Live data from Hacker News

My NAS exposes itself over the internet without permission

kn100.me

71–80 of 311 posts

Re: My NAS exposes itself over the internet without permission

#71

Earlier quoted context omitted.

> Notably, it is a must for VoIP Wouldn't making STUN work be a better alternative?

Yes, it’s a feature supported by many VOIP clients, and this comments section is filled with UPnP apologists

As I said, "without going through a relay".

And TURN is one of those relays.

(I host a STUN and TURN relay myself, because I had to for my personal VoIP server for enough people to be able to connect on it. Downside is more use of bandwidth.)

edit: replaced STUN with TURN where appropriate, I did confuse both as they were provided as a single package.

Re: My NAS exposes itself over the internet without permission

#72
post #43

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

I find it amusing that many people are convinced that IPv6 is less safe, because there is no NAT, and at the same time use UPnP. No, NAT isn't designed for security, the blocking of incoming traffic is just side effect, you should use a firewall for security.

Yep, the author depends on NAT as a security feature, when it was never designed to be one. UPnP is a convenience feature, and is disabled in all security focused networks. If you want convenience and security, set up two VLANs, one for your insecure UPnP devices, and one for your more sensitive devices.

Re: My NAS exposes itself over the internet without permission

#73

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

Edited: deleted my comment as I was unintentionally offensive.

You mean ignoring the fact that a NAS which claims to not be available over the internet is available over the internet?

The correct solution is the NAS manufacturer needs to correct the issue and provide a software update.

This article shouldn't be ignored at all. Your supposed "correct solution" does nothing to fix the root issue.

Re: My NAS exposes itself over the internet without permission

#74
post #61
post #55

Earlier quoted context omitted.

I'm wondering what definition of the word "offensive" you're using.

Offensive as Rude. Then @kn100 assigns to @bunnyfoofoo the offending behaviour. It's the personal responsibility thing. "I'm offended" vs "You're offensive".

I think it's pretty clear than the author believes he may have offended people with his statement, and is rephrasing in a more precise manner to avoid confusion.

Re: My NAS exposes itself over the internet without permission

#75
post #44

Earlier quoted context omitted.

Edited: deleted my comment as I was unintentionally offensive.

To rephrase this somewhat less offensively (I am the author) "I realised a potential solution but decided the drawbacks of disabling uPnP were larger than the potential risk keeping uPnP enabled poses". My household makes use of many different services that would need to be port forwarded one by one in order to keep everything working, and some games just punch whatever port they like using uPnP so it's hard to keep…

I'm sorry, I didn't mean to come off as offensive. I agree that it would be bothersome to convert from uPnP to non-uPnP, but you really only need to set it up once. Then any new devices you add to your network don't require individual workarounds.

Re: My NAS exposes itself over the internet without permission

#76

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

Sure, UPnP can open ports to the outside world, but that's something that might be desired in some cases. However, devices should default to local access only, and offer an option to expose them to the world, with appropriate warning.

> However, devices should default to local access only

Unfortunately we need to act based on what is and not what should be.

Re: My NAS exposes itself over the internet without permission

#77
post #63
post #55

Earlier quoted context omitted.

I'm wondering what definition of the word "offensive" you're using.

To be very exact, being offended is a choice, in that nobody can offend you if you don't let them. You can always choose to not take offense. (The statement in question does seem rude and dismissive to me, however.)

I believe the eminent feminist and humanitarian, Elanor Roosevelt, would have agreed with the fairness of your assessment.

https://quoteinvestigator.com/2012/04/30/no-one-inferior/

Re: My NAS exposes itself over the internet without permission

#78
post #36
post #15

Earlier quoted context omitted.

Do you have a router you recommend? Ideally something running free software

Look at the range of devices from GL.inet. They run a custom version of openwrt with a nice UI on top. But most are upstreamed and you can flash vanilla openwrt on them. They re quite cheap as well. I m not affiliated with them but I have bought devices from them. I use one between the router s ISP and my home network.

This is a safe bet if you don't need advanced hardware features, I have several gl.inet devices, you can build your own OpenWRT for and turn off the phone home functionality.

Re: My NAS exposes itself over the internet without permission

#79
post #50
post #44

Earlier quoted context omitted.

To rephrase this somewhat less offensively (I am the author) "I realised a potential solution but decided the drawbacks of disabling uPnP were larger than the potential risk keeping uPnP enabled poses". My household makes use of many different services that would need to be port forwarded one by one in order to keep everything working, and some games just punch whatever port they like using uPnP so it's hard to keep…

It's not offensive. But you were offended. Big difference.

Actually, I also found grandparent's (bunnyfoofoo) tone offensive. It's borderline derogatory, since it disregards the situation of the original author in many levels, plus everyone fixates on the wrong point.

UPnP has its security implications, but it doesn't mean that random appliances can just open ports through it without any settings whatsoever.

Everybody has the freedom to have opinions and free to express them, however we shouldn't disregard other person's situation while expressing our opinion. Talking about theoretical best practices is always easy in a vacuum.

Addendum: I want to congratulate bunny for trying to learn from his/her mistakes, for being honest and sincere. I wanted to leave it here since there's no other way to contact. I also made a lot of mistakes and HN taught me how to discuss this stuff, so you're at the right place.

Re: My NAS exposes itself over the internet without permission

#80

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

On the other hand, if you want to play games on your network you absolutely must have UPNP. Unless the game has a dedicated server infrastructure. But even then you risk higher latency on VOIP if it even works at all.
Post reply on HN