Full Version : Security Issues
geckophone >>Technical and Security >>Security Issues


<< Prev | Next >>

Gecko_admin- 08-26-2004
We received a query regarding GP's security and whether or not a third party could possibly gain access to a user's machine during a conversation. As we felt that this question is likely to be of interest to all of you, we decided to post a transcript of the conversation here.

This is the original question:
QUOTE
I have a number of users asking whether or not gecko phone is safe to use.  The obviuous issue is related to that of most instant messenger programs in that while you are ingaged in a chat (either typed or VOIP ) another user could theoretically enter the chat room and possibly gain access to as much as your entire hard drive.  How is that handled with gecko and how long has gecko phone been in existence?  Your assistance would be greatly appreciated.  Thank you.


And this is the reply given by GeckoPhone's head programmer:
QUOTE
I am a GeckoPhone developer and I believe it to be fairly secure.

Some instant messanger programs do have various holes which can be exploited by hackers to gain access to other peoples machines. These exploits are usually based on buffer over-runs and other sloppy programming techniques.

GeckoPhone is quite a minimalistic peice of software and its buffers are all checked in order to prevent over-runs. Because the software is fairly simple, the chances of exploits is reduced.

The minimalism is reflected in the relatively small file size of the installer, only 500K including the graphical skin set, all codecs etc. Most other voip p2p solutions are way over 1 megabyte in size.

Obviously I can't guarantee that the software is completely secure but I've heard no reports to the contrary yet.

The software has been published for only 10 days, so obviously it has not been thouroughly -*test*-('")ed in the field yet. At the moment we have several hundred users and nobody has reported a bug (yet!!).

Hope this information helps you.



Free Forum Hosting by Forumer.comTM!