Re: Security News This Week: Hackers Are Erasing Western Digital Hard Drives Remotely
nospam <[email protected]> Tue, 29 Jun 2021 11:09:49 -0400
| Newsgroups | alt.privacy.anon-server,alt.comp.os.windows-10,alt.comp.hardware.homebuilt,comp.os.linux.advocacy |
|---|---|
| Organization | A noiseless patient Spider |
| Message-ID | <290620211109495978%[email protected]> |
In article <[email protected]>, Frank Slootweg <[email protected]> wrote: > > > > The problem is with "My Book Live", an idiotic and unsafe > > "personal cloud" device designed to be accessed from > > online. So as with remote desktop, the real problem is with > > people thinking it's safe to allow direct access to their > > computers from the Internet. > > It's not 'idiotic' and it's not 'unsafe', but like anything, it *can* > be *made* unsafe in the hands of clueless people. No news at eleven. yep, but unfortunately, there are a lot of clueless people and the default settings are often that of convenience more than security. > I had a similar device, a WD (Western Digital) MyCloud NAS, and have > a similar device, a Synology DS115j NAS. I did and do not use the > 'personal cloud' feature, because I do not really need it and - like > anything and everything - it has its risks. what i do is use a vpn to connect directly into my home network. i can then access servers or other computers, which all have username and passwords of their own (and not the same as the vpn), so it's going to be quite an accomplishment for someone to hack into anything. nothing is 100% secure, but this is close enough without going wildly overboard. > Also note that the reports are about people 'losing all their data'! > How is that possible? Did they only have *one* copy of their data? If > so, that was yet another user-caused problem. Again, no news at eleven. yep. the same net effect would have happened if their backup drive had failed rather than be remotely erased, but that doesn't make for any headlines. > As to "the real problem is with people thinking it's safe to allow > direct access to their computers from the Internet", it's not about > access to their computers, but to their data. And guess what, quite a > lot of their - and mine and your - data has "direct access from the > Internet" and is only protected by a username+password and perhaps 2FA. > Think of any and all of your online accounts - including, but by no > means limited to - email, bank(s), etc., etc.. The main difference is > that in the latter cases, security is partly/mostly managed by the > service provider, instead of only by the user. yep, but unfortunately, their security is often quite poor. at least one of experian's servers had a login of admin/admin. <https://www.forbes.com/sites/kateoflahertyuk/2019/10/20/equifax-lawsuit- reveals-terrible-security-practices-at-time-of-2017-breach/> Brace yourself, because this isn¹t going to make pretty reading, especially if you¹re a cybersecurity professional. According to the filing in the U.S. District Court for the Northern District of Georgia, Atlanta Division, Equifax was protecting sensitive personal information on a portal used to manage credit disputes with the username ³admin.² And if that wasn¹t enough, the password protecting that data was probably the first one an attacker would guess: Yes that¹s right, it was also ³admin,² according to the lawsuit. The class action lawsuit calls this ³a sure-fire way to get hacked.² But that is not all. The lawsuit also points out that Equifax was storing unencrypted user data on a public facing serverso it could have been viewed by any attacker who chose to compromise it. Meanwhile, Equifax didn¹t encrypt its mobile applications eitherand when it did encrypt data, it left the encryption keys on the same public facing servers.