sketchucation logo sketchucation
    • Login
    🤑 SketchPlus 1.3 | 44 Tools for $15 until June 20th Buy Now

    Validation/protection needed

    Scheduled Pinned Locked Moved Developers' Forum
    7 Posts 6 Posters 1.1k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      remus
      last edited by

      Could be a bit tricky, as everything in ruby is just plain text, so anything that another ruby can look for can be seen by a person. Perhaps if all the rubies were .rbs instead, but then youd lose a large proportion of the learning materials available to new coders 😉

      A tricky problem indeed.

      http://remusrendering.wordpress.com/

      1 Reply Last reply Reply Quote 0
      • R Offline
        remus
        last edited by

        I wouldnt think youve got much cause to worry, especially if you know the source of your ruby.

        http://remusrendering.wordpress.com/

        1 Reply Last reply Reply Quote 0
        • A Offline
          azuby
          last edited by

          The check for script modification could be done using simple checksums - MD5. All in all you need a script validating the validation script 😉

          azuby

          *error initus :: Blocks | CurrentDate | d/Code | extensionmanager | FFlipper | HideEdges | MeasuredArea | ModelHistory | PluginsHelp | PronButton | SAWSO | SCP | SU²CATT

          Bad English? PM me, correct me. :smile:**

          1 Reply Last reply Reply Quote 0
          • M Offline
            mattg
            last edited by

            Modelhead you worry too much. That's why you've lost all your hair!

            1 Reply Last reply Reply Quote 0
            • K Offline
              kwistenbiebel
              last edited by

              I don't know zip about coding, but maybe Google could implement some sort of malware ('mal code'?) detector for ruby plugins in SU7. Some sort of routine that warns you whenever 'possible' harmful code is about to be compiled...

              It could work like the 'No script' blocker add-on for Firefox, a system that lets the user decide to give permission to run this or that particular code...

              Don't know if this makes sense, I am completely code ignorant, besides some stuff we had to do in high school in Basic and TurboPascal 😆 ...

              1 Reply Last reply Reply Quote 0
              • R Offline
                RickW
                last edited by

                Basically, there are two bad things that could happen with a malware ruby:

                1. Mess up your model (either by adding rogue geometry or deleting everything and saving/closing the file)
                2. Hard drive attacks:

                a. Install a virus/trojan/other payload
                b. Collect personal information
                c. Destroy files
                The problem with trying to block either of these things from happening is that it would also prevent legitimate scripts from working. For example, Windowizer would be flagged for creating "rogue" geometry and PageExIm would be flagged for hard drive access.

                The best protection is to know your source, but I understand the concern. Todd and I have been thinking about what we can do at Smustard (for more than just security issues), and one option is server-based plugins. We're exploring other options as well, but it takes time to make these things happen. Meanwhile, if you get a script and wonder if it is "harmless", just post it and one of us ruby guys will look at it.

                RickW
                [www.smustard.com](http://www.smustard.com)

                1 Reply Last reply Reply Quote 0
                • jujuJ Offline
                  juju
                  last edited by

                  Fortunately Smustard has the MySmustard plugin to help one track updates to their scripts, to me this already works like a validation system of sorts, kinda moot as a pure validation system for Smustard ATM since you get the scripts from Smustard in the first place.

                  It's the idea that counts, a master data register of the scripts out there and SU checks it (MD5 checksums verification on the server database would help) everytime it starts up, maybe even report new scripts and analyse them in a kind of SAFE MODE before running them.

                  I suppose it doesn't help people much that use SU offline, thus some kind of encrypted database file (with the MD5 checksums) distributed with SU for validation purposes would probably help as well. Should be easily updatable and probably wouldn't be a space hog.

                  Save the Earth, it's the only planet with chocolate.

                  1 Reply Last reply Reply Quote 0
                  • 1 / 1
                  • First post
                    Last post
                  Buy SketchPlus
                  Buy SUbD
                  Buy WrapR
                  Buy eBook
                  Buy Modelur
                  Buy Vertex Tools
                  Buy SketchCuisine
                  Buy FormFonts

                  Advertisement