3 ms·
Not a security expert, but this is a huge code smell. Always be cautious of trusting certs of any kind, especially test/dev certs with top level privileges lol
by BandButcher 3y ago
Not a security expert, but this is a huge code smell.
Always be cautious of trusting certs of any kind, especially test/dev certs with top level privileges lol personally i would avoid.
Based on the issue there are too many weak points and the "response" given didnt seem to care about the vulnerabilities or user concerns, only said why its needed...
The issue poster was smart in running in a sandbox and comparing files.
- BandButcher 3y agoNever heard of this repo or library, but in the readme: "Yet another remote desktop software, written in Rust. Works out of the box, no configuration required. You have full control of your data, with no concerns about security".... Yikes. Please don't believe in every repo face value. Your best bet is to generate your own certs (https://github.com/FiloSottile/mkcert https://github.com/FiloSottile/mkcert) and sign the dlls yourself.
- MPlus88 3y ago[dead]