WDMyCloud Multiple Vulnerabilities
gulftech.org
gulftech.org
If someone actually wanted to implant a "secret" backdoor it would be disguised as a subtle bug and/or obfuscated in some way.
"Never attribute to malice that which is adequately explained by stupidity." Hanlon's Razor - https://en.wikipedia.org/wiki/Hanlon%27s_razor
[1] "[...] it turns out the error was caused due to buggy code and nothing I was or wasn't doing wrong." - if the code is so obviously buggy and the backdoor part isn't obviously a bug, the developers are probably just being sloppy, not malicious (bad or rushed development).
"The hard-coded backdoor that was found can't be a hard-coded backdoor, because Western Digital would never be so crass and incompetent as to put a hard-coded backdoor hidden in such a way that a security researcher would find it and attribute it to them."
How can one argue against such flawless logic when it even has an aphorism to describe it?
How about creating a new aphorism?
"Never attribute to stupidity alone that which is adequately explained by both stupidity and malice."
I guess the answer is no.
It seems to me that both are adequate explanations. One explanation requires one factor (stupidity), and the other two factors (stupidity and malice). The one factor explanation would seem to be the simpler of the two explanations.
It seems to me the original statement reverses the logic of Occam's razor by preferring the more complex example. I think my point still stands. The original statement makes as much sense as trying to reverse Occam's razor.
The whole enterprise is sabotaged by the simple fact that the logical foundation behind that aphorism can be bluntly, but better, summed as:
"Choose the most adequate explanation."
In this case Hanlon's razor (and probably any where it really applies), is just Occam's razor applied to a particular type of circumstance.
"Never attribute to malice that which is adequately explained by management."
It's either the result an incompetent "secret backdoor" developer, or just plain incompetent development. Either way it's incompetent.
If it makes you feel any better, I acknowledge the spies / hackers / whatever will take advantage of it regardless of it's intent. :-)
A) WD (by a government) or its staff (by WD management) were ordered to put in the backdoor, but didn't agree with doing so, thus made it obvious in the hopes that it would be found.
B) A backdoor that is found but written off as sloppy development is less damaging than a bug that if found and analysed looks deliberate (because bad development practices are hardly new for hardware manufacturers). _Potentially_ makes exploiting it less risky as well - if it's an obvious or known thing, the attacker could be anyone. If it's a subtle, undisclosed bug (that hasn't been used against many targets), that suggests, to some extent, the involvement of whomever could arrange for the bug to be placed there.
It probably isn't deliberate, but that possibility certainly isn't excluded either, so I'd be cautious about treating this as a hard and fast rule.
Is the objection that the way I said it was too disrespectful (no offense was intended, hence the :-) )? Disagreeing with the original statement (it might have downvotes too, but maybe more upvotes are hiding that)? Too obvious? Something else?
It's not that difficult to put in something much more subtle and still have deniability if the intent was malicious.
The initial view was a hotfix that just changed the hardcoded password, because senior management felt lightning would not strike twice.
What led them to believe you wouldn’t find it again? Was it a simple password that you guessed?
The timeline on the below link only refers to one specific incident, the time discussing this in principle went for roughly 11 months, and left me extremely disillusioned with the concept of responsible disclosure.
I found some information that claimed the older MyBooks would AES encrypt the data (even if you never setup a password) making the data totally inaccessible if the factory enclosure ever broke.
Fuck that shit. I pulled the drive back in and copied everything off, then formatted the disk from a real PC and threw that shit away. Today I always buy separate disks and enclosures that allow direct disk access.
If your data is that valuable, surely you were already taking backups/snapshots of it. Right?
I
If abyobe knows a way to get the data out of it I'm interested to know.
https://github.com/themaddoctor/linux-mybook-tools/blob/mast...
I have no idea if this will work for you.
I'm sure it's more stable now than it was when I used it last, but it's frustrating when people say "no, this time it's really stable!" and then you lose data due to a bug. This same thing has never happened to me with ZFS on Linux, which is a shame because the licensing issues make it painful for me to use. I like up to date kernels.
I feel like btrfs should be phased out. It was clearly developed in a fashion that did nothing to prevent preventable bugs. This may be the same frustration that's leading RedHat to work on their own competing filesystem...
Honestly, the older I get, the more sick of IT I become, but what can we do about this?
Im in the market for a NAS right now, so this is perfect timing. I’m more willing to trust FreeNAS than MyCloud but as soon as I write that, I remember lots of Open Source is crap too.
https://www.ixsystems.com/freenas-mini/
You get FreeNas on good hardware by people who know what they are doing. I have been running this for years and I have no complaints exept that the 8 slot variant did not exists when I bought mine.
Edit: It seems they don't sell to the UK :(
It is still way better then the competition.
If RISC-V is fast enough to power a NAS and open source SATA controllers exist, I would absolutely prefer a setup involving that.
If I'm not going to get that... I'd probably prefer a setup from Synology. They'll do a good enough job, probably better than I could, even if the price is a premium.
https://www.ixsystems.com/freenas-mini/
I have won and its pretty awesome, running for years, have replaced the disks multible times by now.
Its very upgradable as well, you can put in more ram, caches and so on.
Open Hardware is pretty much a no-go at the moment, but iXSystems does support a lot of Open Source.
I would recommend this setup above any of these Synology things, when I compare my problems with my friends who have Synology, I usually come out pretty happy with my choices.
If you're trying to provide equivalent functionality, you can keep the same equivalent specs (or more likely, get a spec upgrade anyway) and deliver the same quality end result (IE, no ECC RAM) at a lower cost. You're unlikely to suffer a performance or integrity penalty compared to the equivalent off-the-shelf NAS solution.
If you want to substantially improve on the off-the-shelf NAS solution, ECC RAM is recommended, and will at that point, probably become more expensive.
Then again, if you want 10+ drives, you'll probably still be cheaper doing it yourself.
The big death blow however is the inability to grow a vdev which means you have to pay the for redundancy each time you upgrade. Which isn't cost effective, so the alternative is to buy all drives up front which robs you of taking advantage of falling prices (as you probably don't need all that space on day one but gradually increase the storage used). This forces you to pick smaller drives that are more cost effective today (compared to buying a few larger drives that will become cheaper in the future), which means that you will have to replace the drives sooner when you run out of room in your chassi (or get tired of noise / power consumption).
I love freenas, in my opinion it is the best solution for the home NAS. I use it myself, but I do consider it to be quite costly (whether it is worth it is up to you). The end results all things considering is easily more than double that of a COTS solution that you can easily grow or a more regular linux+mdadm setup. And you also need to buy more of that up front rather than spreading it out over the years.
But it does depend on what your needs are and how much data you use.
And if we want to talk optimized setups it really isn't recommended to add new vdevs to a already populated pool since the usage will be quite unbalanced and affect performance as well.
Most other mainstream filesystems have tools to restore and attempt at repair the filesystem meaning that you can often restore the data.
ZFS also utilizes the memory more which means that it is more likely to be affected by memory issues.
Is it likely? No. But since us mortals seldom have tape backups and usually can't afford to backup everything on their NAS I'd say that ECC is recommended for ZFS, more so than most other filesystems. Just as a consequence of how it is used and the lack of recovery tools, not because of the filesystem itself.
Sure, at home I have a real server with ECC RAM, running on a Solaris derivate with additional VMs... but hey...! ;-)
The hardware is still fine. You can put Debian on it!
There is a very active forum of people replacing the WD firmware with Debian on various models (EX2 Ultra, EX2100, EX4100): https://forum.doozan.com/list.php?2
But if the software is with built-in backdoor there is no reason to trust the hardware.
They also have some very odd practices, like hard-coding specific users and the shell to be used inside OpenSSH binary [2]. This was 2012; haven't checked if the code improved since then.
[1] https://wrgms.com/synologys-secret-telnet-password/
[2] https://serverfault.com/questions/458553/cant-log-in-via-ssh...
Maybe you could claim that someone is offering copyrighted material on the internet, because that's illegal per se, no downloading required, but beware of the backfire.
I can't recommend any competitors specifically since I've just been building my own, but last I looked drobo didn't look that bad.
For reference, I have a QNAP j3455 device. Remotely streams up to 4 hardware accelerated plex streams, runs lots of SSL connections, hosts all my files in a myriad of cool ways, never gets about 30% CPU load. It's amazing.
Try it here if you want: https://www.synology.com/en-us/dsm/live_demo
I use a 45drives 30 bay storinator and the thing is a tank.
Sure, demanding the sources is a necessary first step. But what happens when the manufaturer blocks and there is not enough competition in the market, see Intel and laptops?
This situation has been a problem for years now. What can be done? What regulation or law would help? What should we demand?
For hardware, we could demand that universities get paid to look at samples of hardware to find backdoors, maybe.
We could use reproducible builds too.
Either way, we shouldn't reject the only solution because it has edge cases.
That's why we needed to get rid of DMCA Section 1201, and demand access to source code, at the very least, for security research.
Lets just make open sourcre the rule and be done with it.
You all like open source and you are going to keep it. This is why you agree.
There's a big issue with quality on devices but spreading conspiracy theories only harms that cause. There's no reason to believe this is connected to a government — and it's way below the level of craft we've seen in that regard – and making dubious claims is more likely to cause people to take you and the broader argument less seriously.
> This situation has been a problem for years now. What can be done? What regulation or law would help? What should we demand?
Two good starting points would be protection for security researchers and the requirement that manufacturers promptly support devices for a reasonable amount of time. Things like this happen because there's very little perceived cost to shipping something shoddy compared with not getting as many features to market as quickly as possible.
A followup point, especially for restoring trust that there aren't sophisticated backdoors, would be not just source code but fully reproducible, user-installable builds. This is still fundamentally a losing game if you don't trust the hardware but it'd dramatically increase the odds of someone being able to notice an error, not to mention being a huge win for users’ ability to improve an orphaned device.
The reason why that's unlikely to happen is that companies treat source code as a significant asset, which is why I first mentioned a longer support period. My favorite approach for this problem would be regulation requiring mandatory release of source code, the toolchain, signing keys, etc. if the manufacturer stops supporting something, so the places which want to keep their trade secrets can still do so but are required to help their users at the same time.
Regarding the second point, I completely agree with you. First a period of binding and liable responsibility of the manufacturer for the product including software, followed by the release of full source, toolchain and necessary cryptographic material. I think this should be law, and the first period must be time-limited. Reproducible builds could ensure that backdoors in the software are at least retrospectively detected, and the company and people behind it can be hold accountable for it.
I think you could be underestimating how and to what level the IC misinformation game is played.
I'm not disagreeing with you. Just pointing out your argument isn't as lockdown air tight as believed.
I mostly concur, therefore I certainly hope you're all donating to the Software Freedom Conservancy for their GNU GPL enforcement efforts (see https://sfconservancy.org/supporter/ for more) and encouraging people to license their free software under a strongly-copylefted free software license such as the GNU GPL v3 or later, or the AGPL v3 or later. These licenses allow users to request and deserve to receive complete corresponding source code, build instructions, signing keys, and other materials needed to build the software.
We all need free software for all our computers and we need it whether a manufacturer supports something or not. It's not the public's job to look out for Western Digital's interests including their alleged trade secrets. Western Digital still supports the WDMyCloud device but apparently can't be trusted to handle the software that device runs. It would help WDMyCloud users to publish that device's entire software as free software (if they haven't already), as well as the other things you rightly mention (build instructions, signing keys, and anything else needed to get the device running) so users aren't waiting for this less trusted party to make better choices. Users ought to be free to run, inspect, modify, and share this software or get someone else they trust to do this work on their behalf.
I only run mine on private/home networks with no remote access in to them.
Curious about the version difference...
Both firmwares were released in Nov 2017, and I suspect the vulnerabilities were fixed at that time as well. At the very least nas_sharing.cgi was removed in both versions. But I haven't had a chance to finish my investigations [3].
[1] https://support.wdc.com/downloads.aspx?g=907
[2] https://support.wdc.com/downloads.aspx?g=910
[3] https://gist.github.com/bmaupin/c38c777a0e4fad737a14718b1092...
...but on the bright(?) side, I remember finding lots of software and other fun stuff on "public" D-Link NASes a few years ago, including information critical to repairing the products of one well-known and notoriously-closed company. ;-)
I suspect there are many more of these out there.
May be I have the old way of a NAS that is NOT reachable through the internet at all.
I really want a Time Capsule for all my iOS devices,, and have it only accessible within my Network. But then i am also paranoid about Bit rot on HDD. As I have seen far too many of my Photos or Video with this problem. And I dont believe any consumer grade NAS are quite capable of handling them yet.
I have yet to find a usecase where I want ALL of my files, Photos, Movies or whatever accessible when ever I am. Most of the time I only need one file form work, and it is normally in dropbox or email.
And don't buy a NAS appliance, buy an inexpensive server like a Lenovo TS150 or HP MicroServer, add a couple of RAID disks (Btrfs or ZFS preferred over hardware or software raid) and run something Linux/BSD based that you have better control over.
Btrfs and ZFS should be able to prevent bitrot. ECC memory is highly recommended.
No, in answer to your question, an iFrame on a website you visit can execute commands on your LAN accessible MyCloud.
" the D-Link DNS-320L had the same exact hard coded backdoor and same exact file upload vulnerability that was present within the WDMyCloud. So, it seems that the WDMyCloud software shares a large amount of the D-Link DNS-320L code, backdoor and all. There are also other undeniable examples such as misspelled function names and other anomalies that match up within both the WDMyCloud and the D-Link DNS-320L ShareCenter code."
I've personally seen and worked on, many times, code originally developed for one customer reused in another project for another customer. Mind you, this is totally legal the way our contracts are worded.
For all we know WD could have paid DLink to produce the whole damn thing and just stick a WD logo on them. That sort of thing is far from unheard of.
Probably won't change until the costs of these types of bugs/design flaws outweigh the costs of preventing them.
It could also be intended as a support tool to ease hard to debug solutions remotely. Not having it could make support issues more expensive and slower. Very insecure and misguided (security by obscurity is not security) if this is the case, but not malicious. Just a stupid attempt at saving money. This apparently was the case for another commenter on a different product.
While it's possible it was placed with malicious intent, there are plausible (and all too common) alternatives that explain it.
If you don't know how to determine if you have clean water (e.g. the parent comment), then either you demand proof or expect, uh, dynsentery and a bad time. You should not assume you have clean water.
https://www.nytimes.com/2017/05/04/us/flint-water-home-forec...
Vendors with names people trust should be held accountable when they fuck up like this.
Also you can't trust everything all the way down. A Pi still has proprietary video chips, every Intel and AMD board has some kind of management software, etc. etc. There is no way for one human being to be all Tony Stark and build literally everything from the ground up.
People go to the shop down the block, pick a product from the shelf and they are done with it.
This doesn't make them deserving of backdoors.
"Bought the wrong brand of car ... you had that accident coming"
"Visited the wrong doctor ... you had it coming"
"Ate food at the wrong restaurant ... had it coming"
Not everyone is going to be an expert in every field. This is not how a modern society works.
That said, for Hardware this does not yet work, and firmware is of course another problem.
Lets hope for a better future.
https://www.gnu.org/proprietary/ has a list of other kinds of malware found in proprietary software sorted by type and company or type of product. It's very informative reading and touches on issues which often come up on sites like Hacker News.
Also, ignoring the backdoor and focusing on the other exploits, fairly popular open source software has had similar exploits.
Now, for your mother, the government has the responsibility to protect the people from harms the people can't solve on their own. This happens in crime investigations, ecological regulations, car regulations and nuclear material regulation, among many other areas. In my eyes, security in IT products is clearly one of those areas. Your mother should ask the politician she voted for why they don't fulfill their responsibility.
In Germany, the highest court has stated legally binding in a decision in 2016 (red point 38 in [0]) that the state is responsible for the confidentiality and integrity of the IT equipment of the population. So far the german government chose to ignore that decision.
[0] https://www.bundesverfassungsgericht.de/SharedDocs/Entscheid...
Do you also run an open BIOS, no CPU ME, no cellphone basebands, OSS controllers in your hard drives, and control the firmware on all of your USB/PCIe peripherals?
If you actually do, you ought to realize that you're a one in hundreds of millions type individual, and that those hoops don't work for most people; even technically minded ones.
And if you don't, you're a hypocrite who should be more sympathetic to the numerous compromises that exist in reality.
I saddly can't answer all these questions with yes yet, but I'm constantly looking to improve that situation.
Still, my situation is better in that regard than what most people have. Most people are literally illiterate in the digital world. Schools are failing in this aspect. Often they ignore the digitalization or think it just means to use new media and the internet, which is the totally wrong angle to teach this transformation of our world. Google is especially evil in trying to profit from this situation by creating schooling centres where Google teaches its vision of a digital world using its tools and services.
> And if you don't, you're a hypocrite who should be more sympathetic to the numerous compromises that exist in reality.
Why am I a hypocrite for stating a simple fact? If you use propietary system, you are at the mercy of somebody else who most likely woudn't even answer your questions about it.
I'm very sympathetic to what happens to people around me and also those that are not around me. That is why I advocate for legislation and regulation to solve this problem. The state must fund free and open software and legally require open documents. Also, they must finally get their shit together and properly integrate the digital world into schools, and no, this is not done by giving every child a tablet. I want this to get better for everyone.
Still, I have little sympathy for the decision to buy for example Apple products. There are alternatives that are more open. Whoever chooses the closed system whenever an open alternative exists unnecessarily takes a risk by given a very limited set of people a lot of power over them. Don't do that, don't choose proprietary systems. Don't use Windows, don't use Apple products. It's not hard not to.
> […] Otherwise please use the original title, unless it is misleading or linkbait.
Perhaps: "WD MyCloud Multiple Vulnerabilities (including hard coded backdoor)"