Of course they issue a CYA about their cloud systems not being compromised, but then bury the fact that other systems were compromised by using the passive voice when they point to "threat actors". I'm assuming the My Books phone home in some way to facilitate file access over the internet. If so, that WD system got cracked. That seems more likely since-- at least for my ISP and I'm guessing most home ISPs-- don't ex…
> Anyone know if NAT configs are required to use the feature that let's you access files from anywhere? I doubt it. The specs list UPnP support. DLNA on some versions too. No consumer device is going to expect the average punter to mess with NAT.
WD My Book users wake up to find their data deleted
181–190 of 701 posts
Re: WD My Book users wake up to find their data deleted
#182Earlier quoted context omitted.
Age is of zero relevance for hard drives?
Also - age is of zero relevance to internet connected linux devices? I rely on many "8-10 year old device that hadn’t received a security update in 6+ years". My coffee machine. My fridge. My hifi. All my motorcycles. None of them run linux and are directly connected to the internet.
Re: WD My Book users wake up to find their data deleted
#183Bought one of these for my dad few years ago without noticing the difference. Cheap, hobbled and bricked itself more than once. Even without this incident, would not recommend.
Re: WD My Book users wake up to find their data deleted
#184Hopefully this flushes out the elephant in the room of the irresponsibility of manufacturers selling devices like this and then leaving the software unpatched / unupdated within a year or two of selling it. Unfortunately this needs to become regulated. Either commit to "lifetime" updates (at least 10 years) or be forced to put a massive warning on the label advising the secure period for which the product can be used…
Re: WD My Book users wake up to find their data deleted
#185Hopefully this flushes out the elephant in the room of the irresponsibility of manufacturers selling devices like this and then leaving the software unpatched / unupdated within a year or two of selling it. Unfortunately this needs to become regulated. Either commit to "lifetime" updates (at least 10 years) or be forced to put a massive warning on the label advising the secure period for which the product can be used…
That just effectively means a subscription. So your hard drive will be $100 + $10 a month.
Re: WD My Book users wake up to find their data deleted
#186Don't put all your eggs in one NAS. I alway do scheduled backups to online cold storage like Amazon Glacier.
Re: WD My Book users wake up to find their data deleted
#187Earlier quoted context omitted.
That just effectively means a subscription. So your hard drive will be $100 + $10 a month.
If I'm going to pay a subscription fee, why am I even bothering with an on-premise solution really.
Re: WD My Book users wake up to find their data deleted
#188Earlier quoted context omitted.
You forget HGST. They have a longer track record of reliable models than any other manufacturer, even taking the death star into account.
HGST was acquired by WD in 2012 and stopped being a brand altogether in 2018.
Re: WD My Book users wake up to find their data deleted
#189Earlier quoted context omitted.
By definition "directly connected to the internet" means if a device can on its on accord, direct requests to an entity, ask it a question, and act upon it is true. From what I understand these WD boxes go to a management service in the cloud. and were told they should factory reset. Whether something is pull-only (as in this case) or push (say allows HTTP or SSH access from a random on the internet) is irrelavnt if…
In defense of the parent comment, there is a meaningful difference between a device acting as the terminating IP meaning any open services are directly probe-able and a device sitting behind a firewall. For this particular attack (assuming c2 server compromise?) that might not matter, but ultimately there is a massive difference in attack surface when comparing “direct” with “NATed”
How much would you bet against that being an unauthenticated call or one with leaked hard coded reds?