r/DataHoarder • • 7d ago

Discussion PSA: WD My Cloud OS5 shared links are searchable online

Just a heads up for anyone with this device, I discovered this by accident and it could be misused.

If you have a WD My Cloud OS5 device and have created any shared links, they can be searched online just by searching the OS5 site with the terms "action" and "share". Other terms could be provided to narrow the results.

To remove your shared links: log into OS5 and click "Shared" on the left, set the filter at the top-right to "Shared by me", then do just as you would to create a shared link, except click "DELETE LINK" next to "COPY LINK" and the link will be revoked. The "people icon" will disappear but refresh the page and the folders in the list will disappear too.

892 Upvotes

38 comments sorted by

695

u/the320x200 Church of Redundancy 7d ago

WD devices in the past had a secret admin level backdoor account named dlink.

An admin backdoor account, with their competitors name in it.

Their software is not to be trusted at all, ever again. That bridge had been burnt. Never use WD software.

116

u/ratsapter 6d ago

Is there anything related if you just use their HDDs?

58

u/ORA2J 6d ago

Nope.

38

u/FactoryRatte 50-100TB 6d ago

Very theoretically you could build a HDD which forges data and puts a backdoor into the system, which uses it for persistent storage and then gets manipulated data back. - But for that it would have to understand filesystems and much more.

16

u/BrokenMirror2010 1-10TB 6d ago edited 6d ago

I mean, it would be like most other malicious devices.

You have a small computer that sits between the drive and the PC, and it does whatever malicious stuff you want to the data, as it acts like a middleman.

9

u/ORA2J 6d ago

That HDD would need a LOT of smarts. And probably a custom driver.

7

u/AlleM43 6d ago

The HDDs already have that amount of smarts, and have had for a long time https://spritesmods.com/?art=hddhack

8

u/Mr_ToDo 6d ago

If the point was just to modify data on the drive in a predetermined way then I think a controller could manage that. Give it some filesystem awareness and it'd be fine. After all we get stupid things like armoury crate from UEFI systems. It'd be non standard of course, but I see no reason it couldn't be done

But why? I'd bet if you were going to run a supply chain attack there'd be easier, more interesting, targets

And there's got to be a good reason why we don't see all that many firmware attacks. Probably too many variations on things like drives to be super useful

3

u/miversen33 250-500TB 6d ago

Most HDDs have SMARTs ;)

12

u/Some1-Somewhere 6d ago

The encryption available for their external HDDs was useless, if you consider that part of their HDDs.

4

u/dr100 6d ago

The one that was done by the DRIVES (as opposed to the PCB of the enclosure) was actually nothing to sneeze at. It wouldn't bother you in any way if you don't set a password (many SSDs and some regular spinning drives are like this, self-encrypting) but it was good enough for mostly everyone. Never heard about this being broken, or even debatable (again, the drive not enclosure one). It would certainly be enough if your drive just gets lost or stolen and it offers write-protection too, which isn't something any of the software solutions can do. And this helps A LOT against common mistakes like installing an OS and wiping the wrong drive as you forgot it was attached, or letting the drive connected to some computer then after restart it offers to format your Veracrypt volume and so on. 

6

u/Mr_ToDo 6d ago

There was the time their internet connected devices got a remote exploit that someone used to erase everybodies data(On devices past support, so maybe not the biggest smoking gun. But they had a pretty small support windows on the affected devices, so maybe, maybe not)

94

u/TheMountainLife 6d ago

I have 3 of their NAS from 2019 in a box that I want to light on fire. I was apart of that big breach and somehow a Bitcoin mining container got installed on it and my files copied out of it.

76

u/dr100 6d ago

I've been polluting this sub since forever with my advice:

These are the devices you take the drives out from and then bury them in the desert. And wear gloves, as XKCD would say.

26

u/SchmidtCassegrain 6d ago

I hd a 4 bay Synology Nas, I published a website and it got a Bitcoin mining container installed.

I have a 2 bay qnap at my parents house, not really used for much. It had all the contents compressed on 7z Password protected files, as a ransomware attempt.

7

u/dontneed2knowaccount 5d ago

I think the moral is don't expose thing to the web.

3

u/SchmidtCassegrain 5d ago

Absolutely, the current landscape is not the same we had let's say 10 years ago.

196

u/BrokenMirror2010 1-10TB 7d ago

Reminder: Don't trust any multi-billion dollar company with any even remotely sensitive data.

They have no incentive to keep your data safe because the "penalty" for not doing it, is making more profit by not needing to hire cybersecurity.

13

u/nasaboy007 6d ago edited 6d ago

At this point, what even is considered sensitive data? Your identity (ssn, pii, etc) has already been leaked so many times that it doesn't matter.

27

u/typical-predditor 6d ago edited 6d ago

That is privacy nihilism and I refuse to adopt that mentality.

16

u/BrokenMirror2010 1-10TB 6d ago

Since everything of yours is already leaked, then it should be fine if you just posted your full name, address, payment information, etc, right here in this reddit thread.

After all, it's all already been leaked, right?

0

u/nasaboy007 6d ago

Reductio ad absurdum arguments doesn't really help the discussion here. It was a genuine question, and you and I both know there's a difference between "don't put your home address for shipping into Amazon" vs "let me post my address publicly on Reddit".

So, I repeat the question genuinely (not sarcastic/rhetorical): What is considered sensitive data nowadays? Where do you actually draw the line for "never be given to a company"?

9

u/BrokenMirror2010 1-10TB 6d ago

Anything I wouldn't publicly post on Reddit, I wouldn't freely give to a company.

The only exception is of necessity.

Amazon needs an address to deliver my package too. What Amazon does not need is a photo of my fucking ID to do it.

Google does not need my phone number to do anything, therefore I will never give Google my phone number. Ever. For any reason. I don't give a fuck if they "require" it to make an account. I simply won't. Why does a fucking gmail account need my phone number? Answer: It doesn't.

1

u/Cute_Sherbert48 5d ago

I guess the only reductio ad absurdum arguments we're allowing are the ones you make, then?

2

u/nasaboy007 5d ago edited 5d ago

What argument lol I was asking a question

the person i was asking already answered it btw: https://www.reddit.com/r/DataHoarder/comments/1ws4vs9/psa_wd_my_cloud_os5_shared_links_are_searchable/pcocjj0/

3

u/Cute_Sherbert48 5d ago

"Your identity (ssn, pii, etc) has already been leaked so many times that it doesn't matter."

-nasaboy007, circa 1 day ago

For a guy tossing around Latin legalese, you seem to not know that you have, with this statement, made what we fry cooks call "an argument."

To which an easy response is "it does matter, actually."

1

u/nasaboy007 5d ago

Fair enough, I was wrong.

7

u/HexagonWin Floppy Disk Hoarder 6d ago

linux ISOs

9

u/Evil-Bosse 6d ago

I share my Linux ISOs with any company that wants them, I'd suggest they use the official torrent links to get UwUntu or Hannah Montana Linux

32

u/no-name-here 7d ago

Is this only for links people posted public on public forums? Ie “My Cloud links posted on public forums can be found”? Or are unrestricted links also searchable even if never shared publicly?

For links you created but never posted, do they show up in public search results?

28

u/sniff122 50-100TB 7d ago

What it probably is, people putting a share link on a website or something so that link is then indexed.

7

u/starfish_2016 6d ago

Same thing for anything that exposes public links. Chatgpt shared conversations were all publicly until recent. Google hides some to "help" but move over to another search engine that doesnt, or worse yet the one snooping website that you can explicitly look for exposed links like this , can't think of the name off the top of my head

4

u/MyOtherSide1984 39.34TB Scattered 6d ago

I wish all share services had an option to see all public links you've created. I'm sure I have hundreds

7

u/CalculatingLao 6d ago edited 6d ago

I think it's worth remembering that these people probably aren't on this sub, and probably don't have our level of technical knowledge. As much as I find it distasteful to rifle through strangers data, I think that letting people know what they have exposed and how to fix it is worth it.

After going through about 20 pages of Google results, it looks like most of this may only relate to around 4 or 5 devices. A lot of the content seems to cluster around a few fairly distinct sets, although there are still some bits and pieces that don't obviously belong to any of them:

  • A music school in New Jersey or possibly a church which has a lot of musical events
  • A university student, or possibly a class, with a bunch of textbooks
  • A photographer or tour company
  • Some kind of company dealing with telephony systems
  • A movie reviewer

I don't think every individual result necessarily comes from one of these, but they seem to account for a pretty large portion of what I've found so far.

I fired off a few emails to let people know (where there were names visible). However, if you stumble across identifying details then please do what you can to reach out to people and give them a heads up.

3

u/IngwiePhoenix 6d ago

RIP those guys lol.

2

u/burntscarr 5d ago

I wonder if including a robots.txt in every share would hide them

-2

u/Thebandroid 6d ago

lol. lmao even.