The Daily Static
  The Daily Static
UF Archives
Register
UF Membership
Ad Free Site
Postcards
Community

Geekfinder
UFie Gear
Advertise on UF

Forum Rules
& FAQ


Username

Password


Create a New Account

 
 

Back to UserFriendly Strip Comments Index

Glaring security hole: by RetiQlum22005-06-18 01:02:44
  Tricky... by Red_Wolf 2005-06-18 03:56:51
I only watched their flash demo, but did not try to install the program. So, I am guessing, but I suspect that all of this only works as shown if the PC in question is not password protected (i.e. set to "auto-login", or whatever you call it under Windoze...).

I would expect that if the computer requires password protection, you would have to first make a connection to your PC through the gotomypc.com portal, then over a secure connection transfer your password to your machine. In that respect, at least on principle it is not any less secure than an SSH connection. So, unless you suspect gotomypc.com to have a backdoor in their software, they would never get to know the domain password of your LAN.

Furthermore, to install the gotomypc.com software presumably will require administrator privileges, so no user could install it without their sysops knowing.

Finally, as I said, I have not tried it yet, but I would certainly expect our firewall to intercept the gotomypc.com communications by default.

My main concern is therefore not so much corporate networks, where the sysadmins presumably know what they are doing, but gotomypc.com being used by home users, possibly new to the internet and its dangers, who then due to lack of understanding open their PCs wide to the outside world...

But that's me only guessing...
[ Reply ]

 

[Todays Cartoon Discussion] [News Index]

Come get yer ARS (Account Registration System) Source Code here!
All images, characters, content and text are copyrighted and trademarks of J.D. Frazer except where other ownership applies. Don't do bad things, we have lawyers.
UserFriendly.Org and its operators are not liable for comments or content posted by its visitors, and will cheerfully assist the lawful authorities in hunting down script-kiddies, spammers and other net scum. And if you're really bad, we'll call your mom. (We're not kidding, we've done it before.)