Re: Security News This Week: Hackers Are Erasing Western Digital Hard Drives Remotely

nospam <[email protected]> Tue, 29 Jun 2021 11:09:49 -0400
Newsgroups alt.privacy.anon-server,alt.comp.os.windows-10,alt.comp.hardware.homebuilt,comp.os.linux.advocacy
Organization A noiseless patient Spider
Message-ID <290620211109495978%[email protected]>
In article <[email protected]>, Frank Slootweg
<[email protected]> wrote:

> > 
> >   The problem is with "My Book Live", an idiotic and unsafe
> > "personal cloud" device designed to be accessed from
> > online. So as with remote desktop, the real problem is with
> > people thinking it's safe to allow direct access to their
> > computers from the Internet. 
> 
>   It's not 'idiotic' and it's not 'unsafe', but like anything, it *can*
> be *made* unsafe in the hands of clueless people. No news at eleven.

yep, but unfortunately, there are a lot of clueless people and the
default settings are often that of convenience more than security.

>   I had a similar device, a WD (Western Digital) MyCloud NAS, and have
> a similar device, a Synology DS115j NAS. I did and do not use the
> 'personal cloud' feature, because I do not really need it and - like
> anything and everything - it has its risks.

what i do is use a vpn to connect directly into my home network. i can
then access servers or other computers, which all have username and
passwords of their own (and not the same as the vpn), so it's going to
be quite an accomplishment for someone to hack into anything. nothing
is 100% secure, but this is close enough without going wildly
overboard.

>   Also note that the reports are about people 'losing all their data'!
> How is that possible? Did they only have *one* copy of their data? If
> so, that was yet another user-caused problem. Again, no news at eleven.

yep.

the same net effect would have happened if their backup drive had
failed rather than be remotely erased, but that doesn't make for any
headlines.

>   As to "the real problem is with people thinking it's safe to allow
> direct access to their computers from the Internet", it's not about
> access to their computers, but to their data. And guess what, quite a
> lot of their - and mine and your - data has "direct access from the
> Internet" and is only protected by a username+password and perhaps 2FA.
> Think of any and all of your online accounts - including, but by no
> means limited to - email, bank(s), etc., etc.. The main difference is
> that in the latter cases, security is partly/mostly managed by the
> service provider, instead of only by the user.

yep, but unfortunately, their security is often quite poor.

at least one of experian's servers had a login of admin/admin. 

<https://www.forbes.com/sites/kateoflahertyuk/2019/10/20/equifax-lawsuit-
reveals-terrible-security-practices-at-time-of-2017-breach/>
  Brace yourself, because this isn¹t going to make pretty reading,
  especially if you¹re a cybersecurity professional. According to
  the filing in the U.S. District Court for the Northern District of
  Georgia, Atlanta Division, Equifax was protecting sensitive 
  personal information on a portal used to manage credit disputes
  with the username ³admin.² 

  And if that wasn¹t enough, the password protecting that data was
  probably the first one an attacker would guess: Yes that¹s right, it
  was also ³admin,² according to the lawsuit.

  The class action lawsuit calls this ³a sure-fire way to get hacked.²

  But that is not all. The lawsuit also points out that Equifax was
  storing unencrypted user data on a public facing server­so it could
  have been viewed by any attacker who chose to compromise it.
  Meanwhile, Equifax didn¹t encrypt its mobile applications either­and
  when it did encrypt data, it left the encryption keys on the same
  public facing servers.