Re: Security News This Week: Hackers Are Erasing Western Digital Hard Drives Remotely

nospam <[email protected]> Wed, 30 Jun 2021 11:43:44 -0400
Newsgroups alt.privacy.anon-server,alt.comp.os.windows-10,alt.comp.hardware.homebuilt,comp.os.linux.advocacy
Organization A noiseless patient Spider
Message-ID <300620211143447016%[email protected]>
In article <[email protected]>, Mayayana
<[email protected]> wrote:

> | >   There are some things that can't be made entirely safe. One
> | > is javascript in browsers. Another is setting up your system
> | > for remote access. There are reeasons to risk both. There's
> | > no sensible reason to risk it in order to have a "private cloud".
> | > Thus, idiotic.
> |
> |  I think you don't quite know what a "personal cloud" is and is not.
> |
> |  You seem to say that "There are reasons to risk" "setting up your
> | system for remote access". If so, guess what? The "personal cloud" is
> | also a system which you set up for remote access. It's just not - at
> | least not mainly - a *computational* system, big deal. The "personal
> | cloud" is just a way to access one's files from the Internet, just like
> | "setting up your system for remote access" is, no more, no less.
> 
>   Yes. That's the point. If you set it up to be accessible from online
> then you've set it up to be hacked from online. That's why so many
> attacks in the past have exploited remote desktop, RPC, etc. Once
> you're able to reach your own computer remotely, or allow others to
> by allowing your tech support to work on your desktop, for example,
> then you've made the mistake of applying intranet security protocols
> to the Internet and you're a sitting duck.
> 
>   That's also why there are so
> many problems with hacked security cameras, thermostats, door
> locks, etc. We're creating the IoT without having learned this basic
> lesson in security -- that if you want a door opening to the Internet
> you need to keep it locked. Why do these problems keep happening?
> Because security is a hassle. You want to be able to get your files
> in the easiest possible way. So we pretend the real problem was a bug
> that needed a fix. Or bad config. But there's no end of such problems.
> That's why credit card and corporate database hacks are constant.
> That's why the Russians can turn off the US electric grid. The real
> problem is that you're allowing people from outside to come in the
> front door. The real problem is that these systems shouldn't be online
> in the first place.

no, the real problem is that security is an afterthought.

experian had a login of admin/admin on a public-facing server on the
internet. that's just begging to be hacked.