LabVIEW

cancel
Showing results for 
Search instead for 
Did you mean: 

Silverlight Security Risk


@santo_13 wrote:

If we talk of obsolete and unsupported software, I know many semiconductor giants who still use 50+ year old iron ATE testers that have old CRT monitors (not even grayscale, monitor displays in green), I think they run some sort of DOS or UNIX.


I think you would be hard pressured to find anyone who still can maintain them, not to speak about hacking them! 😁 Besides, back then a network card cost a real fortune (and so did computers) and it is highly unlikely that such a system would/could be connected to a network that can somehow be connected to the Internet even if one really wanted to. Most likely if it has any connection to another system it is by electrical wires and/or maybe an RS-232 connection, or more likely a TTY current loop serial interface.

 

As to the original issue, if that IT departement really wants to make its policy true, they would have to forbid Windows altogether, and every other OS too. There are everywhere old dogs buried that nobody has looked at anymore in many many years. Not because they are super safe, but simply because nobody uses them anymore. Are they vulnerable? Quite likely! Are they a big risk? Really depends if you are paranoid or not.

 

A few examples?

 

- DDE (yes it's still in every Windows computer, and has a security model that simply doesn't exist) 

- (D)COM (still used in everything ActiveX, and even partly in .Net, but most of its complex security configuration was and is so obscure that nobody deals with it anymore, which very well can mean that its configuration easily opens doors of the size of an airplane hangar without anyone noticing, except hackers of course)

 

And Linux isn't really better or any other computer for that matter.

 

 

Rolf Kalbermatter
My Blog
0 Kudos
Message 11 of 15
(1,058 Views)

I'd recommend uninstalling Silverlight on a test machine and seeing what breaks. I recently did an install on a lab machine of some test software with DAQmx drivers and NI-MAX and it didn't automatically install Silverlight, which means it at least thinks it can do SOME things without it.

 

I had to install Silverlight to connect to and configure a network cDAQ chassis, but if you're not using those then you might wind up OK. I don't know if the regular DAQmx stuff uses Silverlight but it's worth a shot, especially if negotiating with your IT is a giant nightmare.

0 Kudos
Message 12 of 15
(1,032 Views)

@BertMcMahan wrote:

I'd recommend uninstalling Silverlight on a test machine and seeing what breaks. I recently did an install on a lab machine of some test software with DAQmx drivers and NI-MAX and it didn't automatically install Silverlight, which means it at least thinks it can do SOME things without it.

 

I had to install Silverlight to connect to and configure a network cDAQ chassis, but if you're not using those then you might wind up OK. I don't know if the regular DAQmx stuff uses Silverlight but it's worth a shot, especially if negotiating with your IT is a giant nightmare.


This is a good idea, and if it breaks your program then turn it back on IT.

 

You can't do your job due to their policy, make it their responsibility to find a solution and watch how fast they are willing to negotiate. 

========================
=== Engineer Ambiguously ===
========================
0 Kudos
Message 13 of 15
(1,026 Views)

@rolfk wrote:
"... A bunch of scary stuff..."

 

 


Well, so much for ever getting a good night's sleep again. 😥

Thanks Rolf!  😜

 

LabVIEW Pro Dev & Measurement Studio Pro (VS Pro) 2019
0 Kudos
Message 14 of 15
(1,019 Views)

I may be wrong (but I don't think so ...), but I believe Silverlight is only needed for the Web Interface which is sometimes used to configure things like cRIOs.  NI certainly knows this.  I'm pretty sure that NXG was using a non-Silverlight Web Interface, and with NXG's demise, and new Web features in LabVIEW 2021, NI may have a replacement either "ready" or "almost ready" ...

 

Bob Schor

0 Kudos
Message 15 of 15
(1,005 Views)