Jump to content


Photo

DefenseWall and software updates.


  • Please log in to reply
18 replies to this topic

#1 Ilya Rabinovich

Ilya Rabinovich

    - DefenseWall -

  • SoftSphere Technologies
  • 4,896 posts

Posted 21 January 2010 - 10:05 PM

Hi everybody!

I have an idea how to initiate software updates from within untrusted zone, but I'm in little doubts.

To implement this feature, I need to run untrusted software as trusted. But if there a password-protected DW's configuration, it will be impossible to initiate update, it will starts untrusted.

So, the question is simple- create a gate allow DW to run untrusted as trusted without password required (password security model hole) or leave it as password-protected?

#2 ruinebabine

ruinebabine

    Sen. Member

  • Active Members
  • 153 posts

Posted 21 January 2010 - 10:53 PM

QUOTE (Ilya Rabinovich @ Jan 21 2010, 11:05 PM) <{POST_SNAPBACK}>
So, the question is simple- create a gate allow DW to run untrusted as trusted without password required (password security model hole) or leave it as password-protected?

I do understand that the actual software's updating processus could be tedious at time for non-techie users of DW, but I would prefer myself not going this route (i.e. punching hole in DW) if trying to solve this issue.

EDIT: So, to answer your question, my preference would be to leave it as password-protected.

Edited by ruinebabine, 21 January 2010 - 10:57 PM.


#3 abc

abc

    Sen. Member

  • Active Members
  • 166 posts

Posted 21 January 2010 - 11:07 PM

QUOTE (ruinebabine @ Jan 21 2010, 11:53 PM) <{POST_SNAPBACK}>
So, to answer your question, my preference would be to leave it as password-protected.

+ 1

#4 CogitoErgoSum

CogitoErgoSum

    GSF mate

  • Active Members
  • 307 posts

Posted 21 January 2010 - 11:24 PM

Hello Ilya,

Please leave it password protected.


Peace & Gratitude,

CogitoErgoSum

#5 takaki

takaki

    Adv. Member

  • Active Members
  • 104 posts

Posted 22 January 2010 - 12:58 AM

QUOTE (abc @ Jan 22 2010, 12:07 AM) <{POST_SNAPBACK}>
QUOTE (ruinebabine @ Jan 21 2010, 11:53 PM) <{POST_SNAPBACK}>
So, to answer your question, my preference would be to leave it as password-protected.

+ 1

+1

#6 Savage

Savage

    Active Member

  • Active Members
  • 62 posts

Posted 22 January 2010 - 02:00 AM

QUOTE (takaki @ Jan 22 2010, 01:58 AM) <{POST_SNAPBACK}>
QUOTE (abc @ Jan 22 2010, 12:07 AM) <{POST_SNAPBACK}>
QUOTE (ruinebabine @ Jan 21 2010, 11:53 PM) <{POST_SNAPBACK}>
So, to answer your question, my preference would be to leave it as password-protected.

+ 1

+1


WTF? simple yes or no.

#7 Sacles

Sacles

    Sen. Member

  • Active Members
  • 225 posts

Posted 22 January 2010 - 09:15 AM

Hello,

I do not use a password for DW. For most users, I do not see the utility of this password. So, I'm interested for Ilya's proposition

Why not give the choice to the users?



#8 bellgamin

bellgamin

    Highly Respected Member

  • Charter Members
  • 360 posts

Posted 22 January 2010 - 09:23 AM

QUOTE (Sacles @ Jan 21 2010, 11:15 PM) <{POST_SNAPBACK}>
I do not use a password for DW.
I also don't use a PW for DW. (I have *another* way of protecting DW from being killed or tinkered with. Bwa-ha-ha winky1.gif )

QUOTE
Why not give the choice to the users?
I agree. Let it be a choice that the user can make or change when configuring DW.


#9 Sacles

Sacles

    Sen. Member

  • Active Members
  • 225 posts

Posted 22 January 2010 - 09:37 AM

QUOTE
I also don't use a PW for DW. (I have *another* way of protecting DW from being killed or tinkered with. Bwa-ha-ha

This is not the passport that will protect DW to be kill by malware. This protection should be integrated into the program DW.

#10 abc

abc

    Sen. Member

  • Active Members
  • 166 posts

Posted 22 January 2010 - 10:33 AM

currently there is no match as the score is 4-2 giullare.gif ...





Frankly, i do not know in depth how the idea has been developed but i think it is useful not break the password security model.

Therefore, if a user had set up a password to protect program settings, you might think of a pop-up in which it is explained that to complete the update process you must type password*...

QUOTE (Sacles @ Jan 22 2010, 10:37 AM) <{POST_SNAPBACK}>
QUOTE
I also don't use a PW for DW. (I have *another* way of protecting DW from being killed or tinkered with. Bwa-ha-ha

This is not the passport that will protect DW to be kill by malware. This protection should be integrated into the program DW.

you are right



* Excuse me if the concept above may seem confusing but English is not my native language..
If anyone still knows the Italian, i could always write in my native language and let others translate my concepts into a proper English evilgrin.gif ..


#11 mossman

mossman

    Adv. Member

  • Active Members
  • 97 posts

Posted 22 January 2010 - 10:44 AM

Another vote for keeping the password protection.

#12 andro

andro

    Adv. Member

  • Active Members
  • 68 posts

Posted 22 January 2010 - 03:14 PM

I think, it would be good to initiate software updates from within untrusted zone. But, of course, it depends on realization of this idea.

I don't use password protection of DW.

#13 Creer

Creer

    GSF mate

  • Active Members
  • 323 posts

Posted 22 January 2010 - 04:04 PM

QUOTE (mossman @ Jan 22 2010, 11:44 AM) <{POST_SNAPBACK}>
Another vote for keeping the password protection.

+1

#14 darthsideous666

darthsideous666

    Active Member

  • Active Members
  • 45 posts

Posted 22 January 2010 - 04:12 PM

Password protected!!

#15 demoneye

demoneye

    Sen. Member

  • Active Members
  • 233 posts

Posted 22 January 2010 - 05:40 PM

IMO password protection can do the trick with out any possibility of security hole .


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users