Earlier quoted context omitted.
How many My Book customers would even understand the meaning of your [correct] advice? When companies fuck people over with a defective product, we should resist the urge to tell the victims to be more tech savvy and not use those sort of products. Particularly when those products are intended for the general public.
It's always the same old thing. But the fundamental problem will never vanish: computers are complex, and no matter how hard you try with neat packaging and software, this complexity cannot be hidden. Sooner or later the illusion bursts at its seams and the user discovers another failure mode that they weren't even aware of. WD really messed up there - but they and others will mess up again, so if the user's goal is…
WD My Book users wake up to find their data deleted
671–680 of 701 posts
Re: WD My Book users wake up to find their data deleted
#672Earlier quoted context omitted.
From conversations on this website about Apple's responsiveness/attitude to security researchers hunting bounties, I have gotten a contrary impression about Apple.
They are not perfect and not always as responsive as I’d like. They issue security updates for their current OS and 2 versions before, AFAIK.
Re: WD My Book users wake up to find their data deleted
#673As of May 15, 2021 the Seagate Access feature of Seagate NAS products will be discontinued. Specifically, the Seagate Access service, Seagate Access through Seagate Sdrive, Seagate Access through Seagate Media App, and Seagate MyNAS will no longer be available after May 15, 2021 at midnight Central European Time. Additionally, customer support for the Seagate Access service will also be discontinued. The removal of this service means that access to all Seagate NAS devices via the Seagate Access web portal, Seagate Sdrive, Seagate Media App, and Seagate MyNAS will no longer function. However, you will not lose remote access to the files on your Seagate NAS since it can be configured and accessed using the FTP/SFTP service. Similarly, your Seagate NAS will not change for standard network access within the home or office network using common network protocols on macOS and Windows. Please know that we remain grateful for your purchase of a Seagate NAS and hope you continue to enjoy it despite this change to remote access via Seagate Access, Sdrive, Seagate Media App and MyNAS. For questions, please contact https://www.seagate.com/contacts/. Cordially, The Seagate NAS Team
Re: WD My Book users wake up to find their data deleted
#674Re: WD My Book users wake up to find their data deleted
#675Earlier quoted context omitted.
Huh. This is a huge security flaw and they decided to not patch it. Winning is patching this. This is so disingenuous (from the first report of this flaw): “Western Digital takes the security of our customers’ data seriously, and we provide security updates for our products to address issues from both external reports and regular security audits.”
> Huh. This is a huge security flaw and they decided to not patch it. Winning is patching this. "Winning" isn't "gee if we could just say we'll patch every discontinued product forever and imagine it had no downsides wouldn't that be great" - that's known as "dreaming".
Having a vendor support patch releases indefinitely would not be a huge burden for Western Digital.
In this case, it was obvious errors in their PHP application.
Re: WD My Book users wake up to find their data deleted
#676Earlier quoted context omitted.
How good do you reckon a 6 years past EOL consumer linux device's defences against a browser running 3rd (or 1st) party javascript making http requests to http://192.168.0.1..254]/cgi-bin/factoryRestore.sh ? How much would you bet against that being an unauthenticated call or one with leaked hard coded reds?
Not sure this makes any sense, the 6 years past EOL consumer linux device isn't running a browser. Or are you assuming the user's browser itself is compromised and is running random javascript hitting the NAS address? That would be unfortunate, but I'm not sure I'd blame it on the "6 years past EOL consumer linux device"
Classic old cross origin request forgery. It ranks #7 I owasp’s top 10 website security flaws, and they have this to say about it:
“XSS is the second most prevalent issue in the OWASP Top 10, and is found in around two thirds of all applications.“
Re: WD My Book users wake up to find their data deleted
#677Earlier quoted context omitted.
It's also important to point out that despite using more energy because it's older hardware, it'll use considerably less energy during its all life, than it takes to produce a new computer. Replacing old hardware with "more energy-efficient" hardware is a trap from green capitalism and the numbers do not add up usually.
I find this claim a little hard to believe. Data centers routinely replace ~3 year old computers because the number of old computers they would need to keep running and cooling exceeds the cost of new more efficient hardware. The price of new hardware includes all the energy costs of producing it. Obviously the environmental externalities of energy aren't fully priced in, but that is also the case for data center ene…
Re: WD My Book users wake up to find their data deleted
#678Earlier quoted context omitted.
My point wasn't clear. 7 years is quite a long time. And as far as I know in general they can't prevent after market parts being produced. So car manufacturers are forced to allow their cars to be repaired, not necessarily with their parts, a long time after they've stopped selling them. IT stuff should start following the same lifecycle.
7 years is a relatively long time for a product, but not necessarily for a car. The average car age at scrap time is 13.9 years (UK stats). [Wildly off topic ranting about the balance of embodied versus emitted CO2 for the typical ICE vehicle omitted. Clue: 10 years is about the break-even point.]
Re: WD My Book users wake up to find their data deleted
#679Earlier quoted context omitted.
> There's really no winning with this. There is: don't release devices with security flaws in the first place. The fact is, they released a fatally flawed device. That the flaw was discovered later doesn't change that fact. I think the way we talk about security patches and updates obscures the fact that they're correcting fundamentally flawed software. In other circumstances, this would result in product recalls. Th…
Software should be more secure. However I don't think it's realistic to expect bug-free perfectly secure software. There is no field of engineering where 100% perfect tolerances are possible, and when you start getting past 99% the resource requirements to get to the next fraction of a % quickly go non-linear. This is why 1) Security patches will pretty much always be necessary and 2) relying on perfect software alon…
This is a false proposition.
All actual engineering professions I know of have processes, checks and balances to avert disasters and premature failures. No one expects all of the shingles to be perfectly straight or have the same color, occasionally a roof may have a bit of a leak, yet I think even a single 4y old roof developing a massive leak would be a big deal. Imagine the consequences if all 4-11y old red roofs from a large construction company collapsed or developed massive leaks overnight.
Neither bridges nor roofs keep standing because they are built perfectly, nor are all bugs security issues. Yet a single fatal flaw can bring a bridge down and a single off-by-one can be a root exploit.
We shouldn't expect perfect software, yet we also shouldn't need security updates (at least not often and on everything). WD SW was fatally flawed, shouldn't have been released, WD should be responsible. SW "engineers" should be ashamed to be associated with such practices. I know I am.
Re: WD My Book users wake up to find their data deleted
#680Earlier quoted context omitted.
Being able to remotely preheat my oven could be useful. But not enough to justify the risk of someone else remotely preheating my oven.
It could also be useful for anyone who worries they left the oven on.