473,385 Members | 1,465 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,385 software developers and data experts.

ClickOnce Security Risk

Hi there,

I've discovered what I believe to be a security risk with ClickOnce. I
have only just started publishing my application using our own Trusted
certificate, before this I was using a test certificate.

The problem is that when I published a new build with the new
certificate and then updated the client on a separate machine, it didn't
even warn me that the signature did not match the previous version. Surely
this is a security risk? So basically I could create an application with
the same name / guid etc, use a test certificate with a similar company name
and then overwrite the app and the user would be none the wiser...

Unless I've missed the point somewhere along the lines of course.

Nick.
Mar 28 '08 #1
1 1271
NickP wrote:
Hi there,

I've discovered what I believe to be a security risk with
ClickOnce. I have only just started publishing my application using
our own Trusted certificate, before this I was using a test
certificate.
The problem is that when I published a new build with the new
certificate and then updated the client on a separate machine, it
didn't even warn me that the signature did not match the previous
version. Surely this is a security risk? So basically I could
create an application with the same name / guid etc, use a test
certificate with a similar company name and then overwrite the app
and the user would be none the wiser...
Unless I've missed the point somewhere along the lines of course.
I'm surprised, I have seen exactly the opposite, any change in certificate being
considered completely invalid. Did the user run the update from a shortcut on
their machine, or go to the web site again? You may have simply installed a new
program on their machine, not updated the old one.
Mar 29 '08 #2

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
by: hannes.lambrecht | last post by:
Hi, A question about clickOnce deployment. How can I make a clickOnce application with elevated permissions work, when dowloaded from the internet zone. I always get the message: "This...
4
by: markoueis | last post by:
Is there any way to embed a ClickOnce Application into the browser? I love the way ClickOnce works, but the problem is I would like it to display the windows form in the browser. I could use a...
5
by: Danny Tuppeny | last post by:
I've been playing around with ClickOnce today, and it's all good stuff. Except, that if I change my application to NOT be full trust (which seems to make very little difference to the user prompt,...
11
by: moondaddy | last post by:
I have a .net 2.0 smarclient app and am trying to deploy it to IIS where users can access it from. I created an application folder in IIS where I'm trying to deployee to. 1) When the...
1
by: Mr. Beck | last post by:
I am in the process of creating a C# ClickOnce application that will be deployed in the coming months. I was initially thinking of deploying it through Windows Installation but due to the need of...
3
by: steven deng | last post by:
I want to know when a clickonce app exits. I have code snippet below. But the Exited event is not triggered. If I change the process to Notepad.exe(see comment line), it works fine. Any suggestion...
3
by: =?Utf-8?B?Tmlrb2xheSBQb2Rrb2x6aW4=?= | last post by:
Good noon, community! Would you be so kind and help me solve my problem. I need Deploy application through ClickOnce technology. I've configuration file where I assign sensitive data about...
3
by: Ryan Liu | last post by:
hi, I like the Publish function comes with VS2008. But 3 questions remain: how to make update path to be flexiable? Because I will give those updates to my cutomers, and different cutomer will...
3
by: =?Utf-8?B?S2VuIExlbWlldXg=?= | last post by:
My clickonce app fails when the install button on the publish.htm page is clicked. User is prompted with a "Cannot Start Application" dialog. Details provided from the dialog are: PLATFORM...
1
by: CloudSolutions | last post by:
Introduction: For many beginners and individual users, requiring a credit card and email registration may pose a barrier when starting to use cloud servers. However, some cloud server providers now...
0
by: ryjfgjl | last post by:
In our work, we often need to import Excel data into databases (such as MySQL, SQL Server, Oracle) for data analysis and processing. Usually, we use database tools like Navicat or the Excel import...
0
by: taylorcarr | last post by:
A Canon printer is a smart device known for being advanced, efficient, and reliable. It is designed for home, office, and hybrid workspace use and can also be used for a variety of purposes. However,...
0
by: Charles Arthur | last post by:
How do i turn on java script on a villaon, callus and itel keypad mobile phone
0
by: ryjfgjl | last post by:
If we have dozens or hundreds of excel to import into the database, if we use the excel import function provided by database editors such as navicat, it will be extremely tedious and time-consuming...
0
by: ryjfgjl | last post by:
In our work, we often receive Excel tables with data in the same format. If we want to analyze these data, it can be difficult to analyze them because the data is spread across multiple Excel files...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.