https

nochjemand
nochjemand
Joined: 6 May 05
Posts: 28
Credit: 402401
RAC: 0
Topic 191883

Hi all,

I think a possibility to verify WUs and other downloaded files, or the connection is a great idea.

Best

Martin

Pooh Bear 27
Pooh Bear 27
Joined: 20 Mar 05
Posts: 1376
Credit: 20312671
RAC: 0

https

The BOINC software already has the ability to talk to the projects, via HTTPS. There is at least one project using it.

The issue for most projects is the cost of the certificates. These are volunteer projects, and are usually under funded. Plus there is a lot more server overhead with HTTPS.

nochjemand
nochjemand
Joined: 6 May 05
Posts: 28
Credit: 402401
RAC: 0

Hi, RE: The issue

Message 47356 in response to message 47355

Hi,

Quote:

The issue for most projects is the cost of the certificates.

100$/a. For a project like e@h no problem i think.

Quote:

These are volunteer projects, and are usually under funded. Plus there is a lot more server overhead with HTTPS.

The overhead is not so much in relation to the sheduler aso.
Unencrypted communication is very dangerous for the clients...

CU

Martin

Wurgl (speak^Wcrunching for Special: Off-Topic)
Wurgl (speak^Wc...
Joined: 11 Feb 05
Posts: 321
Credit: 140550008
RAC: 0

RE: I think a possibility

Quote:
I think a possibility to verify WUs and other downloaded files, or the connection is a great idea.

The bigger problem is, that the project-servers get hacked. When some bad guys create a working boinc malware-client, this could transform all the clients into a big botnet.

IMHO the security bottleneck are the project servers, since all the clienat softwar trusts them, regardless if HTTP or HTTPS.

nochjemand
nochjemand
Joined: 6 May 05
Posts: 28
Credit: 402401
RAC: 0

Hi, RE: The bigger

Message 47358 in response to message 47357

Hi,

Quote:

The bigger problem is, that the project-servers get hacked.

Thats worst case.
Boinc hasn't a mechanism to verfify apss WUs with gpg o.a., so i think the most possible security at this time is https.
Not the encryption - the validation of the connection...

CU

Martin

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.