![]() |
#16 |
Guru
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 895
Karma: 4383958
Join Date: Nov 2007
Device: na
|
It may be a local only exploit, but you do need to consider that any user level remote exploit could then piggy back on this to gain full root access. Granted there's likely numerous local level exploits in other apps and it was the remote user level bug that was the really major one.
However, one poster in that bug thread did hit an important issue, calibre or the website should warn users that installing the mount helper will allow any local user to gain root access to the machine. Since as everyone else points out here, for most users they won't care about that, so long as it's local and not remote, but at least those who do care are now informed and can remedy things on their own. |
![]() |
![]() |
#17 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,888
Karma: 5875940
Join Date: Dec 2007
Device: PRS505, 600, 350, 650, Nexus 7, Note III, iPad 4 etc
|
Quote:
![]() ![]() And the golden rule... if you don't like it then don't use it... and how many calibre users share their hardware with the entire world... or don't you trust yourselves not to hack your own computer... or maybe get a life... ![]() |
|
![]() |
![]() |
#18 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,592
Karma: 204624552
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
Quote:
![]() That's the part of this whole "attention-whoring-masquerading-as-sincere-security-analysis--we're-just-looking-out-for-the-average-peeps-here" tactic that I find the most galling. Wikipedia entries on the same day as the bug report, for god's sake?! Reddit? This forum? How is this NOT a vendetta? Actually, I suspect that an alternative, commercial, calibre-like application is soon to be revealed somewhere on the internet. That's what usually follows quickly on the heels of this type of smear campaign; "Oh, BTW... here'$ a $ecure alternative." ![]() Last edited by DiapDealer; 11-04-2011 at 12:39 PM. |
|
![]() |
![]() |
#19 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,337
Karma: 4000000
Join Date: Oct 2008
Location: Paris
Device: Cybooks; Sony PRS-T1
|
Quote:
|
|
![]() |
![]() |
#20 | |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
Quote:
It was only then, unfortunately for Kovid, that the bug report went viral (such as here and here) as an example of how not to handle bug reports. |
|
![]() |
![]() |
#21 |
Evangelist
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 416
Karma: 1045911
Join Date: Sep 2011
Location: Cape Town, South Africa
Device: Kindle 3
|
|
![]() |
![]() |
#22 | |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
Quote:
![]() It's highly unlikely, while there has been lots of grumblings of forking calibre since this happened, I really can't see anyone doing it, let alone trying to charge for it. |
|
![]() |
![]() |
#23 |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
How is that being mad? elcreative, made assuptions that were in correct as to how this went down and I corrected him or her.
If I was to be mad about anything it'd be for the general lack of regard for the issue and a subset of calibre users (of which I am not). |
![]() |
![]() |
#24 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,592
Karma: 204624552
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
Quote:
|
|
![]() |
![]() |
#25 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,388
Karma: 14190103
Join Date: Jun 2009
Location: Berlin
Device: Cybook, iRex, PB, Onyx
|
splat, just for the sake of fairness and clearness: are you this Jason Donenfeld from the bug track? Thanks.
|
![]() |
![]() |
#26 |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
I want to know that when (not if*) bugs for the platform I use are found, they will be taken seriously and fixed rather than have the messenger ignored. At the moment, the way this is being handled it doesn't give me much faith.
Had Kovid been open to suggestions (repeatead offers of help from Dan Rosenburg) in the first place instead of offering sarcastic replies and ignoring people this would probably not have blown up in the way that it has. *no system is bug free Last edited by splat; 11-04-2011 at 01:21 PM. |
![]() |
![]() |
#27 |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
|
![]() |
![]() |
#28 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,592
Karma: 204624552
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
So how, exactly, did you happen across this particular (previously private) bug report for an open-source ebook management application that you admittedly don't use yourself?
|
![]() |
![]() |
#29 |
Fool
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 468
Karma: 4113712
Join Date: Feb 2003
Device: Kindle: Voyage,PW1,KOA, Kobo: Clara Colour, Nook GLP, Pocketbook verse
|
This thread--and the bug report--seem to have crossed two different worldviews.
One group wants a program that works. Just works. And they don't need to understand the guts or the complexities unless they want to. The other does not want any program to exist if in some circumstances on some machines in some environments anyone with enough technical knowledge might get higher access privileges than are granted to the program. I suppose there is a class of circumstances where the second worldview is sensible. But on this forum, and for the vast majority of Calibre users, I'm betting the first view prevails. Security always comes with inconvenience. Convenience always comes with insecurity. Calibre is not an OS. Get over it. (I guess you can sense my worldview.) |
![]() |
![]() |
#30 | |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
Quote:
Re-read what I said, I never said I did not use calibre, I said I was not one of the affected users (as I do not use Linux). Last edited by splat; 11-04-2011 at 01:52 PM. Reason: correct number of days |
|
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Calibre bug? | pedz | Calibre | 1 | 04-02-2010 11:48 PM |
Calibre exe deleted by Norton Internet Security 2010 | FoolforBooks | Calibre | 18 | 11-24-2009 03:10 PM |
Calibre 0.4.73 Bug? | JuristDoctor | Calibre | 12 | 06-24-2008 03:09 PM |
Leo Laporte/Security Now Notice the Charging Bug | flumbo | Sony Reader | 2 | 04-28-2007 11:51 PM |