Live data from Hacker News

WD My Book users wake up to find their data deleted

arstechnica.com

291–300 of 701 posts

Re: WD My Book users wake up to find their data deleted

#291

Earlier quoted context omitted.

There's really no winning with this. You can release patches 6 years after your device is EoL but there will forever be more security issues and people using your ancient product (think how long it takes some versions of Windows to truly reach less than 100k active machines. Hell I wonder if Windows 3.1 has really reached that number or not. The long tail is going to be loooong). Not to mention you've created a prece…

> There's really no winning with this. There is: don't release devices with security flaws in the first place. The fact is, they released a fatally flawed device. That the flaw was discovered later doesn't change that fact. I think the way we talk about security patches and updates obscures the fact that they're correcting fundamentally flawed software. In other circumstances, this would result in product recalls. Th…

Product recalls are for defects that can cause physical injury. If the MyBook had an electrical defect that could cause a shock hazard or start a fire, it would have been recalled.

Many products have flaws, but if the worst that can happen is that the customer feels ripped off, they don't get recalled. There might be remedies under a express or implied warranty, but tech products typically disclaim all of that in their terms of service.

Re: WD My Book users wake up to find their data deleted

#292

"The My Book Live device received its final firmware update in 2015." A unpatched in 6 years linux device directly connected to the internet? What could possibly go wrong? "There is no IoT, there is only the internet of unpatched linux boxes."

This doesn't appear to have anything directly to do with Linux, just crappy software written by WD running on it. Please be a little more careful with your criticism.

Re: WD My Book users wake up to find their data deleted

#294
post #183

There’s a difference between MyBook and MyBook Live. The Live version (this article) is ONLY accessible over the cloud service for some reason. Even if you’re on the same LAN there’s no SMB, FTP or anything else. Only the cloud connection. The MyBook is a more normal NAS. Bought one of these for my dad few years ago without noticing the difference. Cheap, hobbled and bricked itself more than once. Even without this i…

[deleted]

Re: WD My Book users wake up to find their data deleted

#295
There are a lot of comments on the situation itself, or the companies involved when these type of events happen. Speaking of evolutionary behavior as a whole, why does the industry still keep driving towards IoT / IaaS when events like these are becoming more common? Is there real risk analysis going on that determines that putting crucial operational infrastructure in the hands of a vendor is worth the consequences? I know this particular event is related to a consumer product, but consider how a lot of businesses work. Once a solid system is built, there's no reason to change it - hence the abundance of legacy systems in finance etc.

It makes me feel like these things could eventually go full-circle and companies will value owning their own datacenters. It may also make more financial sense for companies that have recently realized a lot of savings in office space leasing that they could pivot into infrastructure.

Re: WD My Book users wake up to find their data deleted

#296

Earlier quoted context omitted.

The issue at hand is a NAS firmware problem, not a HD drive issue. There are quite a few other brands offering NAS devices e.g. Synology, QNAP, Thecus, Pegasus and more.

Public-facing Synology devices got hit in the past too, but they just used it to mine Litecoin. I think someone calculated it and figured out that it cost something like $400k in electricity to mine $100k of coins on the boxes. Aha! It was $600k in dogecoin in 2014 https://www.pcworld.com/article/2364120/hacked-synology-nas-... That’s worth around $125m today (assuming straight hodling).

And of course Qnap in the recent month. It keeps repeating, and keeps happening, and some ( me ) keep ranting about it and no one / company is doing anything much with it.

Majority of people buy NAS only use it to access their Data within their internal network. But somehow they all include Internet / Cloud features as upsell.

Re: WD My Book users wake up to find their data deleted

#297

Earlier quoted context omitted.

Wow. This is the ultimate IoT failure scenario, the product is in use but no longer supported and an exploit can hit it from the Internet. I suspect there will be litigation, but I am not a lawyer. I will be interested to see it though, what is the responsibility for using things post end-of-life? What we might see is a new “your on your own” mode built into this sort of appliance that once EOL hits it asks you to af…

I think the issue here is "end of life" is defined way too soon for portable hard drives. The mechanical parts have a 4% annual failure rate, or a half-life of 12.5 years. The software should be supported for that long.

12 years?

Typical business life of a computer is 5 years. Typical service/support agreement is 1-3 years.

Try getting Apple to address a failed hard drive that's 12 years old. They'd laugh in your face.

Re: WD My Book users wake up to find their data deleted

#298

According to Western Digital[1], the CVE involved[2] has been public and unpatched since 2019. That's insane. There's "we don't support end-of-life devices" and then there's "we refuse to fix absolutely critical, crippling security vulnerabilities in devices just a few years old." This is well over the line. I smell (but have no idea of the merits of) a class action lawsuit. [1] https://www.westerndigital.com/support…

Typically when building a device like this you get a version of Linux / embedded-OS from the SoC vendor and you are stuck with it because SoC vendor doesn't provide docs that would allow drivers to be maintained. This makes ongoing support harder than it might otherwise be.

Re: WD My Book users wake up to find their data deleted

#299
post #104

Earlier quoted context omitted.

They hooked the backup to the internet. Not a good idea. Nothing connected to the internet is secure, especially since nothing comes with physical write-enable switches.

Incredibly shallow and dangerously bad hot take. I think you have a very poor understanding of what "security" is, nor the concept of backups in general which necessarily (like security) have a very strong human factors requirement. A backup which is too much of a PITA and requires nearly any level of manual effort simply isn't going to get used much or maintained well at all by the vast majority of the population. T…

Read about the recent ransomware attacks.

> if these people had been running to a decent cloud service

They thought they were.

> If that is connected it could get infected as well, now what?

That's what the physical write-enable switch is for. A hardware read-only device cannot be written to.

Re: WD My Book users wake up to find their data deleted

#300

Earlier quoted context omitted.

There's really no winning with this. You can release patches 6 years after your device is EoL but there will forever be more security issues and people using your ancient product (think how long it takes some versions of Windows to truly reach less than 100k active machines. Hell I wonder if Windows 3.1 has really reached that number or not. The long tail is going to be loooong). Not to mention you've created a prece…

> There's really no winning with this. There is: don't release devices with security flaws in the first place. The fact is, they released a fatally flawed device. That the flaw was discovered later doesn't change that fact. I think the way we talk about security patches and updates obscures the fact that they're correcting fundamentally flawed software. In other circumstances, this would result in product recalls. Th…

That's essentially impossible for this class of device, though. While this case is a bug in the on-device API, there are countless others involving previously unknown vulnerabilities in widely-trusted software components. Heartbleed comes to mind.

Hardware needs to be liberated from unsupported software, and users should be made aware of vulnerabilities and support status. Making software vendors liable for future exploits of unknown vulnerabilities opens a can of worms that would have non-neglible consequences for everyone who writes software, and not all of those would be beneficial to security.

Post reply on HN