Re: http://klik.berlios.de/

Marcin Pawlik <[email protected]>
Newsgroups gmane.comp.kde.debian
Message-ID <20040202191027.GA7629@mpmain>
On Mon, Feb 02 at 16:53, Marcin Pawlik wrote:
> On Mon, Feb 02 at 02:21, Kurt Pfeifle wrote:
>> Hi, guys,
>> 
>> any of you running Knoppix should have a look at this:
>> 
>>     ˙http://klik.berlios.de/
> 
> [...]
> 
>> Really, really cool stuff...
> 
> Yes, looks useful. And dangerous. 

[...]

I received a mail from the author. Here it is along with my response:

#v+
On Mon, Feb 02 at 10:25, probono wrote:
> Hi Marcin,
> 
> I just read your post on
> http://marc.theaimsgroup.com/?l=kde-debian&m=107573724232240&w=2
> 
> I am the developer of klik.
>
> I am concerned really about security, too. That is why I have encoded
> the klik client with shc because I really don't know how to to the
> "sandboxing" stuff you are talking about. I just felt encrypting it
> with shc was the best I could to in order to make it a bit more
> secure.

Thank you for your fast response and klik client source in the second
mail. I apologize once again for being so suspicious.

As I said my knowledge about the security is very limited but I don't
think hiding the way an application works can help. Tools like shc may
be useful to protect commercial products from being examined or abused,
but this is not a case here. I believe a complete contradiction
- making it well designed and opened is a better way.

> If you want to help me on this, please drop me a line.

I'm dramatically short of time now, and this is not an easy task I'm
afraid. The first thing I thought about are GPG signed recipes with an
option to see their contents before execution. Of course there is much
more that can be done since unfortunately client-side execution is
always one of the most promising crackers' targets.

OTOH this is also something very useful and worth to be developed. 
We had a thread about similar topic on kde-debian list started here:
http://marc.theaimsgroup.com/?l=kde-debian&m=107446028313281&w=2. 
So maybe Kevin will also be interested...

P.S. Do you mind if I forward this mail to kde-debian list as an
explanation for my questions?
#v-

Regards,

-- 
Marcin Pawlik
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.