You are far better off getting cheap hardware and running TrueNAS or Unraid on it as they actually get regular software updates and don't have a history of major security issues.
You are far better off getting cheap hardware and running TrueNAS or Unraid on it as they actually get regular software updates and don't have a history of major security issues.
The PHP scripts certainly are a horrible mess, in all ways. For example, shell injection prevention is based on using escapeshellarg at each call site... that pattern is _exactly_ the structural root cause for vulnerabilities like the one D-Link had.
In no particular order, and obviously not exhaustive: Everything runs directly as root - nginx, php-fpm, smb, ... No AppArmor/SELinux. There is no Secure Boot support (especially unfortunate since boot is from USB stick). No HTTPS access to web frontend by default. SMB protocol defaults are insecure. SMB shares default to public. SSH allows password-based root login. Pools are unencrypted at rest by default. They have a checkbox to enable telnet for management! Very permissive iptables rules. Almost any features that real competitors like Synology would officially provide come from third parties via a moderately shady app store.
Note it's not about any of these individual points. I see above as signal that they are not security experts and see security as an afterthought, rather than as something that deserves a team of experts that specifically cares about it.
(There's certainly other fields they also aren't experts in, like UX - their predominant UI pattern is "list of dropdown fields". Even in storage, one could have a longer discussion how their Array feature - the true core of their product -, compares to modern solutions. There's a reason they've evolved cache pools to just pools as a separate thing, and some users do pool-only Unraid...)
That's all quite understandable since it's a small team with only 2-3 coders (https://unraid.net/about). But nevertheless.
For the record: you need root on Linux to open ports below 1000. By necessity, these programs need at least one thread that runs as root just from that.
Can't comment on the rest. As I never used it. Fedora server + cockpit UI was enough for me when I switched from my Synology NAS the other day
There are options on pretty much any system, but certainly on Linux with capabilities. None of these require direct support from the application (dropping root after binding does).
You almost never need to run anything as root, especially not with these "run 6 different types of services in a box" type of appliances.
None of this is new; this was already widely considered best practice when I was starting out 25 years ago.
If you're using systemd, you can grant the appropriate capability to the process by setting:
[Service]
AmbientCapabilities=CAP_NET_BIND_SERVICE
in its service file. Note that this will necessarily allow the process to listen to any port; there is, unfortunately, currently no way to lock it down to a single port.(Of course Unraid, being based on Slackware, has a legacy init system that doesn't support this scheme. But there are enough other options.)
Never had issues with Synology.
- Don't get a cloud router (ever!)
- learn about vlans and use them.
- never hook a critical device like a NAS to the wider internet
s/NAS/network/
Unpopular opinion: really you'd be "far better off" using Dropbox or Drive or whatever. By demanding to store your junk yourself you've already walked away from the clearly most robust solution.
Obviously this will engender the standard HN freakout about privacy and Big Tech and whatever, and I won't engage. But at the narrow level of robustness and security, the cloud experts are going to do this objectively better than anything under your personal control, probably by more than an order of magnitude.
There are multiple different tiers of data that I keep: on device, encrypted snapshots, cloud, and NAS. There is differing amounts of money and effort I'm willing to spend depending on the type of data, but no one solutions is sufficient for everything.
[1] I do chuckle at the use of "just 10tb". Obviously the real issue here is that these NAS boxes are deployed in service of movie and porn collections that people don't want to leave with a third party. But my point was about reliability and security, not legality or propriety.
> I do chuckle at the use of "just 10tb"
It's 2024. 2TB SSDs can be bought cheaply, and so can 16TB HDDs.
I think bandwidth is a bigger issue with cloud storage. Most people have terrible upload bandwidth.
Also, it’s not a good idea to store TBs of personal information on someone else’s computer or potentially the internet.
Inb4 the old "dropbox/ftp HN suggestion" meme. I'm not recommending my setup for common users, or even for you. It suits my needs and that's all that I really care about.