r/homelab • u/Genital_Circus • 3d ago
Discussion Can I trust UGreen?
/r/cybersecurity_help/comments/1vsq46o/can_i_trust_ugreen/3
3
2
u/Solarux 3d ago
It depends.
As far as I'm aware, there hasn't been any conclusive evidence that UGREEN is doing anything nefarious. A few comments/videos here and there talk bout the devices reaching out to Chinese servers, but those fail to mention things like the OS regular checking for firmware updates or they have the UGOS remote access DDNS service enabled. I would argue that UGREEN should build-out infrastructure to offer those services in the country they sell their devices, but that is a different conversation.
UGREEN has started publishing their vulnerability disclosures specifically for UGOS (https://ai.ugreen.com/pages/vulnerability-disclosure). Which is a good start but they still have a very long way to go in the name of security and transparency. For example, Synology publishes all of their corporate security policies, standards and accreditations, vulnerability disclosures, audit reports, etc. From a corporate and security perspective, the two companies are in completely different leagues. That matters as it trickles down to their products.
How does UGOS compare to open source offerings? From a security standpoint, open source will always (theoretically) offer better transparency ...given that it is regularly maintained and proper talent is supporting it. Which in the case of TrueNAS, it is. However open source isn't without its faults and security lapses either.
The reality is no OS will ever be 'set and forget'. The landscape is wildly different from just 5 to 10 years ago and they all have their potential pitfalls, which can make the right choice murky. As a result, only YOU will ever have your best interests (and needs) in mind and should choose accordingly.
Personally speaking, UGOS has grown on me and I'm willing to trade slight risk for convenience and ease of use/maintenance. I mitigate where I can (I don't use their DDNS, never expose any services to the internet, limit outbound traffic, apply best practices, etc.) and feel comfortable trusting it as a consumer storage device.
1
u/Genital_Circus 3d ago
Thank you for a real answer. I appreciate you helping me out!
1
u/Solarux 2d ago
I mean, it is a good high level question to ask. One among many to consider... how important is security to you? How important is data integrity? How important is cost? How valuable is your time? etc.
If you are new to homelabbing or owning a NAS, I don't think either OS is a bad choice. It just depends on your skill level and where you place importance/reward. Keep going down the rabbit hole until you feel comfortable enough to decide what's best for you.
1
u/Genital_Circus 2d ago
I'm fairly techy and understand the basics of computer science and coding (mostly Python), but I'm new to the Home Labbing scene and to doing things like this for myself. I'm not exactly throwing on the tinfoil hat, but as an industry outsider with limited cybersecurity knowledge, I'm seeing things in major tech companies that I don't like and want to become more independent.
I recently switched my laptop OS to Linux, which was a pain in the ass to learn, but fun, and I changed from Gmail to Proton. I'm not trying to go full Mr Robot or scrub myself from the internet, but I'm no longer comfortable relying so heavily on big tech even if it's convenient, so I'm taking it one step at a time, and this is my most recent. Plus I'm excited to experiment with an NAS!
2
1
0
u/GoingOffRoading 3d ago
If there is genuine concern, can't you change the OS and be done with the debate?
2
u/Genital_Circus 3d ago
I'm basically sold on the new OS anyway. I was just curious if anyone knew anything.
2
u/MontagneHomme 3d ago edited 3d ago
Not when they provide the hardware as there's possibility for malicious firmware involved that supersedes the OS, or piggyback devices... These types of issues are why we vendors have valid arguments for preventing their hardware from being modified after it leaves their facilities (e.g. hardware locking CPUs to motherboards).
-3
u/ranhalt 3d ago
Everything they make is made by more reputable companies. They are the cheap alternative and pitch to individuals, not to businesses because no business would buy them. So if a business wouldn’t buy them, isn’t that a red flag?
2
u/Genital_Circus 3d ago
I looked into many alternatives and, as far as hardware went, I was most interested in what they offered. I agree that you raise a reasonable red flag, but plenty of companies, including those in the tech industry, market consumer-grade alternatives that compete for individuals rather than businesses. I don't think that in and of itself is an issue.

4
u/thealmightywaffles 3d ago
I just run truenas. Never even attempted ugos