4 ms·
No need for extensive Linux experience: Use a secure password for DSM, turn off "EZ-Internet" and other DynDNS-like services, make sure it's connected to your r
by vomitcuddle 12y ago
No need for extensive Linux experience: Use a secure password for DSM, turn off "EZ-Internet" and other DynDNS-like services, make sure it's connected to your router and not directly to the Internet, don't forward any ports, don't enable DMZ or similar functionality on your router, keep up-to-date with DSM updates, make sure other computers on your network are malware-free (there could be a piece of PC malware exploiting synology devices found on the local network), keep multiple backups in different locations (online and offline) of your most valuable data.
These are just best practices, since we don't know anything about this particular piece of malware yet. They should cover most threats and worst-case scenarios.
If you need access to your Synology device from outside your home network, use a VPN or an SSH tunnel.
- chmars 12y ago> , turn off "EZ-Internet" and other DynDNS-like services, make sure > it's connected to your router and not directly to the Internet, > don't forward any ports, don't enable DMZ or similar functionality on > your router, Best practices only if you do not want to access your data outside of your local network – and that is probably no longer the standard case since data you cannot access from mobile devices etc. is pretty useless. And for compliance and security reasons, many users and companies cannot legally use cloud services and have to therefore to use a 'private cloud', i.e., some local server, for example a NAS accessible from the Internet. A manual configuration is of course recommendable but in the end, a 'private cloud' has to be exposed to the Internet and you have to trust your software vendor. The most you can usually do is to protect your LAN by putting your 'private cloud' in a DMZ (although for consumers, that is usually not an option since consumer routers do not offer a real DMZ).
- hrktb 12y agoAs a private user, the best solution I found was to go through BTSync set on a limited set of document folders. It doesn't need to forward ports or expose the login system. The BTSync server is still a vulnerability, but it's under it's own user and should give less exposure than the other services like the DSFile that check the login/password. Potential damages on a simple breach (i.e. the sharing key leaked or was guessed) should be limited to the shared folders. I hope.
- thefreeman 12y agoI don't have a device, so I cannot verify. But wouldn't an ssh tunnel achieve the goal of penetrating your NAT externally while still not exposing it to the public internet? Granted that is probably not within reach of most users without a tutorial.
- X-Istence 12y agoIt's called VPN... and yes it works on mobile devices too.
- chmars 12y agoHow can I make sure that apps accessing a NAS only use VPN connections? By default, such configuration is not available for OS X and iOS. On iOS, you can use profiles I guess but that is not a standard function.