Live data from Hacker News

WD My Book users wake up to find their data deleted

arstechnica.com

491–500 of 701 posts

Re: WD My Book users wake up to find their data deleted

#491

Read this, then checked my old My Book Live. Sure enough... everything's gone. I just used it for continuous laptop backups over my LAN, so unless one of them crashes tonight, I should be good. But, this will certainly give me pause when considering WD products, and this type of product in particular. This is very bad, WD! Are your other products also vulnerable in this way? Why should anyone ever again trust your co…

>But, this will certainly give me pause when considering WD products

I'd hope it gives you some pause when considering "cloud" products as well, that was the reason I avoided this.

Re: WD My Book users wake up to find their data deleted

#492
post #437

Earlier quoted context omitted.

I agree, but it also makes me consider what the role of software engineering (as a discipline) is in this disaster. Shouldn't we design systems that are hard to break by default ? Shouldn't the OS assume that terrible things are going to happen anyway, and provide protection from bad faith actors in case the OS is indeed left unpatched for 10 years while being fully exposed to the internet? Is it even possible to des…

You're correct that this would be very nice to have. However this is a problem the industry has been struggling with for decades. It's simply not easy (and maybe not even possible) to achieve what you claimed "should" happen. Nobody knows how to produce bug-free software at scale.

I know. I'm just pondering if it's possible to come up with a design that guarantees a secure system even if you assume that all of your protective layers will have security holes in them that you will not be able to patch. Does or can such an architecture exist?

Re: WD My Book users wake up to find their data deleted

#493

"The My Book Live device received its final firmware update in 2015." A unpatched in 6 years linux device directly connected to the internet? What could possibly go wrong? "There is no IoT, there is only the internet of unpatched linux boxes."

This doesn't appear to have anything directly to do with Linux, just crappy software written by WD running on it. Please be a little more careful with your criticism.

Even OpenSSH needs the occasional patch [1]. Users need to be able to supply OSes for their IoT devices or they will eventually become insecure.

[1] https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=OpenSSH

Re: WD My Book users wake up to find their data deleted

#494

According to Western Digital[1], the CVE involved[2] has been public and unpatched since 2019. That's insane. There's "we don't support end-of-life devices" and then there's "we refuse to fix absolutely critical, crippling security vulnerabilities in devices just a few years old." This is well over the line. I smell (but have no idea of the merits of) a class action lawsuit. [1] https://www.westerndigital.com/support…

EOL should be made to legally mean: opensource or something equivalent. If Windows isn't supported on my laptop, I can nearly always replace it with Linux and still keep it alive. With stuff like this, they can decide to never update it again or just turn off some critical service and render a device unusable. It's not just a thing about owning what you purchase and having the freedom to do what you want with it, it'…

This is an interesting point: there is an analogy to be made with unmaintained equipment that can become environmental hazards and making such equipment without proper warnings and recalls.

I was thinking of getting one for myself, but I think I'll stick to USB-connected JBODs.

Re: WD My Book users wake up to find their data deleted

#495

"The My Book Live device received its final firmware update in 2015." A unpatched in 6 years linux device directly connected to the internet? What could possibly go wrong? "There is no IoT, there is only the internet of unpatched linux boxes."

This doesn't appear to have anything directly to do with Linux, just crappy software written by WD running on it. Please be a little more careful with your criticism.

I read it as "Linux had free updates for 6 years and the manufacturer was negligent to apply them".

Re: WD My Book users wake up to find their data deleted

#496
post #446
post #312

Earlier quoted context omitted.

When a car manufacturer sells a car, in many parts of the world they're supposed to still offer parts for it for 7 years after they stop selling it, by law.

That's not exactly great, tbh. A car can easily run for 10y (mine is due for a replacement at 19yo), so 7y seems ecologically unnecessarily wasteful. I get that it doesn't make sense to offer parts for 20yo cars, but if we want to live in a sustainable future, people need to stop replacing cars after 5y or so.

> I get that it doesn't make sense to offer parts for 20yo cars

Why not? Personally i believe a hardware manufacturer should be bound by law to sell parts for any vehicle it sold in the past, as long as it exists. Yes even if it was produced 40 years ago. There's no reason for it to be otherwise.

If this was mandated by law all the tiny incompatibilities that they introduce with very varied models will suddenly go away because they'll be careful to make products that can actually be maintained and repaired decades from now with spare parts compatible with different models.

Some people use cars who are more than 50 years old and they're just fine. Same goes for washing machines, drills, bikes... We have to stop this capitalist nonsense that keeps on producing single-use items that end up in the trash in the coming months. IT'S INSANE!

Re: WD My Book users wake up to find their data deleted

#497
post #408
post #312

Earlier quoted context omitted.

When a car manufacturer sells a car, in many parts of the world they're supposed to still offer parts for it for 7 years after they stop selling it, by law.

But consumer electronics are written off on much shorter timeframes than cars. Are we going to require support for electronics for 7 years? I would be in favor of it, but I don't see it happen. Device was EoL in 2015, the vuln is from 2019, breach 2021. Even if we take the vuln date, that's 4 years after EoL. The question then becomes: is it reasonable to say that electronics are expected to have a life half of that…

Squeezebox touch still going strong here. Maybe I'm an outlier, but things shouldn't be disposable after a couple of years.

Re: WD My Book users wake up to find their data deleted

#498

Earlier quoted context omitted.

By definition "directly connected to the internet" means if a device can on its on accord, direct requests to an entity, ask it a question, and act upon it is true. From what I understand these WD boxes go to a management service in the cloud. and were told they should factory reset. Whether something is pull-only (as in this case) or push (say allows HTTP or SSH access from a random on the internet) is irrelavnt if…

In defense of the parent comment, there is a meaningful difference between a device acting as the terminating IP meaning any open services are directly probe-able and a device sitting behind a firewall. For this particular attack (assuming c2 server compromise?) that might not matter, but ultimately there is a massive difference in attack surface when comparing “direct” with “NATed”

Yeah difference in threat model of “evil internet can make tcp connection to me” vs “basically need a c2 compromise” is huge. Sucks for those that lost data either way.

Re: WD My Book users wake up to find their data deleted

#499
post #428
post #408

Earlier quoted context omitted.

But consumer electronics are written off on much shorter timeframes than cars. Are we going to require support for electronics for 7 years? I would be in favor of it, but I don't see it happen. Device was EoL in 2015, the vuln is from 2019, breach 2021. Even if we take the vuln date, that's 4 years after EoL. The question then becomes: is it reasonable to say that electronics are expected to have a life half of that…

I'd argue that this is serious enough that EOL doesn't apply. Yeah sure EOL for updates, features, minor issues etc. But this is literally "Anyone in the world can remotely make your product unusable and destroy everything on it while you use it as intended" I don't care if a car manifacturer EOL'ed a car model, if an issue gets discovered that will make the engine explode at random they better do recall.

For reference - my 13 yr old BMW just got a recall repair due to a potential problem with the air conditioning system.

Re: WD My Book users wake up to find their data deleted

#500
post #408

Earlier quoted context omitted.

But consumer electronics are written off on much shorter timeframes than cars. Are we going to require support for electronics for 7 years? I would be in favor of it, but I don't see it happen. Device was EoL in 2015, the vuln is from 2019, breach 2021. Even if we take the vuln date, that's 4 years after EoL. The question then becomes: is it reasonable to say that electronics are expected to have a life half of that…

> But consumer electronics are written off on much shorter timeframes than cars. They are, but it kills the planet. We have 12 year old PCs in the family. Well, back then they were high-end models bought for work. Now they are running Linux just fine for general family purpose. They use a bit more of energy than a new model, but where we live you have to heat buildings at least 8 months a year anyway. I am sure produ…

It's also important to point out that despite using more energy because it's older hardware, it'll use considerably less energy during its all life, than it takes to produce a new computer.

Replacing old hardware with "more energy-efficient" hardware is a trap from green capitalism and the numbers do not add up usually.

Post reply on HN