Author Topic: auto download enabled by default only for trusted sites?  (Read 5188 times)

cactusfrog

  • Posts: 390
  • Turrets: +678/-176
    • tremulous fun server offical site
auto download enabled by default only for trusted sites?
« on: December 16, 2008, 06:44:06 am »
I just thought of an idea that i think is a good one. I remember a whole thread about how auto download should be enabled by default but people rejected this because if it were to be enabled by default it would leave people subseptible to downloading viruses and other malware. Well i just thought of a way to fix this. What if instead of just the option to allow autodownloads and disallow autodownloads you could select a third option that allows auto downloads only for trusted sites like mercenary Guild and Trem central. Adding this would allow trusted auto downloads to be enabled by default because there would be a much lower chance of installing malware. THis would make severs with custom maps and mods a lot more popular.   

Archangel

  • Guest
Re: auto download enabled by default only for trusted sites?
« Reply #1 on: December 16, 2008, 06:45:31 am »
or, just sanitize the QVMs from actually being malicious?

Hendrich

  • Posts: 898
  • Turrets: +168/-149
    • TremCommands
Re: auto download enabled by default only for trusted sites?
« Reply #2 on: December 16, 2008, 09:50:16 pm »
Okay, so, how can the client even know which servers are to trust? You might say the devs could tweak thier upcoming client to do so, but what happens if the server closes and/or re-names itself, or if a server is trusted and it decides to go rouge? And why should the devs even bother for som,ethign that a noob should be aware of?

Obviously, if theres a server you would normally trust, turn autodownload on, if not, turn it off. Maybe (For the sake on an example) Amaneiu could go rouge and make the new version of his/her client allow attacking servers to hack int your PC, hell, it doesn't even have to be Amanieu. The idea of this thread just cannot work, and its too much work for the devs just for a problem that rarely happens, but the thought does count.

Sorry CactusFrog, but I don't think this idea could work.  :(

Bissig

  • Posts: 1309
  • Turrets: +103/-131
Re: auto download enabled by default only for trusted sites?
« Reply #3 on: December 17, 2008, 01:24:21 am »
Why should ANYONE, having millions of customers of unsecure default installation OSes in mind, target a few thousand trem population with a custom trojan/virus/whatever. The question is already invalid, thus there is no answer that is relevant.

Archangel

  • Guest
Re: auto download enabled by default only for trusted sites?
« Reply #4 on: December 17, 2008, 08:34:36 am »
Why should ANYONE, having millions of customers of unsecure default installation OSes in mind, target a few thousand trem population with a custom trojan/virus/whatever. The question is already invalid, thus there is no answer that is relevant.
Um, somebody in the community?

gimhael

  • Posts: 546
  • Turrets: +70/-16
Re: auto download enabled by default only for trusted sites?
« Reply #5 on: December 17, 2008, 09:44:22 am »
I think trusted download servers are the wrong approach, because someone could write a malicious qvm and get that uploaded onto a trusted server. The server owner basically has no reliable method to verify that the qvm is clean.

The only person that has a chance to verify this is the qvm builder, so signed qvms would be a better concept.

Amanieu

  • Posts: 647
  • Turrets: +135/-83
    • Amanieu
Re: auto download enabled by default only for trusted sites?
« Reply #6 on: December 17, 2008, 03:30:46 pm »
The first thing that should be done would be to fix the qvm jit compilers and interpreter. (I know a few exploits which haven't been fixed yet) Then put the whole thing in a *real* sandbox, like vx32.

About the issue of downloads: Risujin made a download prompt, but nobody is using it (Tremfusion will have it in the next release)
http://bugzilla.icculus.org/show_bug.cgi?id=3038

Although the download prompt doesn't fix the source of the problem (hacked qvms), it will shift the blame from the developer to the user, because it is their fault they downloaded a virus, even though they were warned.
Quote
< kevlarman> zakk is getting his patches from shady frenchmen on irc
< kevlarman> this can't be a good sign :P