83 ms·
Am I the only one that thinks that connecting the NAS directly to the internet is a stupid idea to begin with? Don't get me wrong, I can totally understand why
by bbernhard90 5y ago
Am I the only one that thinks that connecting the NAS directly to the internet is a stupid idea to begin with?
Don't get me wrong, I can totally understand why people (without much technical background) are tempted to do this. But with all the complexity these NAS systems nowadays have it was only a matter of time for something like this to happen.
- ziml77 5y agoI think it's insane to do. I wouldn't want to open my NAS up to the internet. I can VPN into my home network if I need to access it remotely.
- abfan1127 5y agoI can't imagine attaching anything directly to the internet outside my router.
- criddell 5y agoAnd you likely have UPnP disabled.
- criddell 5y agoI think it's a bad idea as well but I don't blame people for doing so because of how QNAP markets them. Competing products are marketed in the same way.
- karmicthreat 5y agoOther than your router you should not have ANYTHING directly on the internet these days. There is just too much surface area for device software now and cost pressure doesn't allow for security to be much of a priority.
- comboy 5y agoI'd like to hear what HN folks would most comfortably put as that router (device/software).
- sneak 5y agoI use a Unifi USG despite the anti-ubnt security hype. I also use pcengines apu2 with ubuntu focal as VPN routers.
- kalleboo 5y agoI like the Ubiquiti EdgeRouter X since it doesn't try to be as magic and cloud-enabled as the USG (yes there is UNMS but they don't push you use it like they do on the Unifi gear)
- karmicthreat 5y agoAt work I use fortigate equipment and keep it updated. At home I have sold my soul to Bezos and just use an Eero.
- White_Wolf 5y agopersonally I have something like this: ISP modem ---> Netgear (for guests) ---> pfSsense ---> My network with the VPN server for dialling in. I would of added a second pfSense for the NAS and cloud but I thought it would be an overkill.
- azdle 5y agoI use a pcengines APU2C4 (AMC x86 cpu SBC with integrated network switch) with VyOS as my external router.
- nfoz 5y agohttps://routersecurity.org/ https://routersecurity.org/ brought me to https://www.peplink.com/products/soho-series/ https://www.peplink.com/products/soho-series/ But I would love to understand my router better and why/how to trust it, or that I've configured it the best way, to protect from threats both inside and outside my LAN.
- hedora 5y agoI have this pc engines apu2 openbsd setup. Upgrading openbsd is kind of a pain, but other than that, it has been trouble free: https://github.com/elad/openbsd-apu2 https://github.com/elad/openbsd-apu2 In the last 5 years, it has crashed zero times. Once, after a power loss, fsck blocked until I pressed y over and over again.
- ClumsyPilot 5y agoNo reason to believe a random offf the shelf router is any more secure than any other device
- Hamuko 5y agoIt's probably better to only have one random possibly unsecure device connected to the Internet than a dozen random possibly unsecure devices.
- mbreese 5y agoWith the QNAP cloud service, even if the server was behind a firewall/NAT, you could still directly access the NAS from the internet. So, you could still get caught with this. Source: I have a QNAP NAS and after the first week, I couldn’t figure out who was trying to login to it as an admin account. Thankfully, I had changed all the passwords, but by default it had connected to their cloud service and was remotely accessible. I’m still not 100% sure I have it completely secured.
- tomnipotent 5y ago> you could still directly access the NAS from the internet Not unless you intentionally opened a port on the router to allow inbound access. Even default cable modems come with every port blocked by default. Even cloud-enabled services require that the machine behind the modem/router open the connection first, so unless you're getting MITM there's no externally available access.
- callmeal 5y ago>No you can't, unless someone intentionally opened a port on the router to allow inbound access. That's what I used to think. Then I found out about upnp on routers. I'd like to have a quiet talk with whoever thought that was a good idea.
- criddell 5y agoQNAP has something called QLink which I believe is a NAT traversal scheme that gets the NAS to open a link to the QNAP servers. No port forwarding is necessary.
- rickdeckard 5y agoActually, enabling the myQNAPcloud service comes with a "Auto router configuration" which makes the NAS send uPNP requests to the router for opening inbound ports. So unless uPNP is disabled on the router (which in most cases would have to be done manually at some point), you don't need to intentionally open a port for inbound access, the QNAP NAS will do it automatically...
- dvdkon 5y agoSo are you completely against self-hosting services or do you apply this only to closed (IoT) appliances?
- karmicthreat 5y agoYour service should probably be sitting behind the firewall/router/proxy. But you really should consider your options and if the service itself needs to be exposed directly to the internet.
- aborsy 5y agoThe device can be hacked even within LAN. These gadgets sometimes use UPnP and open ports on routers. A lot of ISP provided routers support UPnP.
- rce 5y agoIf you use Google or Apple photos you are connecting to their computers that are exposed directly to the internet, but I would much rather own my data rather than have these corporations own it. The question in my mind is why these NAS companies are so comparatively terrible at writing secure software.
- fulafel 5y agoAssuming you aren't talking about completely air gapped parallel IT infra: The alternative comes with different administration burdens after which you've built an insecure internal network that is still indirectly internet connected and can be breached. If it's not that in the beginning, it will become one, due to human factors.
- Hamuko 5y agoNope. My Synology is only reachable via a VPN. Even connecting to the Plex server on it requires a VPN.
- ksec 5y agoYes, I made the suggestions to both QNAP and Synology for having an simple single option to disable ALL Cloud function and Internet connection. I want an Intranet NAS. Not an Internet NAS. But they seems to think they dont add value without the Internet stuff. I dont use any of the Internet stuff. I only want my files to be shared within the network in my home. And doing it myself require so much tinkering.