Password change went fine. I expected existing sessions to my controller login would be terminated upon a password change. I suppose that's not mandatory but it sure wouldn't be surprising behaviour for security software IMO. It's the conservative thing to do, no?
Nope. Already logged-in sessions (web and iOS app) remained functional when I changed the underlying password. No need to re-authenticate.
Before I received their breach email today, the past two days I have been unable to log into my controller at all. This was being reported by others through unofficial channels at the same time (Twitter, Reddit). Ubiquiti was silent until this morning. Maybe it's just a bad coincidence.
I'm a new Ubiquiti customer. My gear is < 30 days old. Their UniFi Dream Machine seemed to be my "dream" for a home network (AP, VPN, notifications, guests, pretty dashboard). It's probably better than the alternatives. But I'm forming a less than stellar first impression of them after this. Honeymoon over.