7 ms·
To rephrase this somewhat less offensively (I am the author) "I realised a potential solution but decided the drawbacks of disabling uPnP were larger than the p
by kn100 6y ago
To rephrase this somewhat less offensively (I am the author) "I realised a potential solution but decided the drawbacks of disabling uPnP were larger than the potential risk keeping uPnP enabled poses". My household makes use of many different services that would need to be port forwarded one by one in order to keep everything working, and some games just punch whatever port they like using uPnP so it's hard to keep playing those with it disabled. Sysadminning at home is only fun for a short while, I do this stuff at work, I'd rather keep my home setup as simple as I can help it.
As usual, various solutions are available, I described one here. Disabling uPnP is an option for some, and I encourage those who want to go that route to go that route.
- hluska 6y agoI agree with bunnyfoofoo’s conclusion - maybe not the tone but certainly the conclusion. It’s tough to trust an article that makes security claims while ignoring so many self imposed security holes.
- edoceo 6y agoIt's not offensive. But you were offended. Big difference.
- dxdm 6y agoI'm wondering what definition of the word "offensive" you're using.
- edoceo 6y agoOffensive as Rude. Then @kn100 assigns to @bunnyfoofoo the offending behaviour. It's the personal responsibility thing. "I'm offended" vs "You're offensive".
- adamweld 6y agoI think it's pretty clear than the author believes he may have offended people with his statement, and is rephrasing in a more precise manner to avoid confusion.
- vczf 6y agoTo be very exact, being offended is a choice, in that nobody can offend you if you don't let them. You can always choose to not take offense. (The statement in question does seem rude and dismissive to me, however.)
- washadjeffmad 6y agoI believe the eminent feminist and humanitarian, Elanor Roosevelt, would have agreed with the fairness of your assessment. https://quoteinvestigator.com/2012/04/30/no-one-inferior/ https://quoteinvestigator.com/2012/04/30/no-one-inferior/
- bayindirh 6y agoActually, I also found grandparent's (bunnyfoofoo) tone offensive. It's borderline derogatory, since it disregards the situation of the original author in many levels, plus everyone fixates on the wrong point. UPnP has its security implications, but it doesn't mean that random appliances can just open ports through it without any settings whatsoever. Everybody has the freedom to have opinions and free to express them, however we shouldn't disregard other person's situation while expressing our opinion. Talking about theoretical best practices is always easy in a vacuum. Addendum: I want to congratulate bunny for trying to learn from his/her mistakes, for being honest and sincere. I wanted to leave it here since there's no other way to contact. I also made a lot of mistakes and HN taught me how to discuss this stuff, so you're at the right place.
- uberswe 6y agoI think some people miss the point of the article. That a NAS like Terramaster F2-210 shouldn't open ports externally and if they do there should be options to turn this feature off.
- washadjeffmad 6y agoIt was clear you didn't want to disable UPnP support on the entire network, but I couldn't tell whether you'd tried disabling it on the NAS. Does the following disable the FS2-210's local UPnP? Go to TOS Desktop> Control Panel> Network Services> Discovery Service> UPnP Discovery > Uncheck "Enable UPnP discovery service" https://help.terra-master.com/TOS/view/?lang/en-us/flag/discovery https://help.terra-master.com/TOS/view/?lang/en-us/flag/disc... I assume this won't break anything you don't want broken (ie- automatic port forwards), but I'm with you that the option is needlessly ambiguous.
- kn100 6y agoThis option was and is disabled - I should have mentioned this in the blog post
- bunnyfoofoo 6y agoI'm sorry, I didn't mean to come off as offensive. I agree that it would be bothersome to convert from uPnP to non-uPnP, but you really only need to set it up once. Then any new devices you add to your network don't require individual workarounds.
- kn100 6y agoIt's fine, I wasn't personally offended nor should you feel like you need to censor yourself. It's really difficult to justify turning uPnP off when you can't necessarily control every application that runs on your network. My wife is going to get rather annoyed when whatever video conferencing software she uses stops working, and I'm gonna get mad when the game I want to play doesn't work - which is why I engage in a somewhat fruitless fight with the stuff I can control to keep the uPnP port punching under control somewhat. It's definitely a bug in the nas that it continues to punch ports no matter how it is configured. Plenty of software gives you the option of not punching ports.
- rubatuga 6y agoYou keep saying "whatever" software wouldn't work without UPnP, but you are failing to give us concrete examples.
- deleted 6y ago[deleted]
- imwillofficial 6y agoYou are responding to His blog, and He shared His reasoning. Go find your own examples on your network. Even better if you can’t find anything and have UPNP disabled.
- zippergz 6y agoFWIW I have never had upnp enabled and I don't recall any cases where it's caused a problem for me. Certainly my wife and I are on videoconferences all day and they work fine. I am completely with you that I can't have network configurations that make the network unusable, confusing, or inconvenient for my family, but are you sure that upnp falls into that category? I'm sure you have different applications than I do, but I think we're pretty normal...