r3wp [groups: 83 posts: 189283]
  • Home
  • Script library
  • AltME Archive
  • Mailing list
  • Articles Index
  • Site search
 

World: r3wp

[Plugin-2] Browser Plugins

JoshM
3-May-2006
[49]
Each plugin instance launches a new thread so viewdll has to be able 
to handle that
Henrik
3-May-2006
[50]
are there any security issues? infinite popups or anything left that 
might bring it out of control?
JoshM
3-May-2006
[51]
i don't know, have you found any? :)
Graham
3-May-2006
[52]
those exist already
JoshM
3-May-2006
[53]
you've had 2 years ;-)
Graham
3-May-2006
[54]
Infinite popups are blocked ..I think there's a limit.
JoshM
3-May-2006
[55x4]
Seriously, I'd love a list of any security problems that you guys 
have encountered as you've used the plugin.
And please feel free to hack at it, try exploting buffer overruns, 
etc.
We want to catch those things now.
just please send me a note privately if you find one :)
Graham
3-May-2006
[59]
I haven't seen any, but then I've not tried to break security ..
Henrik
3-May-2006
[60]
no, we're nice people
Graham
3-May-2006
[61]
My chat client also runs in the plugin ...
JoshM
3-May-2006
[62]
oh cool, can you send me the URL? i'd love to check it out
Carl
3-May-2006
[63]
Working on that.
Graham
3-May-2006
[64x3]
though I note I had to run a dummy window first otherwise the client 
run inside the browser window instead of as a separate window
http://www.compkarori.com/reb/
If the chat client wipes your hard drive, consider it a security 
exploit!
Carl
3-May-2006
[67]
Problem: the security certificate for IE has expired (about 2 months 
ago). We will need to renew it.
JoshM
3-May-2006
[68]
until then, we can't post the 1.3.2 version.
Carl
3-May-2006
[69]
Anyone have a good low-cost source of certificates?
JoshM
3-May-2006
[70]
code signing certificates
Graham
3-May-2006
[71]
if you post it, it won't install under IE now?
Carl
3-May-2006
[72]
Otherwise, we'll go back to Thawte.
JoshM
3-May-2006
[73]
no, it won't install without a valid certificate.
Carl
3-May-2006
[74x3]
(The vender certification process can take a lot of time... they 
have to verify that we are "good guys".)
So, we're probably locked into Thawte.
Otherwise it can take a week.
Graham
3-May-2006
[77]
has it been tested under IE7 as well?
JoshM
3-May-2006
[78x2]
No, I don't have it installed...if someone does, please tell me how 
it goes.
graham, how do i register for an account with your chat program?
Graham
3-May-2006
[80x2]
at the login page, there's a register button.
I guess Eliza wasn't too helpful?
JoshM
3-May-2006
[82x4]
no ha ha that was funny
We're trying to get the mozilla stuff posted. That's not packaged 
for installation yet (that's 5% of the missing 10%).
But you can copy the files to FireFox\plugins, so it's not that hard.
OK, so I want to get a discussion started. What do you guys want 
to see in the next version of the plugin?
Henrik
3-May-2006
[86]
well, I'm not sure what the level of ambition is for the next version?
JoshM
3-May-2006
[87]
1.3.2 is going out as-is, just an upgrade to the latest rebol viewdll.
Henrik
3-May-2006
[88]
but at some point it'll be essential to run encapsulated scripts 
and use secure connections
JoshM
3-May-2006
[89]
1.3.3 is a feature upgrade, so i'm open to ideas...as long as it 
doesn't rely on something in rebol 3, we can look at it.
Henrik
3-May-2006
[90]
is it in any way tied in with the SDK? is it possible to do /pro 
or /command stuff?
JoshM
3-May-2006
[91]
Not sure on that, I need to check with Carl....I think I understand 
your overall question though, can we make a version of the plugin 
that supports pro/command right?
Henrik
3-May-2006
[92]
I need the plugin for an application that could potentially be used 
for a few thousand users in an open enterprise environment, but signed 
scripts and security are essential there.
JoshM
3-May-2006
[93x3]
got it. we'd have to look at some sort of licensing.
maybe have rebol in the plugin download a license from a web server 
or something like that.
we'd have to figure out a way to prevent others from using your license.
Graham
3-May-2006
[96x3]
A way to protect plugin source code
A way to add higher order encryption
is a must...