Can someone please explain to me, a casual home user, why it's dangerous to expose my NAS login page to the internet?... - eviltoast

…without snark or jumping down my throat. I genuinely want to know why it’s so unsafe.

I’m running a Synology DS920+, with my DSM login exposed through a Cloudflare tunnel. I have 2FA enabled, Synology firewall enabled with these rules in place. I also have this IP blocklist enabled.

After all of this, how would someone be able to break in via the DSM login?

  • AnApexBread@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    It’s basically the same as any other time people expose something to the internet.

    Most don’t know what they’re doing or how to do it safely so they put a vulnerable device out in a vulnerable state.

    The only reason a NAS is worse is because it’s more common for a home user to have a NAS then it is to do something like host a WordPress, and a NAS has more personal stuff than a WordPress does (usually)