3 ms·
> "It's a worrying meme that you shouldn't even expect your internet-connectible devices to survive the internet, and when they break its your fault." This has
by roc 12y ago
> "It's a worrying meme that you shouldn't even expect your internet-connectible devices to survive the internet, and when they break its your fault."
This has been the go-to techie reaction to security problems since the time of dial-up modems. It's a bad attitude [1], but it's not a "meme". It's the only successful strategy an entire generation of technologically-minded people have found and preached in response to a generation's-worth of terrible software security, slow/absent/can't-be-arsed software providers and under-educated users.
Should things be different? Sure. Attitudes should be better and the software should be better. But so long as the latter isn't reflected in reality, there isn't much hope for the former.
[1] It's a bad attitude because blaming the user puts them on the defensive and reduces the chance of any progress being made.
- Alupis 12y agoYou can't have your cake and eat it too. If you want to buy an off-the-shelf "home appliance" you will get just that -- a product where you cannot update firmware/software, reconfigure security and firewall settings, etc. Maybe it's secure the day you buy it -- but in 5 years? With no updates? No way. If you buy something more enterprise grade -- or, the best option, roll your own with some of the very good options like FreeNAS or OwnCloud, then you will be able to keep it secure and up-to-date. But this takes more effort - and is likely the reason the OP did not opt for one of these very fine options. > "It's a worrying meme that you shouldn't even expect your internet-connectible devices to survive the internet, and when they break its your fault." That's not true -- you have an ethernet/network capable device; not an internet capable device -- nowhere on the box does it say "Plug this directly into the open public network in front of your firewall or inside a DMZ. You need to be responsible with your devices. Just because it can serve a web page does not mean it should be accessible over the internet! This is true even with enterprise grade gear. Saying you want to not worry about security at all but still want to put devices on the public internet that need protection is like saying you want to have a car but don't want to ever change it's oil. Sure, you as an individual can avoid changing oil -- hire a technician. Same goes with your home network. So no, it's not a bad attitude -- it's irresponsible and/or ignorant home users.
- kstrauser 12y ago> That's not true -- you have an ethernet/network capable device; not an internet capable device -- nowhere on the box does it say "Plug this directly into the open public network in front of your firewall or inside a DMZ. It pretty much does exactly that. It's marketed and designed for you to open ports directly to it for its various first-party packages, like PhotoStation, CloudStation, WebDAV, etc. I think it's reasonable to expect that those packages, which are major selling points for this system, should be reasonable capable of working on the public Internet.
- me1010 12y ago> like PhotoStation, CloudStation, WebDAV, There are secure ways to run things and insecure ways to run things. It's very possible to setup a postfix or exim smtp server as an insecure open relay running on port 25. It's also possible to have either running securely on port 25... And an open port is meaningless by itself. It's the security options applied by the system and application running a service on the port that matter. The examples you give are just applications that run over http or https... https requires an SSL cert from a trusted CA, and http is a very bad idea for anything that you log into, or that has free access to your home network from the Internet. I imagine most users skip this step... http://docs.qnap.com/nas/4.0/en/security.htm?zoom_highlightsub=ssl%2Bcertificate http://docs.qnap.com/nas/4.0/en/security.htm?zoom_highlights... Note, the SSL certificate instructions... You can upload a secure certificate issued by a trusted provider. After uploading a secure certificate, users can connect to the administration interface of the NAS by SSL connection and there will not be any alert or error message. ... The error message referred to here is the web browser message indicating that the SSL certificate doesn't match a trusted CA, and therefore your "secure" NAS connection might be Man-In-The-Middle attacked... And if you don't upload an SSL cert - and connect via http externally - it means that the most amateur of "bad guys" already has your 30 character username and your 45 digit/character/special character password...
- kstrauser 12y agoYou're right, but I'm not sure that we're saying different things. (FWIW, I actually bought an SSL cert just for my Synology DS412+.) We don't have enough information to even guess at what the root problem might be, but I contend that this particular piece of hardware is designed for and meant to live on the open Internet. Yes, that's a very scare place. But it's not unreasonable to think that an up-to-date Unix server should be capable of the job, especially when it's vendor explicitly sales it on the basis that it is. I'm strongly hoping that the vulnerability turns out to be something already patched in a software update and not a 0-day. That would go a long way toward making me feel better about the situation.