Their workaround is 'local access', where you create an account to connect to your NAS over the local network. Where it is physically located. Which honestly raises more questions than it answers.
There's also a reference to their devices being factory reset remotely with attendant loss of data.
So overall, it would seem that western digital don't know what the hell they're doing.
factory reset incident was in 2021, certain WD NAS devices exposed to the internet had an unauthenticated endpoint and someone decided to “be a jerk” and basically hit up the entire IP space looking for these exposed NAS devices and “curl /path/to/pleaseresetanddeletealldata” to each one of them
unrelated to this year’s outage (some claim WD got ransomwared internally) but still shows poor practices in general
Comments
Their workaround is 'local access', where you create an account to connect to your NAS over the local network. Where it is physically located. Which honestly raises more questions than it answers.
There's also a reference to their devices being factory reset remotely with attendant loss of data.
So overall, it would seem that western digital don't know what the hell they're doing.
factory reset incident was in 2021, certain WD NAS devices exposed to the internet had an unauthenticated endpoint and someone decided to “be a jerk” and basically hit up the entire IP space looking for these exposed NAS devices and “curl /path/to/pleaseresetanddeletealldata” to each one of them
unrelated to this year’s outage (some claim WD got ransomwared internally) but still shows poor practices in general