I just don’t understand why WD call it “My Cloud” if they now force me to authenticate through WD!
Before OS5 I could attach my phone directly to WD and the behaviour was what the name suggested
Even when I login to my PR2100 using the browser, I no longer communicate directly!! It all goes through WD.
I like that they want to offer authentication and account management on their server side as a backend
But I want the option to take control over “my cloud”
Otherwise just change the name of this product to WD Cloud.
It was a big mistake to upgrade to OS5. There is no consumer benefits, just WD benefits and control
Surely no privacy improvements like you suggested and my CPU busier then before and the OS is limited than before
Please bring back old features and let users choose if they want WD involvement in our private NAS
I just hate this OS
For the “connection type” called “direct”, my understanding is that you are forming a direct communication link with you NAS across the internet. If the “Connection type” is “relay”; then things are going through a WD server. If you are on your home network with the tools. . . it reports “local”; which is pretty self explanatory?
I might be wrong on what DIRECT and LOCAL means; so I would appreciate clarification
NOTE: The WD KB articles have IMPROVED; but are still written using circular definitions and are not clear on how the WD servers are involved.
My thinking is if you are logging into anything using an external server. . .well. . . yeah. . .opportunity for snooping exists.
NOTE: The web app will NEVER report “local”; although the phone apps do.
I think . . if you access your NAS from within your network (using file explorer/finder); or accessing through a VPN connection from across the internet. . .(I mean VPN to your home router; not VPN to WD Web app) WD servers are not involved at any point. (I have not recently tried VPN with cloud access turned “off”. Can’t remember if that works. . .
Local - means the client (web or mobile app) and the NAS are on the same local network
Direct - This is the same as Port forwarded connection. The client is not on the same network as the NAS and the client is able to establish a port forward connection to the NAS
Relay - The client is not able to establish a local or direct connection and establishes a relay connection. Typically seen on networks where upnp is disabled or is on a double NAT.
Local and Direct connection : Client is talking directly to the NAS. For relay connection , the relay servers facilitate the connection between client and NAS and has no additional involvement from WD
Considering we are talking about local NAS units, and not Cloud servers like OneDrive, or Dropbox; one can presume that a fair fraction of your userbase are people who value privacy.
I would suggest this type of information should be in the knowledge base articles.
Clarity on exactly how WD servers and what not are involved would be beneficial.
For the web applications. . .in direct mode. . . I imagine that some sort of communication is required with WD for handshaking, authentication and establishing minor things like. . . oh. . the IP address of the network and the port assignment of the NAS? But I presume nothing more than that?
(For others: for your own VPN connection. . .you have to supply the WAN IP address of your VPN server. . .and then the VPN server needs to deal with router issues on your network, as well as security authentication.)
(I am not sure exactly what the relay connection is about; but when you start talking about double NAT configurations. . .that implies that the NAS is buried deep in the network and you can’t use simple xx.xx.xx.xx:yyyy protocol to address the unit.)
Yeah, I noticed this with my Cloud EX 2 Ultra. Not a fan of it since it seems I have someone constantly trying to connect to my drive from outside the home network. Would really hope they add an update to disable this.
In networking you have many options but really ‘direct connection’ or not!
Direct connection should be client to server speaking directly (at layer3 to 7), basically from logical point of view “direct” (communication between two sides only!)
The other (non-direct session) option split to tens of options. Relay, proxy, with or without load-balancer / firewall that built a session but also manipulating the session (like NAT or with VIP), relay, scrubbing data, inline appliance/server that analyses the user-plane and many many more options.
Bottom line
When I type my NAS address or use my app behind the same LAN, then I expect ALL data to be transferred in the LAN weather I have internet access or not!
When I go to my NAS in 192.168.0.10 (just an example of private address) from my home, I don’t want WD OS to redirect me to some public Domain name! I don’t care it’s for control plane only… I want the full session to be internal.
If I’m outside my LAN then it’s ok if WD would offer the feature of remote connection assistance- but I still want my dat to be directly between client to server (over the internet) rather than any other involvement of 3rd side or any proxy like method. At least give me the option to choose
In my case I have IPsec and I don’t need or want 3rd side involvement at all. I should have the very basic option to communicate to the IP of the device without 3rd party act as MITM
I put a sniffer and quite shocked from the network behaviour of every single session. No wonder tcpdump is not part of this system.
I have still hope that people in WD will fix this and will let the user choose how we prefer to establish a session! Using their assistance or direct!
Call it MyCloud? Then make it like one!
Not only it’s featureless compared to Synology/QNAP but now it’s just worse.
I am not convinced that you are being forced to authenticate through WD as you describe. What you may see is that when you use a browser to connect to your local PR2100 the location redirects to a subdomain of remotewd.com.
I believe WD have done this so that they can issue a proper real-world TLS certificate (from LetsEncrypt) for every individual device. If you do a hostname lookup on the device-local-…remotewd.com address then it should simply resolve to the local IP address of your PR2100. So you are still connecting directly to your PR2100, just that this is now protected by Transport Layer Security.
$ host device-local-xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.remotewd.com
device-local-xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.remotewd.com has address 192.168.1.20
Note that 192.168.1.20 is a RFC1918 private net address, so my connection to the PR2100 is direct and does not route to the public Internet.
@vandelay Can you explain why, after updating to OS 5, there are constant “LAN access from remote” port 4430 notifications (looking at it through Netgear router logs)? All of the IP addresses start with 52, which I am sure is a part of Western Digital’s domain. Even though there aren’t any ports opened on the device itself or the router, it seems that there is one open due to how OS 5 is set up.
@vandely
Capture the traffic and you will see. You wget to the private address and you get some redirected + multi internet session.
The rest of the session is direct, however like I said, there is a lot of internet activities too. (Captured with hub)
Btw not sure why they removed the tcpdump, probably they want to hide this
Anyway, I don’t too much worry or think that they copy my data… I have NGFW to prevent it. But it also shows me that it blocks connections when I’m not using my NAS from the internet.
It’s just really annoying! It should be “my cloud” under my control
And if I turn off analytics- I want it off!
Bottom line OS5 is more limited, restricted and quite dodgy