PSA - WD My Book Li...
 

[Closed] PSA - WD My Book Live! vulnerability

11 Posts
9 Users
0 Reactions
51 Views
 PJay
Posts: 4693
Free Member
Topic starter
 

I'm not sure if anyone on here uses Western Digital's old "My Book Live!" NAS drives (we still have one) but apparently they're vulnerable to a [url= https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo ]remote factory reset attack[/url] which wipes the data.

WD's response seems a bit half hearted as they recommend disconnecting the device from the internet and accessing it directly from a computer (loosing most of the point of a NAS drive); they're also offering data recovery tools and a trade up programme.

There's no mention of new firmware (it's a discontinued model) although they admit it's a firmware vulnerability but I'd hope that they'd be looking at this.

 
Posted : 30/06/2021 12:07 pm
Posts: 621
Free Member
 

Woah, heard the factory reset thing, but not that root privs could be gained. That is properly shite.

WD are such a bunch of ****s. We ordered some enterprise drives a while back and they were completely different to the previous batch we had. Same part number and price, but much worse performance.

 
Posted : 30/06/2021 12:42 pm
Posts: 1796
Free Member
 

they recommend disconnecting the device from the internet and accessing it directly from a computer (loosing most of the point of a NAS drive)

I believe they just recommending disabling remote access. I know you're losing some of the functionality you paid for but how often do you actually access your drive remotely? You'll still have it on your LAN which is where the vast majority of people use a NAS device.

 
Posted : 30/06/2021 12:43 pm
Posts: 6694
Full Member
 

I had one of these, bricked itself after a couple months so effectively became a dumb drive, utter rubbish, wouldn't touch their products again.

 
Posted : 30/06/2021 12:46 pm
Posts: 41510
Free Member
 

I've got the similar WD My Drive.

TBH my first thought was those hackers are probably able to access the data on it quicker and easier than I can.

It's the most hatefully frustrating, user unfriendly POS I've ever spent money on.

Supposedly all our phones back up to it, but they don't. And supposedly it's got hours of downloaded video and ripped music on it, but the TV can't access it. If someone could just hack it and wipe it then I'd have an excuse to bin it rather than spend a whole evening trying to get a computer to access it next time I want to recover some Holliday snaps.

 
Posted : 30/06/2021 12:49 pm
Posts: 1796
Free Member
 

It’s the most hatefully frustrating, user unfriendly POS I’ve ever spent money on

Desperately low transfer rate locally too, f*** knows how bad it'd be remotely, I can't remember ever trying.

 
Posted : 30/06/2021 1:14 pm
 PJay
Posts: 4693
Free Member
Topic starter
 

I believe they just recommending disabling remote access.

Actually, yes, I think you're right. I've just done that so hopefully we're covered.

I don't know what the likelihood is of a secure firmware update, we'll have to wait an see.

 
Posted : 30/06/2021 1:14 pm
Posts: 8391
Full Member
 

I had one, the Drive rather than the Live. Horrible, horrible thing. I prised the case apart, liberated the drive and repartitioned/reformatted to use in my son's desktop PC.

 
Posted : 30/06/2021 1:34 pm
Posts: 76786
Free Member
 

I mean,

Having a local drive exposed to the Internet just sounds like an astonishingly bad idea generally to me. If you need access to data on the go there's a dozen better ways of doing it in this day and age.

I saw an article on Arse back when this first broke, people crying about losing years' worth of data. The concept of backups has existed for about as long as electricity and having spent far too many hours of my life with knackered hard drives attempting data recovery for folk I now consider this a learning opportunity.

Storage is cheap. Back up your shit.

 
Posted : 30/06/2021 3:02 pm
Posts: 76786
Free Member
 

I don’t know what the likelihood is of a secure firmware update, we’ll have to wait an see.

The fact that WD are offering an upgrade replacement programme would suggest to that the likelihood is "none whatsoever." They're what, ten years old now? Must be heading that way at least.

 
Posted : 30/06/2021 3:05 pm
Posts: 6529
Full Member
 

I back up my WD to the cloud as I only really use it to hold my library for Sonos. Got fed up of the back up software as it seemed to triple the space I needed.

 
Posted : 30/06/2021 3:12 pm
Posts: 5617
Full Member
 

More importantly don't they also store the encryption key on the drive, so if there is a failure you also lose the encryption key, essentially making it all useless?

I recall this being a reason I went with a synology drive way back when, I should probably actually fire it up and backup to it again too!

 
Posted : 30/06/2021 3:15 pm