Re: http://klik.berlios.de/
Marcin Pawlik <[email protected]>
| Newsgroups | gmane.comp.kde.debian |
|---|---|
| Message-ID | <20040202191027.GA7629@mpmain> |
On Mon, Feb 02 at 16:53, Marcin Pawlik wrote: > On Mon, Feb 02 at 02:21, Kurt Pfeifle wrote: >> Hi, guys, >> >> any of you running Knoppix should have a look at this: >> >> Ëhttp://klik.berlios.de/ > > [...] > >> Really, really cool stuff... > > Yes, looks useful. And dangerous. [...] I received a mail from the author. Here it is along with my response: #v+ On Mon, Feb 02 at 10:25, probono wrote: > Hi Marcin, > > I just read your post on > http://marc.theaimsgroup.com/?l=kde-debian&m=107573724232240&w=2 > > I am the developer of klik. > > I am concerned really about security, too. That is why I have encoded > the klik client with shc because I really don't know how to to the > "sandboxing" stuff you are talking about. I just felt encrypting it > with shc was the best I could to in order to make it a bit more > secure. Thank you for your fast response and klik client source in the second mail. I apologize once again for being so suspicious. As I said my knowledge about the security is very limited but I don't think hiding the way an application works can help. Tools like shc may be useful to protect commercial products from being examined or abused, but this is not a case here. I believe a complete contradiction - making it well designed and opened is a better way. > If you want to help me on this, please drop me a line. I'm dramatically short of time now, and this is not an easy task I'm afraid. The first thing I thought about are GPG signed recipes with an option to see their contents before execution. Of course there is much more that can be done since unfortunately client-side execution is always one of the most promising crackers' targets. OTOH this is also something very useful and worth to be developed. We had a thread about similar topic on kde-debian list started here: http://marc.theaimsgroup.com/?l=kde-debian&m=107446028313281&w=2. So maybe Kevin will also be interested... P.S. Do you mind if I forward this mail to kde-debian list as an explanation for my questions? #v- Regards, -- Marcin Pawlik