QUOTE(xxboxx @ Jun 21 2023, 06:47 PM)
With 2FA or SecureSignIn it is as safe as using Google Drive or Dropbox. There's still the risk of 0 day exploit but based on Synology track record I feel the risk is low.
Having another layer of security such as use VPN of course will be more safer.
If don't want to expose your whole NAS to internet but want to have own hosted cloud storage, maybe you want to be able to give link to outsiders to download from your NAS. Can use your NAS to run VM of another DSM and this DSM that will be exposed to the internet.
Yup did have 2FA

not thinking of other things beside the Drive only then feels better
QUOTE(blacktubi @ Jun 21 2023, 10:20 PM)
I knew a SME that use QC with the default ports. It's been a few years and they are still fine.

Keep your DSM updated and configure DSM properly to prevent brute force attack then you should be fine.
For the bare minimum, use a different port to deter the mass scanning brute force attacks.
It's always a balance between security and convenience.
Owh i did change it, btw just home user
QUOTE(ozak @ Jun 21 2023, 10:24 PM)
Been using QC for very long. Till now.
So far so good.

make me more convenience then