Hacker News new | ask | show | jobs
by scr4ve 3837 days ago
> but I'm at a loss as to why some 'hacker' would go to the effort to sift through the type of content that is typically stored on the average NAS box. Like you said, family photos, birthday videos...

It's not 'some hacker' going through your stuff, it's an automated attack scheme. Your adversary may choose to do something CryptoLocker-like or more stealthy stuff that makes your NAS part of a botnet. Neither option is good.

As others pointed out, it is highly likely that the ownCloud instance ends up publicly accessible, because that's the primary way to access files from the outside.

1 comments

Thank you. Out of curiosity, can you point me at a significant case cryptolockering of NAS data? I've read windows boxes being hit.

I have nothing on my WD MyCloud that isn't duplicated somewhere else (either it's a backup of google photos/videos, or dupe'd to a USB drive)

Again, a lock is the same as a HD failure to me. Both could happen with this setup. If the information is too valuable to fall prey to either circumstance then the system as implemented the wrong setup.

Now, a botnet is different. I assume one could not run off of the WD box and the Raspi/Owncloud base is too small to target. Unless you can point me at content that indicates otherwise?

> Out of curiosity, can you point me at a significant case cryptolockering of NAS data?

http://www.theinquirer.net/inquirer/news/2358733/synology-na...

> I have nothing on my WD MyCloud that isn't duplicated somewhere else (either it's a backup of google photos/videos, or dupe'd to a USB drive)

It sounds like it doesn't apply to your case, but a potential issue with Dropbox/ownCloud/Google Drive is that the master server can instruct all copy-holders to delete their copies. You should have off-site backups, but I suspect many people don't.

> I assume one could not run off of the WD box and the Raspi/Owncloud base is too small to target.

This is not really an issue - there are multiple router-based botnets as well. You can't really mine bitcoins, but there are tons of other stuff you can do, e.g. DDoS is usually not constrained by the processing power.