...
Edit: so after some more discussion with the person who owns the miner, the problem is that awesome miner defaults to an allows someone to do this.
It should not even be an option in the GUI
Thanks for your detailed feedback.
...
Firstly, there is a simple fix to this:
AM knows it's own IP address so that should be the default (and normally the only option)
It shouldn't allow W:0/0 ever.
I really can see no reason why anyone would set their miner to W:0/0 unless they have no idea what they are doing, thus defaulting to AM's IP would be the correct answer for the ignorant.
Having it as an 'easy' fix to make your miner wide open to known viruses is REALLY bad and a major security flaw.
(especially since AM is Windows and the known viruses are Windows also)
Since you've ignored this simple fix to your massive security hole in your software, and others have also fallen into this trap since then ...
I'll quote it again and point out that you REALLY should fix it since there is NO reason to give a box option to use W:0/0
If someone is smart enough to know what W:0/0 is (and it should NOT be suggested anywhere in the software, documentation or support) they can of course enter it themselves.
If they have NO idea what they are doing, it should default to the AM PC IP address that it ALREADY knows as I suggested above ... months ago.
After the discussion last time, I did go ahead with a few changes where it was made much easier for a user to select a good configuration. The users are given these four options since several months ago:
- This computer
- This network
- Any computer (less secure)
- Custom IP access rule
By introducing "This computer" and "This network", Awesome Miner made it easier for the users to do the right thing without having to type IP addresses and access rules. Users doesn't have to learn and write the IP access syntax correctly, as Awesome Miner will secure it for you.
I did however not remove the "Any computer" option, but it's clearly stated in the user interface that this option is "less secure".
The changes made was clearly a move in a good direction by making it easier to select a good configuration and warn about the option that isn't secure.
I understand your point about removing this "less secure" option completely from the user interface. It would of course make it even more likely that a user pick a good configuration. I will make this change in the next release - to remove the option "Any computer (less secure)". Thanks!