Re: Security News This Week: Hackers Are Erasing Western Digital Hard Drives Remotely
Frank Slootweg <[email protected]> 29 Jun 2021 13:57:00 GMT
| Newsgroups | alt.privacy.anon-server,alt.comp.os.windows-10,alt.comp.hardware.homebuilt,comp.os.linux.advocacy |
|---|---|
| Organization | NOYB |
| Message-ID | <[email protected]> |
Mayayana <[email protected]> wrote: [...] > It turns out the story is not what it seems: > > https://hardware.slashdot.org/story/21/06/27/008211/western-digital-blames-remotely-installed-trojans-for-wiping-my-book-storage-devices > > The problem is with "My Book Live", an idiotic and unsafe > "personal cloud" device designed to be accessed from > online. So as with remote desktop, the real problem is with > people thinking it's safe to allow direct access to their > computers from the Internet. It's not 'idiotic' and it's not 'unsafe', but like anything, it *can* be *made* unsafe in the hands of clueless people. No news at eleven. I had a similar device, a WD (Western Digital) MyCloud NAS, and have a similar device, a Synology DS115j NAS. I did and do not use the 'personal cloud' feature, because I do not really need it and - like anything and everything - it has its risks. Also note that the reports are about people 'losing all their data'! How is that possible? Did they only have *one* copy of their data? If so, that was yet another user-caused problem. Again, no news at eleven. As to "the real problem is with people thinking it's safe to allow direct access to their computers from the Internet", it's not about access to their computers, but to their data. And guess what, quite a lot of their - and mine and your - data has "direct access from the Internet" and is only protected by a username+password and perhaps 2FA. Think of any and all of your online accounts - including, but by no means limited to - email, bank(s), etc., etc.. The main difference is that in the latter cases, security is partly/mostly managed by the service provider, instead of only by the user.