Are Android phones facing a remote-wipe hacking pandemic?


Recommended Posts

Is the sky falling?

Are Android phones about to be wiped off the face of the earth?

Will hackers be triggering a factory reset on your phone whenever they feel like it?

Are you going to wish you'd got one of those iPhone jobs after all? (No pun intended. Rhetorical question.)

That's the worry going around since self-confessed Kiwi geek Dylan Reeve put a "test your mobile phone for imminent disaster" page on his website.

For the record, Dylan doesn't actually remote-wipe your device without permission. He just shows you if it might be possible. The Kiwis probably already thrashed your country at rugby, even after two of their players got sent off. They don't need to rub it in by wiping the floor with your phone, too.

The details of the disaster are absurdly simple, so allow me to explain at some length.

There's a special sort of telephone number URI, detailed in RFC 3966, which can be used like this:

tel-uri-eg-500.png?w=494&h=33

As the text of RFC 3966 points out, unromantically but importantly:

The "tel" URI is a globally unique identifier ("name") only; it does not describe the steps necessary to reach a particular number and does not imply dialling semantics. Furthermore, it does not refer to a specific physical device, only to a telephone number.

So telephone URIs don't instruct your browser, or your tablet, or your phone, to dial. They just suggest that it could, if it wanted.

What's got Dylan Reeve hot under the collar is that in some browsers, on some builds of Android, on some phones, the dialling semantics of telephone URIs are: load the default "dialler" or "phone" application, insert the number as if you'd typed it, and wait for you to press the magic green button to initiate the call.

Waiting for the green button is a security measure. It prevents a website calling out without some sort of user interaction. That would be insecure and could be expensive.

In short, some browsers treat tel: URIs almost as a special, and tolerated, form of cross-site scripting (XSS). Visit one site at an innocent-looking URI, and end up redirected to a different URI in a different application for a different purpose.

So far, so good. But what's got Dylan's smoking collar on the verge of bursting into flames is this: automatic in-band signalling.

In-band signalling is when some special character combinations, appearing in your regular data stream, are treated as control sequences.

As you can imagine, this is just the sort of compromise implemented to bring convenience at the cost of security.

The inherent risk of in-band signals is one of the reasons that FTP was designed to use two TCP connections, one outbound and one inbound - so that the data and control channels were kept separate. It was also one of the reasons why FTP withered for data transfer in favour of HTTP, which uses a single channel and thus works more easily.

Mobile phone numbers support a raft of in-band codes with the grandiose collective name of Unstructured Supplementary Service Data (USSD). As Wikipedia notes, in its uniquely uneven yet informative style:

The user composes a message ? usually rather cryptic ? on the phone keyboard. The phone sends it to the phone company network, where it is received by a computer dedicated to USSD. The answer from this computer is sent back to the phone. The answer could be seen on the phone screen, but it is usually with a very basic presentation. The messages sent over USSD are not defined by any standardisation body, so each network operator can implement whatever it finds suitable for its customers.

Sounds like a recipe for confusion, if not actually disaster, doesn't it?

So, what does a USSD look like? Perhaps the best-known, and the one used by Dylan on his demo page, is to enter *#06# to pop up your phone's official identification number, better known at the IMEI.

If you were to type *#06# into the dialler on your own phone, you may very well see that the IMEI pops up as soon as you press the final # key. It's automatic: you're not actually making a call, so the green button isn't needed. Some diallers warn you that you're on the verge of triggering an in-band signal - and give you an out-of-band way to prevent it, which is handy - but some do not.

This means, if you browse to Dylan's test page and your IMEI pops up without any further interaction, that you are at risk of a potentially lethal combination - lethal to your data, anyway.

This is because many phones offer a USSD command for "factory reset". It's meant to be hard to type by mistake - impossible, more or less. But it's not impossible for a miscreant to type into a tel: URI on a malevolent web page, and there's the rub. Or, in fact, the wipe.

What to do?

If your phone is vulnerable - and if Dylan's page says it is, it probably is - then Mr Reeve suggests installing a third-party dialler application which is known to provide safety against the auto-activation of USSDs. That's good advice.

Your current browser or dialler might be safe already. On my Google Nexus phone, for example, running Android 4.1 with the Firefox browser, visiting Dylan's page does pop up the phone dialler. But the *#06# USSD code is not auto-triggered - it just appears as a number you haven't dialled yet. As far as I can see, the dialler only processes the in-band USSD codes if they are typed in by hand. That's good.

(Before you install a brand new dialler app - and you knew I wouldn't resist a little advertising somewhere in the article, didn't you? - you might also consider a trip to the Play Store to install Sophos Mobile Security. Completely free, you get anti-virus, anti-malware, anti-spyware, anti-adware, loss and theft protection, plus a pair of really easy-to-use security and privacy advisor tools.)

The bottom line here is this: get into the habit of backing up your phone. Whether you choose to trust the cloud, or synchronise to your laptop, or just copy important files to removable storage, don't take the long-term data integrity of your phone for granted.

You might suffer a hysterically-funny-to-some-childish-haxxor remote factory reset. It could happen.

But you might also leave your phone in the pub, have it nicked from your bag, or drop it catastrophically onto the only concrete surface for hundreds of metres in every direction (like I did a couple of weeks ago, on a balmy Sunday spring afternoon that was going gorgeously up to that point).

If your digital life is at risk from an unexpected factory reset, then you need to re-arrange your digital lifestyle.

Assume that all your electronic devices might break at any time, and that at least some of them will.

Source: Naked Security

Aren't they overplaying the problem a bit in this article? I thought the issue was specifically with TouchWiz?

Anyway, just tested the website on my S3. The first time I got asked which dialer application I wanted to use. Once I had set a default dialer and tried the site again, the dialer appeared with *06 ready to dial, but it was waiting for me to push the call button. I guess that means I'm safe from this particular attack?

Anyway, Android won't crumble because of this. Now that it's public knowledge I'm sure someone will find someway of officially stopping this kind of thing from happening.

yeah bound to just be a way in the software to make it by default wait for the call button to be pressed no matter what is typed in

i will try mine soon lol

It kinda is because if that sites link that initiates the wipe thus its being done remotely

Balls

not just Touchwiz

my phone is a custom sense rom and it displayed the IMEI directly

Remote USSD Attack - Prevention

An interesting (and potentially devestating) remote attack against at least some Samsung Android phones (including the Galaxy S3) was disclosed recently.

Update 1: Samsung have been aware of this issue for a few months and the latest firmware for Galaxy S3 (4.0.4) appears to resolve the issue.

Update 1a: While some 4.0.4 versions appear to be secure, others are vulnerable.

Update 2: Samsung is not alone in being vulnerable to this issue.

Update 3: An app has been created specifically to catch these URL calls, if you don't want to install another dialer: TelStop (by @colimrm)

In brief it works like this:

  • Phones support special dialing codes called USSDs that can display certain information or perform specific special features. Among these are common ones (*#06# to display IMEI number) and phone specific ones (including, on some phones, a factory reset code).
  • There is a URL scheme prefix called tel: which can, in theory, be used to hyperlink to phone numbers. The idea being that clicking on a tel: URL will initiate the phone's dialer to call that number.
  • In some phones the dialer will automatically process the incoming number. If it's a USSD code then it will be handled exactly as if it had be keyed in manually - requiring no user intervention to execute.
  • A tel: URL can be used by a hostile website as the SRC for an iframe (or potentially other resources like stylesheets or scripts I guess). It may then be loaded and acted upon with no user intervention at all.

I have uploaded a test page to my webspace as the one above is very slow

It will display your IMEI number if your dialer is exploitable

http://haggistech.co.uk/USSDtest/

not sure if for all phone but it is a standard RFC 3966

"tel" URIs are a standard, but I don't think the USSD codes you'd be using to exploit this are. I haven't tried many codes but *#06# (the USSD used on the exploit demo that shows your IMEI) is definitely not working on my phone.

I don't know if that's because of the phone model or because of the carrier.

just in case anyone wondering this is the html for the site i uploaded just so you know nothing dodgy lol


<html>
<head><title>USSD Exploit Test</title>
</head>
<body>
<p>If your phone is vulnerable to the recently disclosed tel: URL attack then this website will cause your phone to open the dialler and display the IMEI code. With other USSD codes it could do any number of other things, including wipe all phone data.</p>
<p>You can find some more information and a simple workaround here: <a href="http://dylanreeve.posterous.com/remote-ussd-attack">http://dylanreeve.posterous.com/remote-ussd-attack</a></p>
<iframe src="tel:*%2306%23" />
</body>
</html>
[/CODE]

If you bothered to read some of the comments and actually research it you will find its not been patched fully

People with the latest S3 firmware are still reporting it working

https://twitter.com/...591062480003072

http://www.engadget....-vulnerability/

and btw, there are apps that prevent this in case you are not on the latest fixes

Some apps have been created specifically to catch these URL calls: TelStop (by @colimrm) and Auto-reset Blocker

So the workaround is found and those who are not patched will probably be patched soon.

I was just referring to the whole doomsday headlines not that the problem doesn't exist.

Its nice to see that the Apple users and fanboys dont need to come here to bash and take-over an Android security flaw. I wish Android fanboys learn a bit with this and behave better in future in Apple topics.

Nice that Samsung secured that, every system has flaws the trick is to acknowledge and secure them fast enough.

tested on my phone a custom CM10 rom with 4.1.1. Put *#06# in the dialer box, but it didn't call and when I tried to dial said it was an invalid code.

My AOKP 4.1.1 (are they still based on CM?) does the exact same thing. Guess we're safe for now.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Neowin is saying these are good prices? Thats crazy. As others have said they are just ######. Time for big tech to bring down the prices for real not this fake crap.
    • The iFlyTek AINote 2 is among the thinnest E-Ink tablets. It has an EMR stylus, a built-in fingerprint reader, and plenty of built-in AI features. You had me until "and plenty of built-in AI features." That and any company that still does the iProduct naming trope is an immediate pass. It suggests the company isn't very imaginative or creative and is trying to piggyback off another company's success. Extremely lame. Also kind of expensive. Better choices at lower prices out there.
    • These are not "great" prices... just "less awful". Apparently "Those who forget the past are doomed to pay higher prices and think they've won."
    • Russia was able to invade Crimea because of those people. But my point is that I've personally heard how great it was to be "back in Russia" right afterwards - look how great it is now. I've asked you a question in another comment which you haven't answered, so I'll ask it again: is it better now without "Europrats"?
    • ZimaBoard 2 1664 Starter Kit review: it's a cool and affordable DIY NAS by Steven Parker IceWhale Technology reached out to me asking if I was interested in testing the ZimaBoard 2, and after convincing them to send me the Starter Kit, it arrived at my doorstep in May. A bit of background: it is a Shanghai-based Chinese company founded in 2020, which specializes in single-board servers and personal cloud solutions. From searching around online, user feedback on the company and ZimaOS is mostly positive, so we're off to a good start. In addition, I should probably point out that although they do not have a large portfolio of NAS devices, with just four of what they do offer, they seem to have covered everything from a relatively low-priced entry point with the ZimaBoard 2, right up to the high end, with the ZimaCube 2 Creator Pack that even includes an NVIDIA RTX PRO 2000. Anyway, as already mentioned, what we have today is the ZimaBoard 2 Starter Kit, and here are the full specifications: ZimaBoard 2 Model 832, 1664 CPU Intel Core N150 (4x E Cores/Threads, Max burst up to 3.6 GHz) TDP: 6W (Base) 10W (Max) Graphics Intel UHD Graphics 24 EUs (1.00 GHz) Memory 8 GB, 16 GB DDR5 4800MT/s non ECC SODIMM (soldered) Disk Capacity 60 TB (30 TB x 2) Supported RAID Types TRAID, TRAID +, RAID0, RAID1, RAID5, RAID 6, RAID 10 Storage 2 x SATA 3.0 6Gb/s Ports with Power Bootloader 32 GB, 64 GB eMMC Network 2x RJ-45 2.5 GbE PCIe 1 x PCIe 3.0 (via LPC) USB Ports 2 x USB-A 3.1 (5 Gbps) Display Mini-DisplayPort 1.4 (4K@60Hz) Hardware Transcoding Engine H.264, H.265, MPEG-4, VC-1 Maximum resolution: 4K (4096 x 2160); Maximum FPS: 60 Virtualization Intel® AES New Instructions Intel® Virtualization Technology (VT-x) Intel® Virtualization Technology for Directed I/O (VT-d) Size (H/W/D) 140mm x 83mm x 31mm Weight 0.4 kg (only ZimaBoard 2 device) Power 12v 5A Power Supply Warranty 1 year (Global) 2 Years (EU) OS ZimaOS v1.6.1 MSRP $339, $399 ($548.60) As you can see above, there are two variants of the ZimaBoard 2. The lesser variant has half the eMMC storage and 8 GB less RAM, although it also costs $60 less than the top variant we are testing today. The above pricing is only for the ZimaBoard 2. I put the MSRP of the Starter Kit next to it in brackets, although as of publishing, it is discounted to $534.50. The ZimaBoard 2 started life on Kickstarter and shipped to backers in August last year. It became available via the official website in late 2025 and Q1 2026. This hobbyist NAS contains the still relatively new N150 Intel CPU released in the first quarter of 2025, with support for DisplayPort 1.4, HDMI 2.1, although in this case, the memory is integrated into the board itself, so it will not be possible to upgrade or expand the amount. It also supports AV1 decoding, as well as H.264, VP8, VP9, H.265 (8 bit), and H.265 (10 bit). The different capabilities in the Alder Lake-N (and Twin Lake) series are listed below. Processor E-cores L3-cache Turbo clock GPU GPU-clock TDP Intel N355 8 6 MB 3.9 GHz 32 EUs 1.35 GHz 9 W Intel Core 3 N350 3.9 GHz 1.35 GHz 7 W Intel Core i3-N305 3.8 GHz 1.25 GHz 9 W Intel Core i3-N300 3.8 GHz 1.25 GHz Intel N250 4 3.8 GHz 1.25 GHz 6 W Intel Processor N200 3.7 GHz 0.75 GHz Intel N150 3.6 GHz 24 EUs 1 GHz Intel N97 1.2 GHz 12 W Intel Processor N100 3.4 GHz 0.75 GHz 6 W The CPU is part of the Twin Lake series that sits near the bottom of the N-series, designed for low- powered systems and entry-level laptops, and as such has a base level TDP of just 6W. As I have noted before, we are seeing another NAS with a great amount of RAM. It's important to mention that the ZimaBoard 2's memory is integrated into the base board (which is why they have two variants of it). As a reminder, up until a couple of years ago, it was commonplace to only get 2 or 4GB max on a flagship Synology or QNAP home NAS. Ever since the likes of TerraMaster and more have entered the market with ample RAM sizes included in their NAS offerings, it has gone a long way in forcing the hands of the traditional makers to up their game a bit. First impressions The Starter Kit came in one outer box with several packages inside it (shown above). I forgot to take pics of it because when it arrived, it wasn't clear what was inside, and I had to confirm with my contact that I received the entire Starter Kit. In the box ZimaBoard 2 ZimaBoard 2 HDD Expansion Bracket + PCIe card frame Zimaboard Mini DisplayPort Male to HDMI Female Cable 4K 60Hz Zimaboard PCIe 3.0 x4 to Dual NVMe M.2 SSD Adapter Card Quick guide [full online guide] Limited warranty notice Screws Design Where to start? You'd be forgiven for mistaking it as an SSD enclosure if not for all the ports on it. It is completely made out of metal, and the top is an entire heatsink. It has a premium feel about it, but it definitely looks like a hobby device. As you will see, the completed build looks like it belongs in a server or meter closet rather than as a showpiece on someone's desk. On what I am calling the rear, there's a Mini DisplayPort (1.4), two 2.5 GbE ports, with Type A 3.1 USB ports, and then the barrel connector port. Around the front, there are two SATA6 ports with a power connector in the middle. Left side Right side One side is completely free of ports. On the other there's a slit that allows for the feed of a CPU fan cable, and a PCIe 3.0 X4 slot. Top Bottom The top is entirely made up of a heatsink except for the extended height for the I/O on the rear. Around the other side, you can find the ZIMA branding and some regulatory information stamped near the bottom. As you may see from the bottom of the ZimaBoard 2, it scratches quite easily from just moving it around on my Ikea island. Teardown Before we get started, let's have a look at this thing on the inside. The steps to get to the board are as follows: Remove the four smaller Torx screws on the bottom of the ZimaBoard 2; Remove the four larger Torx screws on the sides of the device; Carefully unstick the CMOS battery from the PCB; Remove two Phillips screws on the PCB; Lift out the PCB. Yes, as you can tell from the instructions, you need three different tools to remove Torx and Phillips screws (10 in total), and unhelpfully, one of the screws is located under the CMOS battery, which is stuck onto the PCB. Building Now comes the fun part. Because the ZimaSpace website does not provide any guidance on how to put the Starter Kit together. They only have guidance for connecting the CPU fan. However, they did upload a video to their YouTube channel that shows the entire process. To install the fan, first remove the four screws on the bottom of the ZimaBoard 2, then on the inside, there is a CPU FAN connector where you can attach the fan, reattach the ZimaBoard 2 frame, and feed the fan cable through the provided slit. Then remove the nearest screw on the side and attach the fan frame to the side of the device using the same screw. ZimaBard 2 screws Aligning the screws Bottom view Remember those four screws we removed to access the CPU FAN? Longer screws are provided in the box with the HDD Expansion Bracket, which is what you will now need to attach the ZimaBoard 2 to it. Helpfully, the orientation on how to attach it is made obvious when the frame can only be screwed on at the same overall length as the ZimaBoard 2. If you do it the wrong way around (which is what I did initially) one side hangs off the frame, and it becomes difficult to attach the PCIe Adapter Card cable. PCIe card frame Other side PCIe slot connector Next, it's time to attach the PCIe card frame, which is fastened with the help of 3.5-inch SATA HDD (3 screws). These are toolless screws that you can just use your fingers to fasten them with. Then it is time to connect the provided PCIe cable with the slot connector on one side of the ZimaBoard 2, feed it through the bottom of the HDD frame, and fasten it with two standoffs. Both bracket options 2280 standoffs with 2x 4TB MP44Q The PCIe 3.0 X4 card comes with a short bracket option, handy if you decide to place it inside a different NAS or rack server, but here we need the long bracket. Oddly enough, the M.2 standoffs were preinstalled into the 22110 position, but extra standoffs are included in the box, which I installed at the 2280 position for our use. I added a couple of MP44Q M.2 PCIe 4.0 SSDs (2 x 4TB) that can be availed on Amazon for $478.99 (the lowest price for 3 months) that TEAMGROUP supplied us with Then we have the almost completed build, you just need to push the card into the PCIe slot. Unfortunately, IceWhale Technologies did not provide a screw for the PCIe card frame (this is also apparent in their own video). Here it is at several different angles, with the last pic showing the SATA Y-Cable connected to the two WD Red Plus 4TB drives. Setup and Usage Next, you connect your cables to the I/O, and the ZimaBoard 2 powers on automatically, as there is no power button on the device. Power is controlled through the Settings in ZimaOS. BIOS The ZimaBoard 2 includes an Aptio BIOS from American Megatrends [1, 2, 3], and you can setup pretty much everything here including the boot order, which is locked to the UEFI OS, however above that choice you can enable or disable booting to a SATA/USB bootloader so this would still allow you to switch to an alternative bootloader and boot from it, or disable it to instead always start from the first disk with an OS installed on it. Initial Setup Upon connecting to the LAN and booting up, the ZimaBoard 2 can be reached by navigating to the IP address (shown if you have a monitor connected), or you can find it using the ZIMA Client desktop application, which is essentially a Zima device finder. Initializing the ZimaBoard 2 The ZimaOS setup process is pretty straightforward, through a wizard, and in full above, it basically consists of setting up an account and some handy tips, and that's that! Post Setup (ZimaOS update) Upon first boot, you are alerted that there is a ZimaOS update from 1.5.0 to 1.6.1, which I applied; the full process is shown above with the changelog. ZimaBoard 2 Storage Setup Next, it is time to set up the storage. ZimaOS actually throws everything onto the eMMC flash drive; it is also the default location of AppData, which is definitely something to be wary about, as the 45GB available storage could fill up quickly. HDDs I first attempted to create a Storage Pool using the two 4TB WD Red Plus NAS drives, and got an error message: After several attempts and then looking online, I discovered it was a bug with ZimaOS where the fix was simply to reboot ZimaOS and then try again, this time I was able to create a RAID mirror using the two drives. SSDs I did the same for the SSDs, as you will see in the above gallery, when I created the second Storage Pool, it only allowed me to select available drives. ZimaBoard 2 AppData ZimaOS comes with an App Store that includes a repository of almost 400 apps, so you will be able to find most of what you'll need for a NAS (although after a quick search, I wasn't able to find a Surveillance Manager), and now comes the important part: moving the default AppData location off the 45GB eMMC and onto a larger volume: Open Settings Then Apps Then, in the Select a new location field, click on the new Storage volume you want to move it to (in my case, the Apps Storage Pool), which is the SSD RAID mirror. Confirm the Migration warning Be praised! You can also do this for Docker (which by default installs onto the 45GB eMMC flash drive) and the User database. Plex Setup Next, I tested the configuration by installing the Plex Server app from the App Store. The library folders must already exist (which I placed into the Storage Pool). Plex Server setup is straightforward and requires very little configuration. In my case, all I had to do was add the media path I just created, which you can also browse to using the folder icon in the path field. In addition, you can now map the new Media library in Windows Explorer using the Zima Client. Oddly enough, it is not possible to access the ZimaBoard 2 over the Network Neighborhood; you must map drives using the client, which is shown in the last image in the above gallery. I watched one of my Blu-Ray rips, which is Dolby Vision with Dolby Atmos, and the content played fine with no stuttering or buffering, which is what anyone needs in this scenario. ZimaBoard 2 Zima Client mobile app There's also a client for mobile. It is pretty barebones, as shown in the above gallery, for example, the Apps screen launches the WebUI for that app, and the Backup must be done manually. On opening Backup, you can select internal storage folders on your phone to backup to the ZimaBoard 2's storage, and although this is constantly scanned, the backup action itself must be manually triggered. There is an option to allow foreground backup (last image in the above gallery), but this basically means the queued backup gets triggered when you manually open the app. Benchmarking SATA PCIe 3.0 X4 A CrystalDiskMark test on a mapped network drive from within a Windows 11 25H2 PC (image above) connected over a 2.5 GbE was well within acceptable ranges. Writes were generally better on the SSD RAID mirror. SATA PCIe 3.0 X1 I also ran the NAS Performance tester, which tests the link speed performance. As you can see, it pretty much maxes out the 2.5GbE connection. Of course, you can also opt to bond the two 2.5 GbE connections for a bit more umph, but I didn't do that. Thermals Top PCIe card SATA HDDs Next, I measured some hotspots while playing content on Plex. It's fair to say this will perform better than a NAS that is enclosed in a metal or plastic case, as almost everything storage-wise is exposed! Anyway, the ZimaBoard 2 did not break a sweat with Plex streaming or disk benchmarks. ZimaOS Factory Reset ZimaOS does not include a factory reset option. Instead, you have to download the ZimaOS image and flash it to the eMMC manually. The flashing process is shown in the above gallery. The steps to do so are listed below: Download the ZimaOS image here; Open BalenaEtcher (Run as Administrator) and select the image; Select your inserted USB drive (min 8 GB) Flash to it; Connect your USB drive, monitor, keyboard, USB hub (optional), mouse (optional), and network cable (recommended) to the ZimaBoard 2; Connect power and press F11 continuously; Select your USB drive starting with UEFI in the boot device menu; Press Enter on the Install ZimaOS option; Select /dev/mmcblk0 (MMC) flash drive as target; Confirm with (three times) to wipe the target disk; Wait a couple of minutes while ZimaOS installs; Remove the USB drive and confirm with a reboot; Your ZimaBoard 2 has been factory reset. However, you don't have to stick with ZimaOS, in fact the company also offers official CasaOS images, that are based on Debian; or as they say themselves, put anything you want on this "hackable single board server" it's up to you. Conclusion I had a lot of fun putting this together. I've custom-built all my own PCs and servers since the 90s, and this is the first time I have had to put a NAS together. Even if the actual base ZimaBoard 2 was already a completed build, it still feels pretty custom. I just wish that IceWhale Technology included a getting-started guide in the box for the Start Kit, which would have really completed this kit. Instead, I had to search for the official video on the YouTube channel to make sure I wasn't doing anything wrong. So who is this for? Definitely the hobbyist who is comfortable building their own PC and servers. It also has a much smaller footprint than its nearest equivalent (in terms of specs), like the Beelink Me Pro, which is another NAS I will be testing soon. Although the Beelink does not come with the PCIe 3.0 X4 expansion, the ZimaBoard 2 Starter Kit suddenly looks to be a great bargain, even if it only offers the two 3.5-inch bays over the four in the other example. It makes a lot of sense to use Intel's N150 chip inside a NAS; it is more than capable of doing what the ZimaBoard 2 is intended for, media streaming and backup. It also looks like the IceWhale Technology staff are quite active in the official forums helping people with issues they come across with ZimaOS and the devices, peer support seems to be good as well, I was quickly able to find why I was not able to create a new Storage Pool in ZimaOS v1.6.1 even though that is quite a serious bug, hopefully it will be fixed in the next update. If you are comfortable with the command line and Docker, you'll be fine. You can do great things with this hardware. This was my first time with ZimaOS. It seems a bit barebones in comparison to the likes of Synology DSM, TOS, and UGOS, but it has a ton of apps to get you started with your home or small business NAS. Where to buy As of publishing, IceWhale Technology is running a discount of up to 5% for the Starter Kit. If you opt to get just the ZimaBoard 2 itself, it does come with a SATA Y-Cable, so you will be able to connect up to two 3.5-inch HDDs to it. ZimaBoard 2 1668 Starter Kit for $534.50 on Amazon US (was $548.60) ZimaBoard 2 832 Starter Kit for $372.88 on Amazon US (was $390.60) Zimaboard 2 1668 (16GB+64GB) for $419.90 on Amazon US Zimaboard 2 832 (8GB+32GB) for $359.90 on Amazon Disclosure: IceWhale Technology provided a free sample without any editorial input or review pre-approval. Good to know The Amazon link is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, when you purchase through links on our site, we earn from qualifying purchases.
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      487
    2. 2
      +Edouard
      220
    3. 3
      PsYcHoKiLLa
      147
    4. 4
      Steven P.
      74
    5. 5
      FloatingFatMan
      70
  • Tell a friend

    Love Neowin? Tell a friend!