Problem about remove a review and risk to those who use

Here you can contact the editors of our Extensions site, as well as access infomation relating to this site.

Moderator: JED Team

Forum rules
Forum Rules
READ ME <-- please read before posting, this means YOU.
Locked
fptquangngai
Joomla! Apprentice
Joomla! Apprentice
Posts: 28
Joined: Sun Jan 11, 2015 10:13 am
Location: tech
Contact:

Problem about remove a review and risk to those who use

Post by fptquangngai » Thu Jan 29, 2015 1:12 pm

Hello everybody.

Recently we found risks in a component and put this in the review. The component owner requested the review to be removed. Meanwhile the component stays for sale with the errors present and presents a risk to any one who should pay for it.

My question is :
Why remove a review that points out a risk to those who use it, and could save them their business.

Why leave this component there for others to purchase and use, knowing there is a serious risk in it.

The component in question stores user logins and passwords in a session table un encrypted and never deletes them, leaving them there for others to read, export and reveal.

The component has an ecommerce functionality that destroys transaction history which is against accounting practice and could potentially land a business in serious trouble.

But this is not a valid reason to object or remove a component.

I dont understand.
Thank's a lot!
site specializing in technology: https://viettelquangngai.net/
chào mừng đến với cộng đồng:https://internetvietnam.net/

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Problem about remove a review and risk to those who use

Post by mandville » Thu Jan 29, 2015 1:18 pm

A review was probably the wrong choice. you should have reported it instead and even informed the vel team .
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

xpozay
Joomla! Apprentice
Joomla! Apprentice
Posts: 35
Joined: Wed Oct 31, 2007 7:19 pm
Location: Singapore

Re: Problem about remove a review and risk to those who use

Post by xpozay » Thu Jan 29, 2015 4:00 pm

I have seen similar issues with extensions ie saving passwords stuff in the open or delete records. While I personally feel this is not appropriate (in many countries illegal), it is a feature that some people may be happy with or may want. It is not up to us to dictate how others use extensions. Thus I do not see why reporting the extension would be a 'better' thing to do. Unless of course there is a Joomla rule saying against this .....

That said, I do agree with fptquangngai, the Extension Review is an appropriate place to make your comment. There is a Functionality area in the review and this is related to the extension's functionality. As a potential buyer, I would be thankful for such a review and stay clear.

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Problem about remove a review and risk to those who use

Post by mandville » Thu Jan 29, 2015 4:28 pm

a security risk or bug report would be out of place on a usability review . Send it via the proper channels and get it fixed is so much better .
The published review would also likely lead to people testing for other vulnerability. Blame game time.
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “extensions.joomla.org - Feedback/Information”