…without snark or jumping down my throat. I genuinely want to know why it’s so unsafe.
I’m running a Synology DS920+, with my DSM login exposed through a Cloudflare tunnel. I have 2FA enabled, Synology firewall enabled with these rules in place. I also have this IP blocklist enabled.
After all of this, how would someone be able to break in via the DSM login?
Most NAS aren’t designed to be exposed to the World Wide Net. The login page isnt designed to handle things like DDOS or brut force attacks. Most of them don’t have 2 factor login option built in.
This plus, the fact you are exposing all of your data via this web interface. Allowing hackers to easily crypt mine/delete/steal your data.