Live data from Hacker News

My NAS exposes itself over the internet without permission

kn100.me

151–160 of 311 posts

Re: My NAS exposes itself over the internet without permission

#151

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

So I don't know about routers or networks. I live in a an apartment. Which router (+ a extra point / 2 hub mesh) is recommended these days. There seems to be a plethora of options. But most of always end with ubiquity, which today feels like a bad choice. Also kind of expensive. Preferable something Completely local. No cloud service. Preferable opens source.

I live in EU.

(Sorry if it's bad form to ask for product recommendations, but I am unhappy with/ don't trust, my isp provided router, and gp explicitly mentions buying a router)

Re: My NAS exposes itself over the internet without permission

#152

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

So I don't know about routers or networks. I live in a an apartment. Which router (+ a extra point / 2 hub mesh) is recommended these days. There seems to be a plethora of options. But most of always end with ubiquity, which today feels like a bad choice. Also kind of expensive. Preferable something Completely local. No cloud service. Preferable opens source. I live in EU. (Sorry if it's bad form to ask for product r…

Mikrotik

Re: My NAS exposes itself over the internet without permission

#153

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

So I don't know about routers or networks. I live in a an apartment. Which router (+ a extra point / 2 hub mesh) is recommended these days. There seems to be a plethora of options. But most of always end with ubiquity, which today feels like a bad choice. Also kind of expensive. Preferable something Completely local. No cloud service. Preferable opens source. I live in EU. (Sorry if it's bad form to ask for product r…

Can you get rid of your ISP provided router? There are lots of obstacles there.

Re: My NAS exposes itself over the internet without permission

#154
post #147

Earlier quoted context omitted.

IMHO IPv6 is an ISP problem, I don't need every (any, really) of my devices accessible from outside my personal VPN, and IPV4 private space is more than sufficient for that. IPv6 is overly complex, therefore insecure. Thanks to the US Patriot Act I dont even trust the VPN stuff tbh.

> IPv6 is overly complex I'm being a bit pedantic about this since you're right that in practice, setting up stuff for IPv6 is in-fact complex since support for it is all over the place. But I want to stress that IPv6 as a protocol is much simpler, more intuitive and much more versatile than IPv4. I'd even go so far as to say that it's actually fantastically suited for local networks, especially so in complicated set…

The basics of the client side are simple.

But the routing is not simple.

I'm pretty well versed in networking generally - even IPv6, but a quick glance over something like: http://ipv6now.com.au/primers/IPv6RoutingSecurity.php

Makes it obvious why it still hasn't gotten anywhere, _no one_ wants to dig through all that unless they really really have to.

Security depends on securing the routing and address allocation. So it is hardly surprising very few were/are willing to step up a declare IPv6 installations safe for service.

Combine that with most users being happy and comfortable with 1 IP address and there was no mass market appeal for IPv6 hardware or software.

I'd go so far as saying the vast majority of people do not even realise their machines can be accessed from the outside world when they only have one public address behind their "firewalled super safe ISP router", and would be terrified to find out they can.

Re: My NAS exposes itself over the internet without permission

#155

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

So I don't know about routers or networks. I live in a an apartment. Which router (+ a extra point / 2 hub mesh) is recommended these days. There seems to be a plethora of options. But most of always end with ubiquity, which today feels like a bad choice. Also kind of expensive. Preferable something Completely local. No cloud service. Preferable opens source. I live in EU. (Sorry if it's bad form to ask for product r…

I've replied to a couple of others, normally I would have recommended Ubiquiti, but I no longer do. Not just because of their recent breach debackle, but because their software quality has declined since some of their best developers left.

The short but not so useful answer is, run something with pfSense or similar, I hear PCEngines hardware works well and is open source from the bootloader up.

Ubiquiti has hardware offloading using Cavium hardware so you need to get some throughout tests if you need high bandwidth in hardware without the offloading hardware.

Re: My NAS exposes itself over the internet without permission

#157
post #39

Earlier quoted context omitted.

UPNP is pretty important for a lot of online games.

Which ones? I have it turned off and haven't had any issues with games.

Ubisoft games come to mind. Without UPnP or specific ports forwarded you’ll have limited NAT support which many games will tell you.

Re: My NAS exposes itself over the internet without permission

#158

> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy…

That sounds like he didn't even try.

Re: My NAS exposes itself over the internet without permission

#159

Earlier quoted context omitted.

So I don't know about routers or networks. I live in a an apartment. Which router (+ a extra point / 2 hub mesh) is recommended these days. There seems to be a plethora of options. But most of always end with ubiquity, which today feels like a bad choice. Also kind of expensive. Preferable something Completely local. No cloud service. Preferable opens source. I live in EU. (Sorry if it's bad form to ask for product r…

I've replied to a couple of others, normally I would have recommended Ubiquiti, but I no longer do. Not just because of their recent breach debackle, but because their software quality has declined since some of their best developers left. The short but not so useful answer is, run something with pfSense or similar, I hear PCEngines hardware works well and is open source from the bootloader up. Ubiquiti has hardware…

Pfsense isn’t a replacement for ubiquity if you want a single plane for firewall switch’s and aps - I don’t know if any reasonable one sadly

Re: My NAS exposes itself over the internet without permission

#160

Earlier quoted context omitted.

So I don't know about routers or networks. I live in a an apartment. Which router (+ a extra point / 2 hub mesh) is recommended these days. There seems to be a plethora of options. But most of always end with ubiquity, which today feels like a bad choice. Also kind of expensive. Preferable something Completely local. No cloud service. Preferable opens source. I live in EU. (Sorry if it's bad form to ask for product r…

Mikrotik

The ux is... not good and I wouldn’t recommend it for anyone not experienced
Post reply on HN