Page 1 of 1

Security bulletins and notification via e-mail

Posted: Wed Aug 13, 2014 1:33 am
by cornflake
I would like security bulletins and to receive notification of them via e-mail. For example if something in Sandboxie is vulnerable I would like it if you could e-mail me. I am already a customer and you have my e-mail. I have several computers and on many of them I don't plan to update Sandboxie unless the version I'm using is vulnerable. I've found it difficult to figure out what version, if any, is vulnerable. I posted a related question here:
I'm using Sandboxie 4.08. Is that version still secure?

Thanks

Re: Security bulletins and notification via e-mail

Posted: Sat Mar 07, 2015 10:20 pm
by cornflake
Is it really just me? I just heard about this hard link vulnerability and it was fixed weeks ago. It would have been nice to have some e-mail notice or something like, hey, there's a vulnerability in sandboxie! Really I don't think this is too unreasonable. Thanks

Re: Security bulletins and notification via e-mail

Posted: Thu Jul 09, 2015 2:03 pm
by Craig@Invincea
cornflake wrote:Is it really just me? I just heard about this hard link vulnerability and it was fixed weeks ago. It would have been nice to have some e-mail notice or something like, hey, there's a vulnerability in sandboxie! Really I don't think this is too unreasonable. Thanks
For now, I would advise you to regularly check the Change logs http://www.sandboxie.com/?VersionChanges And monitor the forum. If it's something major, it'll be posted here first. We don't maintain a list of user emails.

Re: Security bulletins and notification via e-mail

Posted: Thu Jul 09, 2015 2:18 pm
by cornflake
Craig@Invincea wrote:
cornflake wrote:Is it really just me? I just heard about this hard link vulnerability and it was fixed weeks ago. It would have been nice to have some e-mail notice or something like, hey, there's a vulnerability in sandboxie! Really I don't think this is too unreasonable. Thanks
For now, I would advise you to regularly check the Change logs http://www.sandboxie.com/?VersionChanges And monitor the forum. If it's something major, it'll be posted here first. We don't maintain a list of user emails.
Thanks for your reply. Even if you don't maintain a user list you could make one. You have my e-mail associated with my license for example, and also you have my e-mail associated with my account on this forum. Or you could just make a separate list and have a form where people could sign up. I really think it's a lot to do to have to go through the forum posts to find the latest security issue. I'm just not going to do that every day although I do check the forums occasionally. If you had a bulletin with the latest information, and I received an e-mail notification, we could react to that much faster. That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.

Re: Security bulletins and notification via e-mail

Posted: Thu Jul 09, 2015 3:28 pm
by Dun
cornflake wrote:That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.
+1 To the thread so users can subscribe to get email notifications

Re: Security bulletins and notification via e-mail

Posted: Tue Jul 14, 2015 9:01 am
by Craig@Invincea
Dun wrote:
cornflake wrote:That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.
+1 To the thread so users can subscribe to get email notifications
A security thread is an idea. As for the emails we collect. Yes, we have it from the forum registrations and Cleverbridge would have it from the orders from licensing.

Re: Security bulletins and notification via e-mail

Posted: Wed Aug 26, 2015 2:15 pm
by Craig@Invincea
Dun wrote:
cornflake wrote:That could even be done in a master thread that any forum user could subscribe to. You lock the thread and then each time a security issue is found you update the thread with details of the issue and workarounds,etc.
+1 To the thread so users can subscribe to get email notifications
Security Sticky thread has been created..http://forums.sandboxie.com/phpBB3/view ... 11&t=21656

Re: Security bulletins and notification via e-mail

Posted: Wed Aug 26, 2015 6:23 pm
by Dun
Thank you, already subscribed :)

Re: Security bulletins and notification via e-mail

Posted: Thu Aug 27, 2015 9:43 am
by Craig@Invincea
Dun wrote:Thank you, already subscribed :)
You're welcome. Hopefully, its a dull thread. :wink: