Re: Cloud integration now works on Switch!

Matan Bareket <[email protected]> Sun, 13 Oct 2019 17:21:38 -0400
Newsgroups gmane.games.devel.scummvm
Message-ID <CAJF4eF6e0KndgkTvVxA4vxfdytz=LHp6gr34-Ccw5B1kDiSX7w@mail.gmail.com>
--===============4805400051276015039==
Content-Type: multipart/alternative; boundary="000000000000c258710594d157c2"

--000000000000c258710594d157c2
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

There's no problem supplying a copy of the CA cert as part of the package,
that's pretty common practice for cross platform applications. Thats the
simplest solution

On Sun, Oct 13, 2019 at 4:11 PM Alexander Tkachov <[email protected]>
wrote:

> Hi,
>
> We had the same problem on Android (still unfixed I believe), so you migh=
t
> as well fix that on Android then.
>
> But even though it does work, I doubt that's a proper fix, because you
> basically disabled certificate verification.
>
> I see two ways to "proper fix" that:
>
>    1. Put certificates file somewhere on user's device and pass the path
>    to it via CURLOPT_CAINFO option. We can use latest Mozilla's CA that i=
s
>    published here: https://curl.haxx.se/ca/cacert.pem
>    The "put a file on device" part isn't cool, but we can work with that.
>    Might be also turned into feature, because user would be able to repla=
ce it
>    with their own certificates, or into vulnerability, if hackers replace=
 it
>    with theirs (hackers also would need to control cloud.scummvm.org or
>    something, so I'd say it's not probable).
>    2. Build libcurl with non-OpenSSL backend, so it would have native
>    cert check (see https://curl.haxx.se/docs/ssl-compared.html).
>    That's an ideal option, but the problem is that you'd need to port
>    GnuTLS or something to Android/Switch/whatever and that seems to be he=
ll of
>    a tough thing to do.
>
>
>
> Maybe we can have this fix for now, but really intend to "proper fix" it
> in the nearest future. Not that users really care about certificate
> verification, but that is kinda the right way to do it.
>
> =E2=80=94 Alexander
>
>
>
> 14.10.2019, 02:43, "rsn8887" <[email protected]>:
>
> Hello all,
> I fixed cloud integration on the Nintendo Switch today. It now works as
> intended.
>
> I committed the fix to master branch and cherry-picked it to branch-2-1.
>
> FWIW, I am voting for a 2.1.1 release. This is a pretty big improvement
> IMO, albeit limited to this one platform.
>
> Cheers,
> rsn8887
> --
> rsn8887 [email protected]
> Patreon: https://www.patreon.com/rsn8887
> Twitter: https://twitter.com/rsn8887
> Github: https://github.com/rsn8887
> Podcast: https://retrotalk.coolatoms.org
> ,
>
> _______________________________________________
> Scummvm-devel mailing list
> [email protected]
> https://lists.scummvm.org/listinfo/scummvm-devel
>
> _______________________________________________
> Scummvm-devel mailing list
> [email protected]
> https://lists.scummvm.org/listinfo/scummvm-devel
>

--000000000000c258710594d157c2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">There&#39;s no problem supplying a copy of the CA cert as =
part of the package, that&#39;s pretty common practice for cross platform a=
pplications. Thats the simplest solution<br></div><br><div class=3D"gmail_q=
uote"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Oct 13, 2019 at 4:11 PM=
 Alexander Tkachov &lt;<a href=3D"mailto:[email protected]">alexander@tk=
achov.ru</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le=
ft:1ex"><div>Hi,</div><div>=C2=A0</div><div>We had the same problem on Andr=
oid (still unfixed I believe), so you might as well fix that on Android the=
n.</div><div>=C2=A0</div><div>But even though it does work, I doubt that&#3=
9;s a proper fix, because you basically disabled certificate verification.<=
br>=C2=A0</div><div><div>I see two ways to &quot;proper fix&quot; that:</di=
v><ol><li>Put certificates file somewhere on user&#39;s device and pass the=
 path to it via CURLOPT_CAINFO option. We can use latest Mozilla&#39;s CA t=
hat is published here: <a href=3D"https://curl.haxx.se/ca/cacert.pem" targe=
t=3D"_blank">https://curl.haxx.se/ca/cacert.pem</a><br>The &quot;put a file=
 on device&quot; part isn&#39;t cool, but we can work with that. Might be a=
lso turned into feature, because user would be able to replace it with thei=
r own certificates, or into vulnerability, if hackers replace it with their=
s (hackers also would need to control <a href=3D"http://cloud.scummvm.org" =
target=3D"_blank">cloud.scummvm.org</a> or something, so I&#39;d say it&#39=
;s not probable).</li><li>Build libcurl with non-OpenSSL backend, so it wou=
ld have native cert check (see <a href=3D"https://curl.haxx.se/docs/ssl-com=
pared.html" target=3D"_blank">https://curl.haxx.se/docs/ssl-compared.html</=
a>).<br>That&#39;s an ideal option, but the problem is that you&#39;d need =
to port GnuTLS or something to Android/Switch/whatever and that seems to be=
 hell of a tough thing to do.</li></ol></div><ol></ol><div>Maybe we can hav=
e this fix for now, but really intend to &quot;proper fix&quot; it in the n=
earest future. Not that users really care about certificate verification, b=
ut that is kinda the right way to do it.</div><div>=C2=A0</div><div>=E2=80=
=94 Alexander</div><div>=C2=A0</div><div>=C2=A0</div><div>=C2=A0</div><div>=
14.10.2019, 02:43, &quot;rsn8887&quot; &lt;<a href=3D"mailto:raist66676@gmx=
.de" target=3D"_blank">[email protected]</a>&gt;:</div><blockquote><div sty=
le=3D"overflow-wrap: break-word;">Hello all,<div>I fixed cloud integration =
on the Nintendo Switch today. It now works as intended.</div><div>=C2=A0</d=
iv><div>I committed the fix to master branch and cherry-picked it to branch=
-2-1.</div><div>=C2=A0</div><div>FWIW, I am voting for a 2.1.1 release. Thi=
s is a pretty big improvement IMO, albeit limited to this one platform.</di=
v><div>=C2=A0</div><div>Cheers,</div><div>rsn8887</div><div>--</div><div><d=
iv><div style=3D"color:rgb(0,0,0);text-decoration:none;text-indent:0px;text=
-transform:none;white-space:normal;word-spacing:0px"><div style=3D"color:rg=
b(0,0,0);text-decoration:none;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px"><div>rsn8887 <a href=3D"mailto:[email protected]=
e" target=3D"_blank">[email protected]</a></div><div>Patreon:=C2=A0<a href=
=3D"https://www.patreon.com/rsn8887" target=3D"_blank">https://www.patreon.=
com/rsn8887</a></div><div>Twitter:=C2=A0<a href=3D"https://twitter.com/rsn8=
887" target=3D"_blank">https://twitter.com/rsn8887</a><br>Github:=C2=A0<a h=
ref=3D"https://github.com/rsn8887" target=3D"_blank">https://github.com/rsn=
8887</a><br>Podcast:=C2=A0<a href=3D"https://retrotalk.coolatoms.org/" targ=
et=3D"_blank">https://retrotalk.coolatoms.org</a></div></div></div></div></=
div></div>,<p>_______________________________________________<br>Scummvm-de=
vel mailing list<br><a href=3D"mailto:[email protected]" targ=
et=3D"_blank">[email protected]</a><br><a href=3D"https://lis=
ts.scummvm.org/listinfo/scummvm-devel" target=3D"_blank">https://lists.scum=
mvm.org/listinfo/scummvm-devel</a></p></blockquote>________________________=
_______________________<br>
Scummvm-devel mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">Scummv=
[email protected]</a><br>
<a href=3D"https://lists.scummvm.org/listinfo/scummvm-devel" rel=3D"norefer=
rer" target=3D"_blank">https://lists.scummvm.org/listinfo/scummvm-devel</a>=
<br>
</blockquote></div>

--000000000000c258710594d157c2--


--===============4805400051276015039==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Scummvm-devel mailing list
[email protected]
https://lists.scummvm.org/listinfo/scummvm-devel

--===============4805400051276015039==--