Security bulletins and notification via e-mail

Ideas for enhancements to the software
Post Reply
cornflake
Posts: 231
Joined: Fri May 13, 2011 5:44 pm

Security bulletins and notification via e-mail

Post by cornflake » Wed Aug 13, 2014 1:33 am

I would like security bulletins and to receive notification of them via e-mail. For example if something in Sandboxie is vulnerable I would like it if you could e-mail me. I am already a customer and you have my e-mail. I have several computers and on many of them I don't plan to update Sandboxie unless the version I'm using is vulnerable. I've found it difficult to figure out what version, if any, is vulnerable. I posted a related question here:
I'm using Sandboxie 4.08. Is that version still secure?

Thanks

cornflake
Posts: 231
Joined: Fri May 13, 2011 5:44 pm

Re: Security bulletins and notification via e-mail

Post by cornflake » Sat Mar 07, 2015 10:20 pm

Is it really just me? I just heard about this hard link vulnerability and it was fixed weeks ago. It would have been nice to have some e-mail notice or something like, hey, there's a vulnerability in sandboxie! Really I don't think this is too unreasonable. Thanks

Craig@Invincea
Sandboxie Support
Sandboxie Support
Posts: 3523
Joined: Thu Jun 18, 2015 3:00 pm
Location: DC Metro Area

Re: Security bulletins and notification via e-mail

Post by Craig@Invincea » Thu Jul 09, 2015 2:03 pm

cornflake wrote:Is it really just me? I just heard about this hard link vulnerability and it was fixed weeks ago. It would have been nice to have some e-mail notice or something like, hey, there's a vulnerability in sandboxie! Really I don't think this is too unreasonable. Thanks
For now, I would advise you to regularly check the Change logs http://www.sandboxie.com/?VersionChanges And monitor the forum. If it's something major, it'll be posted here first. We don't maintain a list of user emails.

cornflake
Posts: 231
Joined: Fri May 13, 2011 5:44 pm

Re: Security bulletins and notification via e-mail

Post by cornflake » Thu Jul 09, 2015 2:18 pm

Craig@Invincea wrote:
cornflake wrote:Is it really just me? I just heard about this hard link vulnerability and it was fixed weeks ago. It would have been nice to have some e-mail notice or something like, hey, there's a vulnerability in sandboxie! Really I don't think this is too unreasonable. Thanks
For now, I would advise you to regularly check the Change logs http://www.sandboxie.com/?VersionChanges And monitor the forum. If it's something major, it'll be posted here first. We don't maintain a list of user emails.
Thanks for your reply. Even if you don't maintain a user list you could make one. You have my e-mail associated with my license for example, and also you have my e-mail associated with my account on this forum. Or you could just make a separate list and have a form where people could sign up. I really think it's a lot to do to have to go through the forum posts to find the latest security issue. I'm just not going to do that every day although I do check the forums occasionally. If you had a bulletin with the latest information, and I received an e-mail notification, we could react to that much faster. That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.

Dun
Posts: 350
Joined: Mon Jun 23, 2014 5:00 am
Location: Poland

Re: Security bulletins and notification via e-mail

Post by Dun » Thu Jul 09, 2015 3:28 pm

cornflake wrote:That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.
+1 To the thread so users can subscribe to get email notifications
Sandboxie 5.19.4 personal lifetime license user || Win10 x64 Pro CU (up to date) || ESET SS 10+ x64 || AppGuard 4+ || Firefox 54+ x64 || UAC on

Craig@Invincea
Sandboxie Support
Sandboxie Support
Posts: 3523
Joined: Thu Jun 18, 2015 3:00 pm
Location: DC Metro Area

Re: Security bulletins and notification via e-mail

Post by Craig@Invincea » Tue Jul 14, 2015 9:01 am

Dun wrote:
cornflake wrote:That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.
+1 To the thread so users can subscribe to get email notifications
A security thread is an idea. As for the emails we collect. Yes, we have it from the forum registrations and Cleverbridge would have it from the orders from licensing.

Craig@Invincea
Sandboxie Support
Sandboxie Support
Posts: 3523
Joined: Thu Jun 18, 2015 3:00 pm
Location: DC Metro Area

Re: Security bulletins and notification via e-mail

Post by Craig@Invincea » Wed Aug 26, 2015 2:15 pm

Dun wrote:
cornflake wrote:That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.
+1 To the thread so users can subscribe to get email notifications
Security Sticky thread has been created..http://forums.sandboxie.com/phpBB3/view ... 11&t=21656

Dun
Posts: 350
Joined: Mon Jun 23, 2014 5:00 am
Location: Poland

Re: Security bulletins and notification via e-mail

Post by Dun » Wed Aug 26, 2015 6:23 pm

Thank you, already subscribed :)
Sandboxie 5.19.4 personal lifetime license user || Win10 x64 Pro CU (up to date) || ESET SS 10+ x64 || AppGuard 4+ || Firefox 54+ x64 || UAC on

Craig@Invincea
Sandboxie Support
Sandboxie Support
Posts: 3523
Joined: Thu Jun 18, 2015 3:00 pm
Location: DC Metro Area

Re: Security bulletins and notification via e-mail

Post by Craig@Invincea » Thu Aug 27, 2015 9:43 am

Dun wrote:Thank you, already subscribed :)
You're welcome. Hopefully, its a dull thread. :wink:

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest