Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Mar 2000
Posts: 3,594
Moderator / Template Diva
Moderator / Template Diva
Offline
Joined: Mar 2000
Posts: 3,594
Thanks, Dave_L!

I was talking to one of my buddies last night after I got off work, and he said something like this too. Each plugin gets two keys: one that is a timestamp or something, and one that is a md5 hash of my secret word and that timestamp. These are displayed to the user before he installs the plugin, and he's promted to go to my site to verify the plugin. I then have a script set up on my site where he enters both keys, the script does all the checking, and tells him whether it's valid or not. This would be an optional step, Xenon itself would still be able to install an invalid plugin, but hopefully the user would be smart enough not to install it if it shows up that its not signed properly or whatever. Part of the timestamp key would also have an identifying number that matches a certain plugin - so that when the user verifies it, when it does pass the test it will say "This is a valid key for [Plugin Name Here]" - that way the baddies can't reuse a technically valid key for every new file they make (or they can, but the user will know that's what they're doing).

Thanks again I like the plugin file contents idea, I'll see what I can do about getting that to be part of the process too, since it does seem more secure.

---Jamin


Don't put that signature in your mouth! You don't know where it's been!
Sponsored Links
Entire Thread
Subject Posted By Posted
Digital signature for files? Jamin 01/09/2003 2:19 AM
Re: Digital signature for files? Dave_L_dup1 01/09/2003 5:07 PM
Re: Digital signature for files? Jamin 01/09/2003 5:23 PM
Re: Digital signature for files? Dave_L_dup1 01/09/2003 5:24 PM

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Bill B
Bill B
Issaquah, WA
Posts: 87
Joined: December 2001
Forum Statistics
Forums63
Topics37,575
Posts293,931
Members13,824
Most Online6,139
Sep 21st, 2024
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,834
Greg Hard 4,625
Top Posters(30 Days)
Gizmo 1
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2025 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.1
(Snapshot build 20240918)