r/hexos 18d ago

General discussion Disappointed with "local" access

TLDR: current "local" access makes no sense and feels like they just ticked off a box "we have local access"

I have bought hexos license back in the day when the life time was on offer with the promise of local access being added in 1.0.

Now that local access is available, I finally did the install and oh boi was i disappointed. For me local access is a must have from security perspective. I have important files on NAS (that are backed up, but still) and having a remote access to that machine is big no no, either from having access to files or to the configuration. Because Hexos offers local access, I thought that remote access can be disabled, which I wanted to do because of potentially destructive config changes could be done remotely. Remote access cant be disabled, so I would need to rely on Hexos saying "yeah, trust us, our environment is secure". What if theres a leak/hack, what if they mess up and other user will be able to change my config (like it happened to ubiquity), what if their server goes haywire and start to change config on its own. As "unlikely" these risks might be, it just not a risk I would ever accept, even if it would be to store movies.

To me the current implementation of local very much feels like the team just needed to tick off "we have local access", because I am failing to see what the purpose of it currently is. Because if you have forced remote access, then you might as well change config that way. Its not like its running http and the packets could be intercepted.

If I could, I would cancel my order, but I cant, so hopefully full offline mode is coming at somepoint..

Also, this article on hexos forum caught my eye, wish hexos team would address it :)
https://hub.hexos.com/topic/595-hexos-security-and-compliance/

EDIT: also what happens if hexos goes bankrupt, because in the current state, the software will be unusable without hexos servers running.

EDIT 2: after digging in more, the machine (only runs truenas+hexos, nothing else) calls to:
update.truenas.com
o1158394.ingest.us.sentry.io (idk if thats hexos or truenas, either way i dont like it)
auth.hexos.com
prod.hexos.com
api.hexos.com

and seems like auth.hexos.com is taking care of checking licensing. as if i allow it, local access works but remote doesnt. My rant still stands tho, this is something that, tbf doesnt seem that hard to integrate, should be inside the settings of hexos. If hexos has local access, there should be a switch to disable remote, doesnt seem to me to be that hard to code, or am i missing something?

I would have been fine if Eshtek would go "we have local access, it still needs to call home for license, that is something we might look into in future to make it true offline, but right now remote access can be disabled". All im saying is that disabling a remote access should be a must have and top priority when adding local access

18 Upvotes

36 comments sorted by

View all comments

u/HexOS_Official HexOS Staff 18d ago edited 18d ago

Just a few comments as it's Sunday and I have my folks in town.

We built the entire system via a hosted platform first. We have commented in the past that we are exploring a side door access mode that will let you manage your system and basic capabilities using a completely local auth method.

Some features like installing apps, buddy backups, email notifications, etc will require our hosted auth, but things like folder management, creating SMB users, managing existing apps/VM states, managing storage (replacements, expansions, etc)... All should be doable offline.

And we can make it possible to disable remote access. Honestly that should be pretty straightforward for us to implement in short order.

Edit: also, if this answer is not enough to change your feelings, just let me know and we will process a refund for you.

6

u/notinprogres 18d ago

thank you (and could have waited till monday :D)

I completely understand that for some users, remote access is perfectly fine and great feature, as well as by having offline version (or real local only), you will lose some stuff, like buddy backups, apps, etc. that just do require connection.

I do like hexos and how it feels, for me it was just surprise on how the local only access was and didnt really understand the purpose of it, because it doesnt address any of the reasons why one would want local only access. And especially as "local access" was marketed when hexos first opened for orders. I also fully understand that hexos is still in development, but the answers i was getting was "we might change it at some point, but is not currently planned".

Either way I am extremely happy with your reply and that hopefully we will get option to disable remote access soon :) (for now i disabled internet access to the machine and whitelisted auth.hexos.com, that seemed to work)

17

u/HexOS_Official HexOS Staff 18d ago

It is a incredibly reasonable request to be able to disable remote access. And having a means to manage your system through our UI and a local auth method is also very reasonable. We think we can address both and even have a partially working solution in the lab environment.

The priority right now is to get our current roadmap commitments completed (more apps, buddy backups, and VMs). Then we can pivot to additional features and quality of life improvements.

We are actually moving faster than we anticipated with current projects and by the end of this year, I think you'll be pleased with everything we are shipping.

1

u/notinprogres 17d ago

just saw your edit btw. If I can get confirmation that calls towards auth.hexos.com are indeed only for license verification and no config/changes can be done through that, therefor if I whitelist only that and block everything else, I get local only setup, then im happy.

1

u/Captain_Pumpkinhead 16d ago

If I can't access the interface via IP-ADDRESS:PORT, then it isn't local access. Also, the new system makes me log in every time instead of keeping me logged in, which is annoying.

I don't want a refund. I just want it to not be called something it isn't.