Nicholas TongQNAP TS-464
11 / 46
QNAP TS-464: the box with a reputation
The QNAP I inherited had been exposed to the internet for three years before I saw it. A sign shop off Telephone Rd, the NAS living on top of a filing cabinet next to a laminated fire evacuation map, port 8080 forwarded so the owner could check files from his truck. This was April 2021, the week Qlocker was locking up QNAP web consoles all over the internet and zipping people's files for ransom, and this box had every default: admin account, forwarded port, myQNAPcloud configured, no 2FA. It survived on timing and luck, which is not a security control, and I have thought about that cabinet a lot since.
Plainly, per my rules: the TS-464 is not a purchase recommendation, and I paid for it myself. It costs roughly twice the 2-bay Synology I wrote about last week, bare, and the drives are extra.
the part everyone gets wrong
"QNAPs get hacked" is the summary people walk away with, and it flattens a real story into the wrong lesson. The hardware isn't the vulnerability. What kept happening, Qlocker in 2021, Deadbolt in 2022, the long tail of advisories around exposed web consoles and backup apps, is a pattern of defaults and reachability: management ports forwarded, myQNAPcloud adopted because the setup wizard suggested it, patches deferred because patching a NAS felt like maintenance. QNAP's own advisories page is the honest document here, and the pattern is exposure.
So the first spec to read on any QNAP isn't the CPU. It's the operating system choice, because that decides whether your data has integrity checking, snapshots, and immutable storage, or just a filesystem with a sync job.
the mechanics
The TS-464 is a 4-bay with an Intel Celeron N5095, four cores bursting to 2.9GHz, 8GB of DDR4 soldered in, and two 2.5GbE ports that trunk to 589 MB/s in QNAP's own testing, which is 10GbE-class throughput without buying a network card. Two M.2 2280 PCIe Gen 3 slots take NVMe for cache or a Qtier storage pool, and there's a PCIe Gen 3 x2 slot for a 10GbE card if you ever need it. HDMI on the back, two 10Gbps USB ports with a One Touch Copy button, and up to 72TB in RAID 5. It won Wirecutter's home NAS pick in 2023, which is how most people found it.
The interesting switch is software. Out of the box it runs QTS on ext4. Since QTS 5.2.1 you can migrate to QuTS hero, QNAP's ZFS-based system, which gives you end-to-end checksumming, real snapshots, WORM immutable storage, and data reduction. On a filesystem, checksums mean silent bitrot gets caught instead of served to you at full speed. ZFS is memory hungry, and 8GB works but the deduplication features will eat it, so know that before you switch. I switched, because checksums and snapshots are the two features I care about most, and I left the RAM alone and turned off dedup.
QTS's app model is Container Station and Virtualization Station, which means this box can run Docker and actual VMs, and with a keyboard and HDMI it presents like a small desktop. That's the pitch that separates it from the Synology: it wants to be a tiny server, not an appliance.
where it breaks
Here's the thing. Every capability above is also attack surface, and QTS's app ecosystem is where QNAP's incidents lived. A box running a web console, a backup app, and a cloud discovery service has more code reachable from the network than an appliance that mostly serves files, and the 2021-2022 ransomware waves were aimed at exactly that reachability. myQNAPcloud, the default-flavored remote access path, is the first thing I turn off, because the attack pattern around it is documented and the alternative costs nothing.
The fan under sustained load is loud in the way small-server fans are, less "quiet NAS" and more hair dryer with opinions. The PCIe slot is Gen 3 x2, so the 10GbE upgrade caps under full duplex 10G speeds, fine for most, worth knowing if you're building for two workstations scrubbing video. The M.2 slots are PCIe x1 each, so don't expect flagship NVMe numbers out of them either, cache duty is the honest job.
And the price sits awkwardly: at roughly double the 2-bay Synology before drives, it's a homelab purchase pretending to be a starter purchase. My admission is that I set that client's port forward myself in 2017, years before I took the box over, because that was the standard playbook and I didn't know what I didn't know.
what to do
- Decide the OS first. If integrity matters, QuTS hero and ZFS snapshots; if you want the app store and the lighter footprint, QTS on ext4 with scheduled snapshots.
- Disable myQNAPcloud and remove every port forward. Remote access goes through Tailscale, full stop.
- 2FA on every account on the box, and the auto-update schedule on.
- Snapshots hourly on the shares that matter, and Hybrid Backup Sync to an offsite target with versioning. The snapshots are your rollback, the offsite is your survival.
- Leave the Malware Remover app for what it is: a scanner, not a strategy.
The sign shop's files survived Qlocker, then Deadbolt missed them too, and the owner never found out how close either came. The box got patched that week and retired two years later, cabinet and all.
Take the port forward down tonight.