Re: Pirated WebCat? NOT...
This WebDNA talk-list message is from 2003
It keeps the original formatting.
numero = 49766
interpreted = N
texte = Common guys.First of all, if you donıt have anything to hide, meaning to pirate yournumber, there is no need to worry.Further on, do any of you work on MacOS X? If so go ahead and installLittleSnitch this is a small application which tells you what program iscalling home (as a side note you can also block the connection).Anyhow, the point is that about every second program on my machine iscalling home and this is NOT mentioned anywhere in their documentation.It is hard for me to believe that SMSI point of doing this is to snap yourdata under your nose or anything illegal. We are NOT talking about a littlecompany with some freaks. They are just protecting their hard work over theyears and I think that is their right.btw: Did you guys ever think about that with every app you work thedeveloper knows how to crack any of your data, since they are the ones whodeveloped it in the first place!Sincerely,Nitai AventaggiatoCEOOn 25.4.2003 13:51 Uhr, Rene van der Velde
wrote:> Well this little story just convinced me NOT to upgrade to 5.0 and I'm> thinking to switch to a different platform alltogether.> > ------------------------> > On vrijdag, 25 april 2003, Kenneth Grome wrote:>>> Something that also bothers me is the apparent ability that Smith Micro has>>> to retrieve the Serial number from my server. . .what else can you retrieve?>>> If you can get this, can you read database files and decrypt credit card>>> numbers too? Let me know and try to convince me that you>> can't. . .>> >> >> They *CAN* retrieve any piece of information that is accessible to>> any webdna code on the server!>> >> All they have to do is put an internally hard-coded tcpconnect>> context into the webdna engine code, along with the related code that>> looks inside the files stored on the server, and then webdna can>> traverse your entire folder hierarchy and grab any piece of>> information it finds there, then send it to who knows where?>> >> To SMSI's server?>> To someone else's server?>> >> Yes of course this means that the credit cards, which are already>> stored unencrypted in webdna's plan text cart files and webdna>> database files, are potential targets of 'secret acquisition' by>> Smith Micro ... or worse.>> >> What could be worse?>> >> Well, possibly a disgruntled employee (or former employee) who has>> written portions of webdna's internal code, possibly adding his own>> little data grabbing snippets that deliver our customer's credit>> card data to his server, even without the knowledge of others at SMSI>> ... :(>> >> My question is not so much whether the company as a whole is honest>> enough to be trusted to allow this kind of internal data gathering>> capability to exist. Because personally I have never trusted them>> after they (PCS) promised me 50% of the revenues from the sales of>> Typhoon (which I developed with them) only to learn later that they>> would go back on their promises and cut me out of the deal. This>> illustrates a clear lack of integrity for which I have no respect>> whatsoever.>> >> And of course their repeated attempts to bully me into giving them my>> webdna.net domain when I was the first to register it and when I>> owned it long before they ever managed to get a trademark on the>> webdna character string, that is yet another unethical behavior by>> a company who seems to think we own them our trust.>> >> But regardless of these issue which I have personally had with>> PCS/SMSI over the years, I cannot help wondering just how many truly>> trustworthy people actually worked on webdna's engine code?>> >> Or how many not-so-trustworthy people may have had an opportunity to>> slip in their own versions of a 'secret data grabbing' feature that>> is completely unknown to the SMSI management???>> >> My feeling, based partially on my own experiences in dealing with>> this company and its predecessor, is that SMSI could easily have>> treated their own people with the same kind of disrespect they have>> shown me over the years. And this kind of treatment can cause really>> some people to feel, shall we say, less than happy about SMSI's>> treatment of them -- and possibly even vengeful.>> >> It wouldn't take much tweaking in the engine code by someone who>> doesn't like the fact that he didn't get his promised raise last year>> to create a very serious threat to the security of any site running>> any version of WebDNA with this code in it.>> >> Because of these issues, I feel that there is no possible way that>> SMSI will ever convince me that they can be trusted. I have>> personally had far too many bad experiences with them. It is only>> their word that we have to rely on, and that's what I continue to>> find unbelievable.>> >> I mean, does *anyone* really believe that they were NOT trying to>> sneak this feature into the software?>> >> I'm sorry but I simply do not believe that when this kind of>> 'feature' is added to software that never used to be able to do such>> a thing, it is a BIG DEAL! And if the company were truly an ethical>> company it would make every effort to report and explain this new>> feature immediately, in CAPITAL LETTERS, so everyone would be able to>> rest assured that they were not trying to hide it.>> >> Correct me if I'm wrong here, but I don't think that this is what>> SMSI did ... :(>> -- >> >> Sincerely,>> Kenneth Grome>> ------------------------------------------------------------->> My programmers will write WebDNA code for you at $27 an hour!>> ------------------------------------------------------------->> >> ------------------------------------------------------------->> This message is sent to you because you are subscribed to>> the mailing list .>> To unsubscribe, E-mail to: >> To switch to the DIGEST mode, E-mail to>> >> Web Archive of this list is at: http://webdna.smithmicro.com/>> > > > -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list .> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to> > Web Archive of this list is at: http://webdna.smithmicro.com/-- Tools to energize your businessContent Management & eBusiness SystemsComputerOil GmbH http://computeroil.com/Unionstrasse 4 info@computeroil.com8032 Zürich/SwitzerlandTel: +41 (0)43 333 1 555-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Associated Messages, from the most recent to the oldest:
Common guys.First of all, if you donıt have anything to hide, meaning to pirate yournumber, there is no need to worry.Further on, do any of you work on MacOS X? If so go ahead and installLittleSnitch this is a small application which tells you what program iscalling home (as a side note you can also block the connection).Anyhow, the point is that about every second program on my machine iscalling home and this is NOT mentioned anywhere in their documentation.It is hard for me to believe that SMSI point of doing this is to snap yourdata under your nose or anything illegal. We are NOT talking about a littlecompany with some freaks. They are just protecting their hard work over theyears and I think that is their right.btw: Did you guys ever think about that with every app you work thedeveloper knows how to crack any of your data, since they are the ones whodeveloped it in the first place!Sincerely,Nitai AventaggiatoCEOOn 25.4.2003 13:51 Uhr, Rene van der Velde wrote:> Well this little story just convinced me NOT to upgrade to 5.0 and I'm> thinking to switch to a different platform alltogether.> > ------------------------> > On vrijdag, 25 april 2003, Kenneth Grome wrote:>>> Something that also bothers me is the apparent ability that Smith Micro has>>> to retrieve the Serial number from my server. . .what else can you retrieve?>>> If you can get this, can you read database files and decrypt credit card>>> numbers too? Let me know and try to convince me that you>> can't. . .>> >> >> They *CAN* retrieve any piece of information that is accessible to>> any webdna code on the server!>> >> All they have to do is put an internally hard-coded tcpconnect>> context into the webdna engine code, along with the related code that>> looks inside the files stored on the server, and then webdna can>> traverse your entire folder hierarchy and grab any piece of>> information it finds there, then send it to who knows where?>> >> To SMSI's server?>> To someone else's server?>> >> Yes of course this means that the credit cards, which are already>> stored unencrypted in webdna's plan text cart files and webdna>> database files, are potential targets of 'secret acquisition' by>> Smith Micro ... or worse.>> >> What could be worse?>> >> Well, possibly a disgruntled employee (or former employee) who has>> written portions of webdna's internal code, possibly adding his own>> little data grabbing snippets that deliver our customer's credit>> card data to his server, even without the knowledge of others at SMSI>> ... :(>> >> My question is not so much whether the company as a whole is honest>> enough to be trusted to allow this kind of internal data gathering>> capability to exist. Because personally I have never trusted them>> after they (PCS) promised me 50% of the revenues from the sales of>> Typhoon (which I developed with them) only to learn later that they>> would go back on their promises and cut me out of the deal. This>> illustrates a clear lack of integrity for which I have no respect>> whatsoever.>> >> And of course their repeated attempts to bully me into giving them my>> webdna.net domain when I was the first to register it and when I>> owned it long before they ever managed to get a trademark on the>> webdna character string, that is yet another unethical behavior by>> a company who seems to think we own them our trust.>> >> But regardless of these issue which I have personally had with>> PCS/SMSI over the years, I cannot help wondering just how many truly>> trustworthy people actually worked on webdna's engine code?>> >> Or how many not-so-trustworthy people may have had an opportunity to>> slip in their own versions of a 'secret data grabbing' feature that>> is completely unknown to the SMSI management???>> >> My feeling, based partially on my own experiences in dealing with>> this company and its predecessor, is that SMSI could easily have>> treated their own people with the same kind of disrespect they have>> shown me over the years. And this kind of treatment can cause really>> some people to feel, shall we say, less than happy about SMSI's>> treatment of them -- and possibly even vengeful.>> >> It wouldn't take much tweaking in the engine code by someone who>> doesn't like the fact that he didn't get his promised raise last year>> to create a very serious threat to the security of any site running>> any version of WebDNA with this code in it.>> >> Because of these issues, I feel that there is no possible way that>> SMSI will ever convince me that they can be trusted. I have>> personally had far too many bad experiences with them. It is only>> their word that we have to rely on, and that's what I continue to>> find unbelievable.>> >> I mean, does *anyone* really believe that they were NOT trying to>> sneak this feature into the software?>> >> I'm sorry but I simply do not believe that when this kind of>> 'feature' is added to software that never used to be able to do such>> a thing, it is a BIG DEAL! And if the company were truly an ethical>> company it would make every effort to report and explain this new>> feature immediately, in CAPITAL LETTERS, so everyone would be able to>> rest assured that they were not trying to hide it.>> >> Correct me if I'm wrong here, but I don't think that this is what>> SMSI did ... :(>> -- >> >> Sincerely,>> Kenneth Grome>> ------------------------------------------------------------->> My programmers will write WebDNA code for you at $27 an hour!>> ------------------------------------------------------------->> >> ------------------------------------------------------------->> This message is sent to you because you are subscribed to>> the mailing list .>> To unsubscribe, E-mail to: >> To switch to the DIGEST mode, E-mail to>> >> Web Archive of this list is at: http://webdna.smithmicro.com/>> > > > -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list .> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to> > Web Archive of this list is at: http://webdna.smithmicro.com/-- Tools to energize your businessContent Management & eBusiness SystemsComputerOil GmbH http://computeroil.com/Unionstrasse 4 info@computeroil.com8032 Zürich/SwitzerlandTel: +41 (0)43 333 1 555-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Nitai @ ComputerOil
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Re:Emailer tracking (1997)
Apoligy (1997)
bug in [SendMail] (1997)
formula inside database to calculate weights (1997)
Web Developer Product Awards (1997)
Re:no [search] with NT (1997)
SiteEdit Pro Update Announcement (1997)
Public Beta for WebCatalog 4.0 is Available (2000)
shipcost (1997)
[WebDNA] hideif within a search (2009)
Make sure I understand this??? (1997)
Ok here is a question? (1997)
Date Time Oddness (1999)
Payments -> Bank Accounts (2005)
[OT] Am I an Idiot? (2004)
Why WebDNA is not popular (2002)
Multiple catalog databases and showcart (1997)
WebCat2 - Getting to the browser's username/password data (1997)
authorize.net hex coded variables (2002)
EIMS Problems (1997)