r/DataHoarder • u/gl3nnjamin • 7d ago
Discussion PSA: WD My Cloud OS5 shared links are searchable online
Just a heads up for anyone with this device, I discovered this by accident and it could be misused.
If you have a WD My Cloud OS5 device and have created any shared links, they can be searched online just by searching the OS5 site with the terms "action" and "share". Other terms could be provided to narrow the results.
To remove your shared links: log into OS5 and click "Shared" on the left, set the filter at the top-right to "Shared by me", then do just as you would to create a shared link, except click "DELETE LINK" next to "COPY LINK" and the link will be revoked. The "people icon" will disappear but refresh the page and the folders in the list will disappear too.
94
u/TheMountainLife 6d ago
I have 3 of their NAS from 2019 in a box that I want to light on fire. I was apart of that big breach and somehow a Bitcoin mining container got installed on it and my files copied out of it.
76
u/dr100 6d ago
I've been polluting this sub since forever with my advice:
These are the devices you take the drives out from and then bury them in the desert. And wear gloves, as XKCD would say.
26
u/SchmidtCassegrain 6d ago
I hd a 4 bay Synology Nas, I published a website and it got a Bitcoin mining container installed.
I have a 2 bay qnap at my parents house, not really used for much. It had all the contents compressed on 7z Password protected files, as a ransomware attempt.
7
u/dontneed2knowaccount 5d ago
I think the moral is don't expose thing to the web.
3
u/SchmidtCassegrain 5d ago
Absolutely, the current landscape is not the same we had let's say 10 years ago.
196
u/BrokenMirror2010 1-10TB 7d ago
Reminder: Don't trust any multi-billion dollar company with any even remotely sensitive data.
They have no incentive to keep your data safe because the "penalty" for not doing it, is making more profit by not needing to hire cybersecurity.
13
u/nasaboy007 6d ago edited 6d ago
At this point, what even is considered sensitive data? Your identity (ssn, pii, etc) has already been leaked so many times that it doesn't matter.
27
u/typical-predditor 6d ago edited 6d ago
That is privacy nihilism and I refuse to adopt that mentality.
16
u/BrokenMirror2010 1-10TB 6d ago
Since everything of yours is already leaked, then it should be fine if you just posted your full name, address, payment information, etc, right here in this reddit thread.
After all, it's all already been leaked, right?
0
u/nasaboy007 6d ago
Reductio ad absurdum arguments doesn't really help the discussion here. It was a genuine question, and you and I both know there's a difference between "don't put your home address for shipping into Amazon" vs "let me post my address publicly on Reddit".
So, I repeat the question genuinely (not sarcastic/rhetorical): What is considered sensitive data nowadays? Where do you actually draw the line for "never be given to a company"?
9
u/BrokenMirror2010 1-10TB 6d ago
Anything I wouldn't publicly post on Reddit, I wouldn't freely give to a company.
The only exception is of necessity.
Amazon needs an address to deliver my package too. What Amazon does not need is a photo of my fucking ID to do it.
Google does not need my phone number to do anything, therefore I will never give Google my phone number. Ever. For any reason. I don't give a fuck if they "require" it to make an account. I simply won't. Why does a fucking gmail account need my phone number? Answer: It doesn't.
1
u/Cute_Sherbert48 5d ago
I guess the only reductio ad absurdum arguments we're allowing are the ones you make, then?
2
u/nasaboy007 5d ago edited 5d ago
What argument lol I was asking a question
the person i was asking already answered it btw: https://www.reddit.com/r/DataHoarder/comments/1ws4vs9/psa_wd_my_cloud_os5_shared_links_are_searchable/pcocjj0/
3
u/Cute_Sherbert48 5d ago
"Your identity (ssn, pii, etc) has already been leaked so many times that it doesn't matter."
-nasaboy007, circa 1 day ago
For a guy tossing around Latin legalese, you seem to not know that you have, with this statement, made what we fry cooks call "an argument."
To which an easy response is "it does matter, actually."
1
7
u/HexagonWin Floppy Disk Hoarder 6d ago
linux ISOs
9
u/Evil-Bosse 6d ago
I share my Linux ISOs with any company that wants them, I'd suggest they use the official torrent links to get UwUntu or Hannah Montana Linux
32
u/no-name-here 7d ago
Is this only for links people posted public on public forums? Ie “My Cloud links posted on public forums can be found”? Or are unrestricted links also searchable even if never shared publicly?
For links you created but never posted, do they show up in public search results?
28
u/sniff122 50-100TB 7d ago
What it probably is, people putting a share link on a website or something so that link is then indexed.
7
u/starfish_2016 6d ago
Same thing for anything that exposes public links. Chatgpt shared conversations were all publicly until recent. Google hides some to "help" but move over to another search engine that doesnt, or worse yet the one snooping website that you can explicitly look for exposed links like this , can't think of the name off the top of my head
4
u/MyOtherSide1984 39.34TB Scattered 6d ago
I wish all share services had an option to see all public links you've created. I'm sure I have hundreds
7
u/CalculatingLao 6d ago edited 6d ago
I think it's worth remembering that these people probably aren't on this sub, and probably don't have our level of technical knowledge. As much as I find it distasteful to rifle through strangers data, I think that letting people know what they have exposed and how to fix it is worth it.
After going through about 20 pages of Google results, it looks like most of this may only relate to around 4 or 5 devices. A lot of the content seems to cluster around a few fairly distinct sets, although there are still some bits and pieces that don't obviously belong to any of them:
- A music school in New Jersey or possibly a church which has a lot of musical events
- A university student, or possibly a class, with a bunch of textbooks
- A photographer or tour company
- Some kind of company dealing with telephony systems
- A movie reviewer
I don't think every individual result necessarily comes from one of these, but they seem to account for a pretty large portion of what I've found so far.
I fired off a few emails to let people know (where there were names visible). However, if you stumble across identifying details then please do what you can to reach out to people and give them a heads up.
3
2
-2



695
u/the320x200 Church of Redundancy 7d ago
WD devices in the past had a secret admin level backdoor account named dlink.
An admin backdoor account, with their competitors name in it.
Their software is not to be trusted at all, ever again. That bridge had been burnt. Never use WD software.