shadowhawk2zero opened this issue on Mar 28, 2010 · 93 posts
kawecki posted Tue, 30 March 2010 at 12:52 PM
Quote - Why are you trying to get others to worry about this? You have no idea what the API is. You have no idea what the security model is. You have no idea what can and cannot be done via RPC. You have no idea whether or not the RPC server will even listen to anything from outside your computer. (By the way, it won't accept any calls from outside your computer.)
Do you know something about system programming, computers, security?
Rule #1: A vampire only can enter if you open the door.
Nobody can enter your computer if there is no way to enter, but in the moment you create an opening think that only you will use it someone else can use it too.
No thief can rob a car without doors, but if you put a door in the car, you can put locks with 2048 bytes encryptions, passwordsm alarms, gps, etc a thieve will open it, disarm the alarms and disable the gps in few seconds and car are robbed in every monent no matter how it are protected.
It is a little metaphoric and symbolic to explain the basic concepts, if you are able to understand.
Poser stuff was 100% secure in zip format (no exe installers) Poser stuff were only text files and image files, nothing executable by Windows. There only worst thing that could happen is make Poser crash loading a corrupted Poser's file. If Poser would be well done, neither a corrupted file will be able to crash it. Poser was a house with closed doors or a car without doors.
In the moment you created Python scripts you have created something executable inside Poser's content and you opened the door to the vampires. Now we need an antivirus and virus guard for Poser content. As Norton, McAffee and other antivirus maker doesn't care about Poser you are left without any protection.
I don't want to scare nobody, it is only metaphoric and hackers doesn't care about Poser stuff too. Also the damage is limited to what Python is able to do.
Microsoft did the same thing with their scripts and RPC and more, most done with the intention of Microsoft control your computer and know what you are doing, but this opened the gates of Hell and so millions and more millions of computers are infected by virus every day.
Banks when used their computers and their own networks were secure, nobody was able to enter their system. The only robbery cases were involving employers working inside the bank..
Today banks use Microsoft products and internet and every moment people have robbed their accounts from outside the bank.
If you want to make a secure system talk to me. You owe me $500 for the lesson
Stupidity also evolves!