Another Exploit Hits WD My Book Live Owners

A hard drive, disassembled
(Image credit: Photo by Ivo Brasil from Pexels)

While it will come as no comfort to those who had their Western Digital My Book Live NAS drives wiped last week, it seems they were attacked by a combination of two exploits, and possibly caught in the fallout of a rivalry between two different teams of hackers. 

My Book Live packaging

(Image credit: Western Digital)
Ian Evenden
Freelance News Writer

Ian Evenden is a UK-based news writer for Tom’s Hardware US. He’ll write about anything, but stories about Raspberry Pi and DIY robots seem to find their way to him.

  • dehjomz
    Would the windows 11 TPM requirement have prevented this ?? I doubt it.
    Reply
  • tomnewb
    Does anyone know if this also affects the WD My Cloud devices? or is just the My Book Live?
    Reply
  • you could not pay me to use thier stuff. ugh.
    Reply
  • hotaru251
    dehjomz said:
    Would the windows 11 TPM requirement have prevented this ?? I doubt it.
    no.

    many modern mb have it built in or optino to add one on.

    If TPM could stop this they'd basically always be used (as it would be a selling point they would brag about)
    Reply
  • spongiemaster
    tomnewb said:
    Does anyone know if this also affects the WD My Cloud devices? or is just the My Book Live?
    Just the old My Book Live. WD is offering My Cloud devices as a replacement, so one would certainly hope they aren't affected as well.
    Reply
  • mikewinddale
    dehjomz said:
    Would the windows 11 TPM requirement have prevented this ?? I doubt it.

    A TPM basically secures a password. But WD commented out the code that requires a password. So even if WD had secured the password in a TPM, it wouldn't help.

    (Not to mention the fact that Windows Hello uses a TPM to secure Windows-related passwords and credentials. WD uses its own software to administer the drive, so Windows Hello and other Windows-related security procedures wouldn't have even come into play.)

    Microsoft never claimed that a TPM is a magical device that solves all security issues whatsoever. It's simply one way of making certain things more secure than they otherwise would be.

    You might as well say that nobody should wear a seatbelt because it won't save you if you crash at 120 mph. Sure, but what if you crash at 60 mph?

    Just because a security or safety device is not 100% effective in all imaginable circumstances doesn't mean it isn't valuable.
    Reply