this post was submitted on 23 Nov 2023
6 points (100.0% liked)

Homelab

371 readers
9 users here now

Rules

founded 1 year ago
MODERATORS
 

...without snark or jumping down my throat. I genuinely want to know why it's so unsafe.

I'm running a Synology DS920+, with my DSM login exposed through a Cloudflare tunnel. I have 2FA enabled, Synology firewall enabled with these rules in place. I also have this IP blocklist enabled.

After all of this, how would someone be able to break in via the DSM login?

you are viewing a single comment's thread
view the rest of the comments
[–] littelgreenjeep@alien.top 1 points 1 year ago (10 children)

Kinda like the others have stated, you’re trusting the company to have fixed any known vulnerabilities, but also that there aren’t any unknown exploits.

Ultimately the question isn’t should you or not, but is the risk worth it? If your home finances are contained there in, if those impossible to recover or reproduce pictures are stored on there, then if you were to have your system locked with ransomware, how important is that data? Do you have their camera system? Would you mind the random internet looking at those cameras? That’s the real question.

If you only have some downloads you could find again and if you lose everything on the system, then you’re not risking much, so it’s kinda why not?

[–] DarkChoomba@alien.top 1 points 1 year ago (5 children)

The other risk to that is they’d possibly gain access to your internal network through your NAS. No telling what a bad actor would do.

[–] HoustonBOFH@alien.top 1 points 1 year ago (1 children)

Much more likely to gain access via a compromised desktop, or smart phone.

[–] norrisiv@alien.top 1 points 1 year ago (1 children)

The NAS runs its own OS and is just as vulnerable as a desktop or smartphones. They’re all computers.

[–] HoustonBOFH@alien.top 1 points 1 year ago (1 children)

Yes, but the other computers I listed have a person behind them that will click things. Like a "close" button that actually installs malware. A NAS does not click things.

[–] NOAM7778@alien.top 1 points 1 year ago (1 children)

True, but, what if you host VMs on the NAS? Or data for some application? Those can result in an attacker running code on them, and from there, in most homelab networks, i assume is a short way from owning everything in your network

[–] HoustonBOFH@alien.top 1 points 1 year ago

When you turn your NAS into a hosting platform, it is no longer just a NAS.

load more comments (3 replies)
load more comments (7 replies)