<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"
	>
<channel>
	<title>Comments on: Parallels security issue?</title>
	<atom:link href="http://aralbalkan.com/841/feed" rel="self" type="application/rss+xml" />
	<link>http://aralbalkan.com/841</link>
	<description>Passionate geekisms.</description>
	<lastBuildDate>Tue, 22 May 2012 18:33:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Markus Zeller</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-191567</link>
		<dc:creator>Markus Zeller</dc:creator>
		<pubDate>Fri, 24 Oct 2008 12:00:41 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-191567</guid>
		<description>I doubleclicked a *.sql file and it opened with Notepad in Windows inside Parallels. Then I was absolutely shocked being able to see ALL the files of my Mac - even the system files.

So made some searches and found this post and read the statement of the Paralles worker.

Then I decided to do some tests. Of course I love my TimeMachine saving my files and bring it back in case of failure. Now, I copied some files from /bin and other important folders to the Windows disk. I could READ them all and SAVE over the copies, but NOT the originals on my Mac.

My conclusion:

It is quite safe and in case of Trojans only documents could be corrupted. Security is also belonging to the user - so don&#039;t install any shit! If it installs a virus (is there any known??!) to my Mac I need to start the &quot;app&quot; by myself and Finder notes me when I first start an app I never did before and asks me to trust the source. At least then, it&#039;s my task to use my brain.</description>
		<content:encoded><![CDATA[<p>I doubleclicked a *.sql file and it opened with Notepad in Windows inside Parallels. Then I was absolutely shocked being able to see ALL the files of my Mac &#8211; even the system files.</p>
<p>So made some searches and found this post and read the statement of the Paralles worker.</p>
<p>Then I decided to do some tests. Of course I love my TimeMachine saving my files and bring it back in case of failure. Now, I copied some files from /bin and other important folders to the Windows disk. I could READ them all and SAVE over the copies, but NOT the originals on my Mac.</p>
<p>My conclusion:</p>
<p>It is quite safe and in case of Trojans only documents could be corrupted. Security is also belonging to the user &#8211; so don&#8217;t install any shit! If it installs a virus (is there any known??!) to my Mac I need to start the &#8220;app&#8221; by myself and Finder notes me when I first start an app I never did before and asks me to trust the source. At least then, it&#8217;s my task to use my brain.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Possible security issue with Parallels &#171; noah little</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-75528</link>
		<dc:creator>Possible security issue with Parallels &#171; noah little</dc:creator>
		<pubDate>Mon, 08 Oct 2007 11:17:35 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-75528</guid>
		<description>[...] Possible security issue with&#160;Parallels February 13, 2007 at 11:49 am &#124; In tech notes and tools &#124; Tags: mac, parallels From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</description>
		<content:encoded><![CDATA[<p>[...] Possible security issue with&nbsp;Parallels February 13, 2007 at 11:49 am | In tech notes and tools | Tags: mac, parallels From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dkp</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10640</link>
		<dc:creator>dkp</dc:creator>
		<pubDate>Fri, 16 Feb 2007 19:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10640</guid>
		<description>Actually, I am the same dkp. Anyway, email addresses of the form username site@blablabla.com will fail. The  site component is the apparent problem. Plus&#039;ing an email name is a means of tracking where spammers find your address. Everything from the   to but not including the @ are ignored by the mail delivery systems but it should be preserved.

I also did not like serv&#039;s response and said as much in the forum. The good news is with the build 3170 RC3 release the default is to disable the global share. It still seems like a lame way to provide the functionality but the &#039;high astonishment factor&#039;, to quote Mike Cowlishaw, is gone.</description>
		<content:encoded><![CDATA[<p>Actually, I am the same dkp. Anyway, email addresses of the form username <a href="mailto:site@blablabla.com">site@blablabla.com</a> will fail. The  site component is the apparent problem. Plus&#8217;ing an email name is a means of tracking where spammers find your address. Everything from the   to but not including the @ are ignored by the mail delivery systems but it should be preserved.</p>
<p>I also did not like serv&#8217;s response and said as much in the forum. The good news is with the build 3170 RC3 release the default is to disable the global share. It still seems like a lame way to provide the functionality but the &#8216;high astonishment factor&#8217;, to quote Mike Cowlishaw, is gone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pauline McNamara @ NTE &#187; Blog Archive &#187; Possible security issue with Parallels</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10459</link>
		<dc:creator>Pauline McNamara @ NTE &#187; Blog Archive &#187; Possible security issue with Parallels</dc:creator>
		<pubDate>Tue, 13 Feb 2007 10:49:11 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10459</guid>
		<description>[...] From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</description>
		<content:encoded><![CDATA[<p>[...] From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aral</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10366</link>
		<dc:creator>aral</dc:creator>
		<pubDate>Mon, 12 Feb 2007 10:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10366</guid>
		<description>Hi dkp (not the one from the forums, I&#039;m assuming). I read serv&#039;s response but don&#039;t  find it satisfactory. Later in the thread he says that that it&#039;s his personal opinion and shouldn&#039;t be taken as the official response from Parallels. 

When you disable the global share, it&#039;s been my experience that you can still cut and paste files so, at least for me, the additional convenience is not worth the security risk. I agree with dkp (on the forums) that security should be the primary consideration here and that virtual machines should be sandboxed from the host machine. 

Regarding the email issue -- it&#039;s the first time I&#039;ve heard of it. If you email me (my first name at the name of this domain), I&#039;ll look into it with your email address and share the fix, once I have it, with the k2 people.</description>
		<content:encoded><![CDATA[<p>Hi dkp (not the one from the forums, I&#8217;m assuming). I read serv&#8217;s response but don&#8217;t  find it satisfactory. Later in the thread he says that that it&#8217;s his personal opinion and shouldn&#8217;t be taken as the official response from Parallels. </p>
<p>When you disable the global share, it&#8217;s been my experience that you can still cut and paste files so, at least for me, the additional convenience is not worth the security risk. I agree with dkp (on the forums) that security should be the primary consideration here and that virtual machines should be sandboxed from the host machine. </p>
<p>Regarding the email issue &#8212; it&#8217;s the first time I&#8217;ve heard of it. If you email me (my first name at the name of this domain), I&#8217;ll look into it with your email address and share the fix, once I have it, with the k2 people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dkp</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10358</link>
		<dc:creator>dkp</dc:creator>
		<pubDate>Mon, 12 Feb 2007 00:57:17 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10358</guid>
		<description>The global share requirement was explained by &quot;serv&quot; from Parallels here:

http://forum.parallels.com/post41289-49.html

I&#039;ve not tried it as it isn&#039;t anything I would need, but others will certainly appreciate the convenience.

BTW, your comment page does not accept legitimate mail addresses.</description>
		<content:encoded><![CDATA[<p>The global share requirement was explained by &#8220;serv&#8221; from Parallels here:</p>
<p><a href="http://forum.parallels.com/post41289-49.html" rel="nofollow">http://forum.parallels.com/post41289-49.html</a></p>
<p>I&#8217;ve not tried it as it isn&#8217;t anything I would need, but others will certainly appreciate the convenience.</p>
<p>BTW, your comment page does not accept legitimate mail addresses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Savvas</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10339</link>
		<dc:creator>Savvas</dc:creator>
		<pubDate>Sun, 11 Feb 2007 14:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10339</guid>
		<description>I couldn&#039;t agree more Aral.
My current problem is that some of win apps(Flash, Flex Builder, IE, Acrobat) when running in XP don&#039;t show up on dock and i can&#039;t keep them there in order to open them directly..

(you select the application you want in the dock, control-click and select Add to favorites from the context menu.)

Any ideas?</description>
		<content:encoded><![CDATA[<p>I couldn&#8217;t agree more Aral.<br />
My current problem is that some of win apps(Flash, Flex Builder, IE, Acrobat) when running in XP don&#8217;t show up on dock and i can&#8217;t keep them there in order to open them directly..</p>
<p>(you select the application you want in the dock, control-click and select Add to favorites from the context menu.)</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aral</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10323</link>
		<dc:creator>aral</dc:creator>
		<pubDate>Sun, 11 Feb 2007 01:04:13 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10323</guid>
		<description>Hi Savvas,

I just checked and I can still drag and drop. Not entirely sure what d&amp;d functionality I&#039;ve lost. Turning this option off seems to be a good idea in general.</description>
		<content:encoded><![CDATA[<p>Hi Savvas,</p>
<p>I just checked and I can still drag and drop. Not entirely sure what d&#038;d functionality I&#8217;ve lost. Turning this option off seems to be a good idea in general.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: val brown</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10319</link>
		<dc:creator>val brown</dc:creator>
		<pubDate>Sat, 10 Feb 2007 19:20:34 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10319</guid>
		<description>Welcome to the wonderful world of Windows.  Jump in the pool, you get wet.  You don&#039;t want to get wet -- AT ALL -- then don&#039;t jump in the pool.  For me, I&#039;ve been working with Windows, Mac, Unix etc for quite a while now and am very comfortable in switching amongst them so Parallels&#039; transparent interoperability is wonderful.

i just remember it&#039;s Windows and partly that involves remembering that the vast majority of OS implementations in the world actually ARE Windows.  So there are benefits to it, despite the risks.</description>
		<content:encoded><![CDATA[<p>Welcome to the wonderful world of Windows.  Jump in the pool, you get wet.  You don&#8217;t want to get wet &#8212; AT ALL &#8212; then don&#8217;t jump in the pool.  For me, I&#8217;ve been working with Windows, Mac, Unix etc for quite a while now and am very comfortable in switching amongst them so Parallels&#8217; transparent interoperability is wonderful.</p>
<p>i just remember it&#8217;s Windows and partly that involves remembering that the vast majority of OS implementations in the world actually ARE Windows.  So there are benefits to it, despite the risks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Savvas</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10259</link>
		<dc:creator>Savvas</dc:creator>
		<pubDate>Fri, 09 Feb 2007 08:53:29 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10259</guid>
		<description>Neither do i.
It asks me to connect to &quot;my machine&quot; as Guest..
Aren&#039;t you able to drag and drop?</description>
		<content:encoded><![CDATA[<p>Neither do i.<br />
It asks me to connect to &#8220;my machine&#8221; as Guest..<br />
Aren&#8217;t you able to drag and drop?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

