Skip to main content

Dashboard access to my machine

Thread needs solution

I have just upgraded from True Image 2016 to 2017.

Just going through the process of testing it and creating the first backup when I stumbled upon the dashboard.

What an extraordinary feature. It was showing me the status of the running backup on my machine. Not only that, but I was able to cancel the backup and also restart it.

I go through hoops to try to secure the environment in my house, and Acronis (which is about giving recoverability on my machines) invites people to hack away at my user credentials for the cloud and play with the backups that I am running.

The most offensive thing about it was that I wasn't asked if I would like to make this new attack vector available to the internet, it just went ahead and silently did it.

So I have now stopped and disabled the service which connects to the cloud and allows the remote control to happen.

 

But is there a more official way (an option perhaps)? - I didn't even purchase the cloud option!

 

Thanks for any advice

 

 

0 Users found this helpful

Colin, welcome to these user forums.

I can only suggest that you should open a Support Case directly with Acronis Support (link to Contact Support below in my signature) and raise this issue with them.  Having said that, I have never heard of anyone being hacked via the Acronis Dashboard and even though you can control what backups are performed including the ability to delete these, if your backups are only stored on your local system / network / drives, then there is minimal risk of these being attacked via the dashboard.  

Acronis do provide the means of encrypting all of your backups regardless of where they are stored, so you can use this extra protection as needed.

There is no official method of disabling the Cloud Dashboard other than simply not signing in to your Acronis Account within the ATIH 2017 GUI - this will have the side effect of 'nagging' you on each launch to try to get you to sign in but if you can put up with that...!

Hi Steve,

Thanks for the response - I opened a ticket for with support, and they have added the request to 'customer feedback'.

In the short term, their advice was the same as yours - don't log in.

Regards
Colin

Colin, thanks for the feedback, sorry there isn't another answer to your concern.

Hello Colin,

Thank you for your post. I think I should elaborate a bit on the Dashboard feature.

You have already said that, but I would like to emphasize that without knowing your Acronis account credentials nobody can get access to your Dashboard. It is a matter of keeping the sensitive information confidential, just like you do with any other keys, secret phrases and codes.

You wouldn't give away your credit card details to anybody, would you?

Of course, the communication that the software establishes with the Dashboard is exclusively restricted to the backups. The Dashboard gives you an overview of your backups and some control over them (again, only if Acronis credentials are entered) - no more than that.

By simply surfing the web you expose yourself infinitely more than a secure channel to the Dashboard does. By using a web browser you give every website that you visit a lot of information that can be considered "personal": the IP-address, the exact build number and version of the operating system, the screen resolution of your monitor (when the browser is maximized), the exact build number of the browser, your local time etc. The combination of all that information can be used by websites to uniquely identify you and track what you do in the internet and when. So, compared to the secure SSL connection to the Dashboard, there are things that are infinitely more dangerous if we talk about privacy.

Chances that somebody breaks into your computer using the Dashboard are no higher than someone steals your bank account secret information, or remotely logs into your computer using your Windows account credentials, or hacks the military grade AES-256 encryption that is always used in the computer's communication with Dashboard independently of whether you have or not any backups.

We have not provided a button/checkbox to disable the feature because we are absolutely sure it is 100% safe.

Regards,

Slava

Hi Slava,

Thanks for your response.

The feature cannot be 100% secure. The best that you can do is to make it appropriate secure and 'difficult' to attack.

Part of being appropriately secure means me ensuring that I have a strong password which is difficult to guess. Part of it is that you should have appropriate safeguards to prevent repeated password guessing. I have read nothing that gives me that assurance. If you can assure people of safety without having those things, then you didn't understand the security problem.

Nevertheless, you have installed remote control software on my computer which provides an always on mechanism into my machine (a browser does not do this!).

I would like to disable it please.

 

Thanks Colin

 

try{(function() {if (typeof(lpcurruser) == 'undefined') lpcurruser = ''; if (document.getElementById('lpcurruserelt') && document.getElementById('lpcurruserelt').value != '') { lpcurruser = document.getElementById('lpcurruserelt').value; document.getElementById('lpcurruserelt').value = ''; } if (typeof(lpcurrpass) == 'undefined') lpcurrpass=''; if (document.getElementById('lpcurrpasselt') && document.getElementById('lpcurrpasselt').value != '') { lpcurrpass = document.getElementById('lpcurrpasselt').value; document.getElementById('lpcurrpasselt').value = ''; } var lploc=1;var lponlyfill=1;var lpdontsubmit=1;lpcurruser = ''; lpcurrpass = '';})();}catch(e){}
try{(function() {if (typeof(lpcurruser) == 'undefined') lpcurruser = ''; if (document.getElementById('lpcurruserelt') && document.getElementById('lpcurruserelt').value != '') { lpcurruser = document.getElementById('lpcurruserelt').value; document.getElementById('lpcurruserelt').value = ''; } if (typeof(lpcurrpass) == 'undefined') lpcurrpass=''; if (document.getElementById('lpcurrpasselt') && document.getElementById('lpcurrpasselt').value != '') { lpcurrpass = document.getElementById('lpcurrpasselt').value; document.getElementById('lpcurrpasselt').value = ''; } var lploc=2;var lponlyfill=1;var lpdontsubmit=1;lpcurruser = ''; lpcurrpass = '';})();}catch(e){}

You can disable the dashboard which runs as a service. Pretty much any if the Acronis services in computer management can be stopped and set to disabled. I do this myself since I don't use most of them. The only active one I have is the scheduler so my scheduled backups keep chugging along.

dashboard has been around since 2015. Acronis didn't install the software, you did. However, I get that you don't want that particular feature/service whatever you want to call it. It's built into the app so disabling the service manually is how you stop it. Our MVP Google drive has bat scripts you can use to disable features as you see fit if you don't want to manually disable them. Link is below as we have made some other tools and documentation to help other users (like you and me) tweak thing more to their liking or just to be more helpful with certain aspects that come up more frequently in the forums.