Forum: Poser - OFFICIAL


Subject: Content Paradise Security Issues: SSL Bug In Python

CyberStretch opened this issue on Sep 05, 2002 ยท 12 posts


CyberStretch posted Sat, 07 September 2002 at 3:52 PM

Attached Link: Windows binary missing SSL

/P

The link above is the direct link to the bug report. This is the same URL that was placed in the opening post, but not made into a link.

"Also, why would they use what is in Windows more of a scripting language than a programming one to buy stuff securely?"

That is one of the details I am trying to find out, if I ever get a response. The EGISYS PDF clearly states "Native user interface on Python basis in Poser.", which to me would mean that the interface in P5 to Content Paradise is, in fact, Python-based.

If the currently shipping P5 product is Windows-based [verified], and the P5 CP interface is Pyhton-based [apparently verified by EGISYS' PDF], and the Windows Pyhton binary (executable) does not include SSL support [verified through Source Forge], then one could make the logical connection that: Any SSL connection attempted by P5's CP room that uses the affected Windows Python binary would be insecure.

Here again, I invite CL to comment and allay the concerns. However, given the severe nature of this bug and its implications, and not a word from a CL or EGISYS representative other than "Content Paradise is secure" (especially when the technical details were apparently unknown to the individual making the statement), one has to presume the worst-case scenario from a security perspective.