Ubiquiti NDAA Compliance Examined
While many video surveillance manufacturers prominently market / position their NDAA compliance, Ubiquiti does not disclose NDAA-compliant statements publicly, which prompted an IPVM subscriber to ask us for clarification.
Ubiquiti responded to us by saying that the cameras they sell today are NDAA compliant but that some edge cases prevent them from currently issuing a blanket confirmation.
In this report, we examine their statement and the complexities involved.
For background / more on the NDAA, see:
- NDAA Video Surveillance Ban / Blacklists Guide
- NDAA Compliant Video Surveillance List
- US GSA Explains NDAA 889 Part B Blacklisting
- NDAA Ban of Dahua and Hikvision Is Now US Gov Law
Executive *******
***** ****** ** ***** ************ ************* prominently ******* ***** **** ********** (*.*., see****,******) ** ***** ********, ********, *** marketing ** ***** ******** *** ******** being **** ** ************** *******, ******** does *** ******** **** ******* ** is ** ** *** ****-*********, *** users **** ******* **** ********* ** inquire ***** *** ******** *******'* ******.
******** **** **** **** **** * "conservative ********" ******* ********** ************ *** "understand *** *********" ********** **** ****. Ubiquiti ********* **** *** *** ** its ******** *** ****-********* ** **** have **** ******* ******** *************, ****** some ** ***** "***** *******" **** they ** ****** ****, *** *** in ************, ****** ** ********* ** be ********* *** ** *** **** they **** ************.
******** *** *** ******* ** **** what ***** ******** ***** ** ********** or **** ******** ******** *** ** question, ** ** *** *** ******* further ***** ******** *** *** **** compliant.
** ** ******** *** ************* *** to ****** *** ***** ** ******** to ******** ******* **** *** * revised ******* ** **** ********* ***********, e.g., (******* "*" ******** **** *****-*** **. *****-*******). ******** *** *** **** **** and ******* **** ********* ** ******* directly **** **** ** *** **** information / ************, ******* ******** *** questions.
Request ******** ** ********
******* ******** ********* *** **** **** to ******* **** ******** **** ********. For *******,** **** ********** ****:
** ******* *** *** **** ************* was ******. **** * ***** *** they ***** *** ******* *** *************, I *** ******** ** * ****** document ** **** *** *** **** the ************* ***** ** ********. *** Google ******** *** ** ********* ** who * **, *** *** ****** to ** *******, *** * **** the *************, *** *** ********* ** to ****** *** *************, *** *** would **** *** *************. ***** ********** the ******** ******* * ** ****** receive * ******** **** ********.
**** ****, ** *** ******** *****, this ******** *** ******, ******* ********** *********:
***, ** *** ***** *** ** UI, **** **** ***** *** ***** newest ****. * **** *** ****** help ******. **** **** **** ****** about **. * ***** * ********* help **** ** *** ********* *** the **** ******* * *** ** email **** *** ******** ********.
*************, ***** ***** ***, ** *** Ubiquiti *****, **** ******** *** ******, with ***************** ************ *** ******** **** *********:
******** **** ** * *** **** all ********* *********. ***** **** *** products *** **.
** ***** *** ****** **** **** to ****** *** ************.
Ubiquiti ******* **** ********* "**** **** *** **** ****"
******** ***** ** **** ****** ******* "blanket **********" ********** ******* ********** ** some ***-********* ******** ** *** ******* are ***** ** ************. *****, *** new ******* **** **** ** ***** website *** **** *********. **** ******:
*** ******* *** **** ********* *** have **** *** **** ****. *******, some ** *** ***** ******* **** we ** ****** ****, *** **** are ** *** ************ *******, ****** be ********* ** ********* *** ** their **** ** ***********. **** ** why ** ***'* ***** *** ******* statements ** ** **** **********.
******** **** ******* ** ************ *** "likely" *********, *** ** ******* ** the **** ** *************:
******* **** ** **** ***** *** NDAA *********. ******* ** *** ************ channel *** ****** ********* ** ****, but ********* ** ***** **** ** manufacture, ** ***'* *********** ******* **** to *** ****** ********* *** ** to ****** ***** **** **** *** fully *********.
Blanket ********** "** *** **** ******"
******** **** ** *********** *** "*********" associated **** *** ******** *** ****** be **** ** ******* * ******* compliant ********* ** *** "**** ******." They ***:
** **** * ************ ******** ******* compliance ************ *** ** ********** *** tradeoffs **** ******* - ** ****** be ** * ******** ** ******* blanket ********** **** *** ******* ** the **** ******.
Not * "*************** ***********"
******** **** **** ** *** * "straightforward ***********" *** ********* *** ***** is ****** ** ***** *** ******* manufacturers, ****** **** *** ******** *** NDAA ********** ***** ** *** **** of ************* *** *** *** ******* which ****** *** ** *** *** compliant:
** ** **** * *************** ***********, we'd ******* **** ** *** ********* ourselves. *** ***** *** *****, (*) yes, *** ***** ** *** **** of ***********, *** (*) **, ** can't ******* ** *** ******. **** is ******* *** **** ****** *** have **** ********* ** *** ********* contract *************, *** ** ***** ******** us **** ******* ********** ** **** compliance **** *** *****.
**** ********* **** ********'* *********** *** messaging ********* **********. ******** *** ********* partnered / ****** ** **** ***** devices "*********" ***** ***-********* **********, ***** makes ** ********* *** *** ********* to ******* *** ******* ************ **** the ******** *** ****** *********. *** they **** ******* **** ** ******** and ********** *** *** ***-*****.
Challenges *** ******
*** ** *** ******* ********** ****** face ** ******* * ******* ** manufactured (** *********) *** ******** ***-****-********* components ** ************ ** ******** ******* by *** **** ***. ** ********, many ************* ***** ******** *** ********* prominently ******* / ****** **** ** have ********* *** ***** ** ******* their **********, *.*.,
******'* ********** ****** ****:
**,****' ********** ********** ****:
**,*******'* ********** ********:
****, ** **** **** ************* **** fully ****-********* ******* ******* ** *******, such ** ***** ******* *** ******* non-compliant ******** ** ***** *******.
*** ****, *** ******* ********* ***** ************ ****.
*** ******** ** ******. **** ***** Ubiquiti *** **** * ******* **** takes **** ********* *** *** **** the *********. ** ******* **** **** has **** ******* ***** **** **** the ***** ** ***** *** ***, trying ** ***** **** **** *** to **** **** *** ******.
* **** ***** **** ** *** how *****/****** ******** ** **** *****. I ***'* *** ******** ** ***** site **** ********* **** **********.
** *** ********* ********** ******** ** another ****** *** ******** ************* **********. The **** **** **** **** & TAA ********** ** ******* ********** ******** assembling **********.
*. ***** *** ** ************* *********, but ********* ** **** *******, **'* networking *** ******** ******** ****'* ** issue. **'* **** * ****** ***** Protect ******* **** *** ************.
** ****** *** (********* ** *********) get *** *****, ****** *** **** Ubiquiti *** ***** ** **** *** public, **** ***** ** ***********. ** it ******, ***** **** ********** *** anything *** ********* ***** **** **** their **** ** ********** *** *****.
** ** **, *** **** ** email *** ******* **************@**.***
* ** ********* ** *** ******* of ****** ** *** **** ************* from **** ********* **** ** ** another ****, *** *** *** **** report **** ** ****-**-**** / *******, not * **** ******* *********.
** ****** *** *** ** ***** compliance ****, **** **** ** **** them ** ** **********@****.****** * **** ******* ****** / analyze **** **** *******.
* ** ********** ** *** ********** as ****. ** ****** *** ***** product ******* **** ******* ** ******, I ***** **** ** *** ****. Using ****** ****, ***** *** * suppliers *** *** ******** **** *******.
** **#*,
****** *** **** ***** *******. ******** does *** ******* **** **** ********** either (******* ** *** **** **********). But *** **** ** *** ********** see:*** / *** **** ** *** China ********** *****
****, * **** ***** *** ** Ubiquiti *** ******* *** ********* **** will ***** ** ****.
** **** ******** ******** **** *******'* be ******** *** *******.
*'** ** ***** **** ***** ********* make ********* ****** ****** **** *** not ********.
*** ***** ***** **** **** ***** state **** *** ******** ************ ***** date * *** *********. **** *** figure *** **** **** ************ *** their ***** *** ** ***-********* ******** and **** *** *** ****. **** of ************* ** ********* **** *** stock ** * ***********'* *****. **** manufacturers ***** *** **** ** *********** on *** ******* ** ********** *** their *******.
* ***** **** **** ** ********** of *** ****** **** ***** ******** manufacturing. ***** *** *** ***** - "make **** ******* **** **** ********", usually ** ** ******** "**** * product **** ******** ** ***** *****", and **** *** ******** ************ ***** design *** ******* **** ********* **********, performance, ***., ** **** ** ** meets ******* ******* *****. ** **** up ***** * ******* *********, ********** when ****** ** *****...