<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Parallels security issue?</title>
	<atom:link href="http://aralbalkan.com/841/feed" rel="self" type="application/rss+xml" />
	<link>http://aralbalkan.com/841</link>
	<description>Changing the world through technology and oratory.</description>
	<pubDate>Fri, 21 Nov 2008 23:25:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-beta2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Markus Zeller</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-191567</link>
		<dc:creator>Markus Zeller</dc:creator>
		<pubDate>Fri, 24 Oct 2008 12:00:41 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-191567</guid>
		<description>I doubleclicked a *.sql file and it opened with Notepad in Windows inside Parallels. Then I was absolutely shocked being able to see ALL the files of my Mac - even the system files.

So made some searches and found this post and read the statement of the Paralles worker.

Then I decided to do some tests. Of course I love my TimeMachine saving my files and bring it back in case of failure. Now, I copied some files from /bin and other important folders to the Windows disk. I could READ them all and SAVE over the copies, but NOT the originals on my Mac.

My conclusion:

It is quite safe and in case of Trojans only documents could be corrupted. Security is also belonging to the user - so don't install any shit! If it installs a virus (is there any known??!) to my Mac I need to start the "app" by myself and Finder notes me when I first start an app I never did before and asks me to trust the source. At least then, it's my task to use my brain.</description>
		<content:encoded><![CDATA[<p>I doubleclicked a *.sql file and it opened with Notepad in Windows inside Parallels. Then I was absolutely shocked being able to see ALL the files of my Mac - even the system files.</p>
<p>So made some searches and found this post and read the statement of the Paralles worker.</p>
<p>Then I decided to do some tests. Of course I love my TimeMachine saving my files and bring it back in case of failure. Now, I copied some files from /bin and other important folders to the Windows disk. I could READ them all and SAVE over the copies, but NOT the originals on my Mac.</p>
<p>My conclusion:</p>
<p>It is quite safe and in case of Trojans only documents could be corrupted. Security is also belonging to the user - so don&#8217;t install any shit! If it installs a virus (is there any known??!) to my Mac I need to start the &#8220;app&#8221; by myself and Finder notes me when I first start an app I never did before and asks me to trust the source. At least then, it&#8217;s my task to use my brain.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Possible security issue with Parallels &#171; noah little</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-75528</link>
		<dc:creator>Possible security issue with Parallels &#171; noah little</dc:creator>
		<pubDate>Mon, 08 Oct 2007 11:17:35 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-75528</guid>
		<description>[...] Possible security issue with&#160;Parallels February 13, 2007 at 11:49 am &#124; In tech notes and tools &#124; Tags: mac, parallels From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</description>
		<content:encoded><![CDATA[<p>[...] Possible security issue with&nbsp;Parallels February 13, 2007 at 11:49 am | In tech notes and tools | Tags: mac, parallels From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dkp</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10640</link>
		<dc:creator>dkp</dc:creator>
		<pubDate>Fri, 16 Feb 2007 19:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10640</guid>
		<description>Actually, I am the same dkp. Anyway, email addresses of the form username site@blablabla.com will fail. The  site component is the apparent problem. Plus'ing an email name is a means of tracking where spammers find your address. Everything from the   to but not including the @ are ignored by the mail delivery systems but it should be preserved.

I also did not like serv's response and said as much in the forum. The good news is with the build 3170 RC3 release the default is to disable the global share. It still seems like a lame way to provide the functionality but the 'high astonishment factor', to quote Mike Cowlishaw, is gone.</description>
		<content:encoded><![CDATA[<p>Actually, I am the same dkp. Anyway, email addresses of the form username <a href="mailto:%73%69%74%65%40%62%6C%61%62%6C%61%62%6C%61%2E%63%6F%6D"><span id="emob-fvgr@oynoynoyn.pbz-66">site {at} blablabla(.)com</span><script type="text/javascript">
    var mailNode = document.getElementById('emob-fvgr@oynoynoyn.pbz-66');
    var linkNode = document.createElement('a');
    linkNode.setAttribute('href', "mailto:%73%69%74%65%40%62%6C%61%62%6C%61%62%6C%61%2E%63%6F%6D");
    tNode = document.createTextNode("site {at} blablabla(.)com");
    linkNode.appendChild(tNode);
    linkNode.setAttribute('id', "emob-fvgr@oynoynoyn.pbz-66");
    mailNode.parentNode.replaceChild(linkNode, mailNode);
</script></a> will fail. The  site component is the apparent problem. Plus&#8217;ing an email name is a means of tracking where spammers find your address. Everything from the   to but not including the @ are ignored by the mail delivery systems but it should be preserved.</p>
<p>I also did not like serv&#8217;s response and said as much in the forum. The good news is with the build 3170 RC3 release the default is to disable the global share. It still seems like a lame way to provide the functionality but the &#8216;high astonishment factor&#8217;, to quote Mike Cowlishaw, is gone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pauline McNamara @ NTE &#187; Blog Archive &#187; Possible security issue with Parallels</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10459</link>
		<dc:creator>Pauline McNamara @ NTE &#187; Blog Archive &#187; Possible security issue with Parallels</dc:creator>
		<pubDate>Tue, 13 Feb 2007 10:49:11 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10459</guid>
		<description>[...] From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</description>
		<content:encoded><![CDATA[<p>[...] From Aral Balkan&#8217;s post Parallels Security Issue? : [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aral</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10366</link>
		<dc:creator>aral</dc:creator>
		<pubDate>Mon, 12 Feb 2007 10:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10366</guid>
		<description>Hi dkp (not the one from the forums, I'm assuming). I read serv's response but don't  find it satisfactory. Later in the thread he says that that it's his personal opinion and shouldn't be taken as the official response from Parallels. 

When you disable the global share, it's been my experience that you can still cut and paste files so, at least for me, the additional convenience is not worth the security risk. I agree with dkp (on the forums) that security should be the primary consideration here and that virtual machines should be sandboxed from the host machine. 

Regarding the email issue -- it's the first time I've heard of it. If you email me (my first name at the name of this domain), I'll look into it with your email address and share the fix, once I have it, with the k2 people.</description>
		<content:encoded><![CDATA[<p>Hi dkp (not the one from the forums, I&#8217;m assuming). I read serv&#8217;s response but don&#8217;t  find it satisfactory. Later in the thread he says that that it&#8217;s his personal opinion and shouldn&#8217;t be taken as the official response from Parallels. </p>
<p>When you disable the global share, it&#8217;s been my experience that you can still cut and paste files so, at least for me, the additional convenience is not worth the security risk. I agree with dkp (on the forums) that security should be the primary consideration here and that virtual machines should be sandboxed from the host machine. </p>
<p>Regarding the email issue &#8212; it&#8217;s the first time I&#8217;ve heard of it. If you email me (my first name at the name of this domain), I&#8217;ll look into it with your email address and share the fix, once I have it, with the k2 people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dkp</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10358</link>
		<dc:creator>dkp</dc:creator>
		<pubDate>Mon, 12 Feb 2007 00:57:17 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10358</guid>
		<description>The global share requirement was explained by "serv" from Parallels here:

http://forum.parallels.com/post41289-49.html

I've not tried it as it isn't anything I would need, but others will certainly appreciate the convenience.

BTW, your comment page does not accept legitimate mail addresses.</description>
		<content:encoded><![CDATA[<p>The global share requirement was explained by &#8220;serv&#8221; from Parallels here:</p>
<p><a href="http://forum.parallels.com/post41289-49.html" rel="nofollow">http://forum.parallels.com/post41289-49.html</a></p>
<p>I&#8217;ve not tried it as it isn&#8217;t anything I would need, but others will certainly appreciate the convenience.</p>
<p>BTW, your comment page does not accept legitimate mail addresses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Savvas</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10339</link>
		<dc:creator>Savvas</dc:creator>
		<pubDate>Sun, 11 Feb 2007 14:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10339</guid>
		<description>I couldn't agree more Aral.
My current problem is that some of win apps(Flash, Flex Builder, IE, Acrobat) when running in XP don't show up on dock and i can't keep them there in order to open them directly..

(you select the application you want in the dock, control-click and select Add to favorites from the context menu.)

Any ideas?</description>
		<content:encoded><![CDATA[<p>I couldn&#8217;t agree more Aral.<br />
My current problem is that some of win apps(Flash, Flex Builder, IE, Acrobat) when running in XP don&#8217;t show up on dock and i can&#8217;t keep them there in order to open them directly..</p>
<p>(you select the application you want in the dock, control-click and select Add to favorites from the context menu.)</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aral</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10323</link>
		<dc:creator>aral</dc:creator>
		<pubDate>Sun, 11 Feb 2007 01:04:13 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10323</guid>
		<description>Hi Savvas,

I just checked and I can still drag and drop. Not entirely sure what d&#038;d functionality I've lost. Turning this option off seems to be a good idea in general.</description>
		<content:encoded><![CDATA[<p>Hi Savvas,</p>
<p>I just checked and I can still drag and drop. Not entirely sure what d&#038;d functionality I&#8217;ve lost. Turning this option off seems to be a good idea in general.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: val brown</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10319</link>
		<dc:creator>val brown</dc:creator>
		<pubDate>Sat, 10 Feb 2007 19:20:34 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10319</guid>
		<description>Welcome to the wonderful world of Windows.  Jump in the pool, you get wet.  You don't want to get wet -- AT ALL -- then don't jump in the pool.  For me, I've been working with Windows, Mac, Unix etc for quite a while now and am very comfortable in switching amongst them so Parallels' transparent interoperability is wonderful.

i just remember it's Windows and partly that involves remembering that the vast majority of OS implementations in the world actually ARE Windows.  So there are benefits to it, despite the risks.</description>
		<content:encoded><![CDATA[<p>Welcome to the wonderful world of Windows.  Jump in the pool, you get wet.  You don&#8217;t want to get wet &#8212; AT ALL &#8212; then don&#8217;t jump in the pool.  For me, I&#8217;ve been working with Windows, Mac, Unix etc for quite a while now and am very comfortable in switching amongst them so Parallels&#8217; transparent interoperability is wonderful.</p>
<p>i just remember it&#8217;s Windows and partly that involves remembering that the vast majority of OS implementations in the world actually ARE Windows.  So there are benefits to it, despite the risks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Savvas</title>
		<link>http://aralbalkan.com/841/comment-page-1#comment-10259</link>
		<dc:creator>Savvas</dc:creator>
		<pubDate>Fri, 09 Feb 2007 08:53:29 +0000</pubDate>
		<guid isPermaLink="false">http://aralbalkan.com/841#comment-10259</guid>
		<description>Neither do i.
It asks me to connect to "my machine" as Guest..
Aren't you able to drag and drop?</description>
		<content:encoded><![CDATA[<p>Neither do i.<br />
It asks me to connect to &#8220;my machine&#8221; as Guest..<br />
Aren&#8217;t you able to drag and drop?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
