LabVIEW Idea Exchange

cancel
Showing results for 
Search instead for 
Did you mean: 
0 Kudos
cy...

pre-launch hash checker

Status: New

The default installation of LabVIEW, along with any associated binaries, should include an encrypted file stored in a strictly restricted location. This file must contain a list of cryptographic hashes for all installed files. The system should verify these hashes regularly, and alert the current session user if any binaries are newly introduced, replaced, modified, or deleted. This represents the minimum expected standard for securing the environment.

CY (expired CLAD)
5 Comments
Petru_Tarabuta
Active Participant

The idea sounds useful. Could you provide specific examples of which files should be hashed?

cy...
Active Participant

Files loaded into memory from insecure default installation folders should be hash-checked. This hash check should also be extended to the pre-build stage.

CY (expired CLAD)
Petru_Tarabuta
Active Participant

Thanks. What do you mean by "insecure default installation folders" and "pre-build stage"?

cy...
Active Participant

do refer to Chapter 4 for the folders in question
https://forums.ni.com/t5/Test-System-Security/LabVIEW-Secure-Development-Guide/td-p/4406611

CY (expired CLAD)
Petru_Tarabuta
Active Participant

Thanks for the link. What do you mean by Chapter 4? Which slide numbers?