/ 1tb acer stock m.2/ 4tb sn850x
Processor 10900k w/Optimus Foundation | 5930k w/Black Noctua D15
Motherboard z490 Maximus XII Apex | x99 Sabertooth
Cooling oCool D5 res-combo/280 GTX/ Optimus Foundation/ gpu water block | Blk D15
Memory Trident-Z Royal 4000c16 2x16gb | Trident-Z 3200c14 4x8gb
Video Card(s) Titan Xp-water | evga 980ti gaming-w/ air
Storage 970evo+500gb & sn850x 4tb | 860 pro 256gb | Acer m.2 1tb/ sn850x 4tb| Many2.5" sata's ssd 3.5hdd's
Display(s) 1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24"/ 3rd LG 43" series
Case D450 | Cherry Entertainment center on Test bench
Audio Device(s) Built in Realtek x2 with 2-Insignia 2.0 sound bars & 1-LG sound bar
Power Supply EVGA 1000P2 with APC AX1500 | 850P2 with CyberPower-GX1325U
Mouse Redragon 901 Perdition x3
Keyboard G710+x3
Software Win-7 pro x3 and win-10 & 11pro x3
Benchmark Scores Are in the benchmark section
Hi,
Yeah spooky the way this and operating system cloud auto uploading of personal files is being pushed so hard by ms and also cell phones to just to email or text a image lol

It's like a fishing expedition to find bad doers at the cost of everyone's elses privacy flushed down the nsa/.. drain.
The "well you have nothing to worry about if not a bad doer" is just a lame side to take seeing fighting the government local or federal with limitless resources is a loosing proposition for individuals

Some countries do have policies that information has to be stored on the same soil as the user but this is just so authorities has direct access to it and don't have to jump threw other countries jurisdictions protocols for access causing delays.
 
Joined
Feb 18, 2005
Messages
5,834 (0.81/day)
Location
Ikenai borderline!
System Name Firelance.
Processor Threadripper 3960X
Motherboard ROG Strix TRX40-E Gaming
Cooling IceGem 360 + 6x Arctic Cooling P12
Memory 8x 16GB Patriot Viper DDR4-3200 CL16
Video Card(s) MSI GeForce RTX 4060 Ti Ventus 2X OC
Storage 2TB WD SN850X (boot), 4TB Crucial P3 (data)
Display(s) 3x AOC Q32E2N (32" 2560x1440 75Hz)
Case Enthoo Pro II Server Edition (Closed Panel) + 6 fans
Power Supply Fractal Design Ion+ 2 Platinum 760W
Mouse Logitech G602
Keyboard Razer Pro Type Ultra
Software Windows 10 Professional x64
No, there is no justification for this. Even if we take the most charitable possible view that Ubiquiti is trying to help you in case the upgrade goes FUBAR, there's no justification for forcing the use of a cloud service over, say, a USB flash drive.

But this is where dumb companies are gonna be dumb companies, and fail both communications and UI design 101. Instead of imposing a decision that could be construed as unpopular on customers, you let them know about it beforehand so they can let you know that you're being a dumb company. And if you fail to do that, you at least put some information in the UI that's forcing that unpopular decision, to inform users about why it's necessary. Ubiquiti has managed to do neither of these things, which is dumb, dumb, dumb.
 
Joined
Aug 30, 2006
Messages
7,221 (1.09/day)
System Name ICE-QUAD // ICE-CRUNCH
Processor Q6600 // 2x Xeon 5472
Memory 2GB DDR // 8GB FB-DIMM
Video Card(s) HD3850-AGP // FireGL 3400
Display(s) 2 x Samsung 204Ts = 3200x1200
Audio Device(s) Audigy 2
Software Windows Server 2003 R2 as a Workstation now migrated to W10 with regrets.
Thanks @claes , I'll try that.
 
Joined
Aug 30, 2006
Messages
7,221 (1.09/day)
System Name ICE-QUAD // ICE-CRUNCH
Processor Q6600 // 2x Xeon 5472
Memory 2GB DDR // 8GB FB-DIMM
Video Card(s) HD3850-AGP // FireGL 3400
Display(s) 2 x Samsung 204Ts = 3200x1200
Audio Device(s) Audigy 2
Software Windows Server 2003 R2 as a Workstation now migrated to W10 with regrets.
@claes, the trick, hack, workaround, worked!
 
Joined
Aug 14, 2013
Messages
2,373 (0.58/day)
System Name boomer--->zoomer not your typical millenial build
Processor i5-760 @ 3.8ghz + turbo ~goes wayyyyyyyyy fast cuz turboooooz~
Motherboard P55-GD80 ~best motherboard ever designed~
Cooling NH-D15 ~double stack thot twerk all day~
Memory 16GB Crucial Ballistix LP ~memory gone AWOL~
Video Card(s) MSI GTX 970 ~*~GOLDEN EDITION~*~ RAWRRRRRR
Storage 500GB Samsung 850 Evo (OS X, *nix), 128GB Samsung 840 Pro (W10 Pro), 1TB SpinPoint F3 ~best in class
Display(s) ASUS VW246H ~best 24" you've seen *FULL HD* *1O80PP* *SLAPS*~
Case FT02-W ~the W stands for white but it's brushed aluminum except for the disgusting ODD bays; *cries*
Audio Device(s) A LOT
Power Supply 850W EVGA SuperNova G2 ~hot fire like champagne~
Mouse CM Spawn ~cmcz R c00l seth mcfarlane darawss~
Keyboard CM QF Rapid - Browns ~fastrrr kees for fstr teens~
Software integrated into the chassis
Benchmark Scores 9999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
Glad it did :)
 
Joined
Aug 30, 2006
Messages
7,221 (1.09/day)
System Name ICE-QUAD // ICE-CRUNCH
Processor Q6600 // 2x Xeon 5472
Memory 2GB DDR // 8GB FB-DIMM
Video Card(s) HD3850-AGP // FireGL 3400
Display(s) 2 x Samsung 204Ts = 3200x1200
Audio Device(s) Audigy 2
Software Windows Server 2003 R2 as a Workstation now migrated to W10 with regrets.
ONE MONTH! after raising a ticket with Ubiquiti, I got the following recommendation:

Updating via SSH​

Note: SSH updating is not an officially supported process and may prevent your UniFi OS console from functioning. Only do this at the request of UI Support. It is only prescribed to work around specific scenarios, such as when:

  • Prior traditional update attempts have failed. A successful SSH update will help verify if initial failures resulted from incorrect network configuration. For more details, see Troubleshooting Device Updates.
  • Your UniFi Network device is not being discovered or cannot be adopted because it has been preloaded with outdated firmware.
  • Your UniFI OS Console cannot be set up because it has been preloaded with an outdated version of UniFi OS.

UAP/USW (Internet)​

  1. Copy the update link from community.ui.com/releases.
  2. SSH into your device.
  3. Run the following command: upgrade paste_download_link_here
    Example: upgrade https://dl.ui.com/unifi/firmware/UAL6/5.60.1.12923/BZ.mt7621_5.60.1+12923.210416.1641.bin

Other methods follow this link:​

https://help.ui.com/hc/en-us/articles/204910064-UniFi-Advanced-Updating-Techniques
 
Top