weixin_39599454
2021-01-02 07:01 阅读 0

is the source of the downloadable plugin somewhere?

该提问来源于开源项目:torrentsTime/embed

  • 点赞
  • 写回答
  • 关注问题
  • 收藏
  • 复制链接分享

18条回答 默认 最新

  • weixin_39599454 weixin_39599454 2021-01-02 07:01

    I'm talking about these two:

    screen shot 2016-02-04 at 2 10 22 pm

    点赞 评论 复制链接分享
  • weixin_39789979 weixin_39789979 2021-01-02 07:01

    I agree with Fernandez and please can you provide a Linux version too? Why would I trust you? I don't want to install a black box on my computer. Moreover, I'd like to know whether your plugin relies on NPAPI as it's going to become unsupported by Firefox: https://blog.mozilla.org/futurereleases/2015/10/08/npapi-plugins-in-firefox/

    Why not using something like WebChimera to build a plugin-free solution?

    Maybe we can try to do some reverse engineering on those native installers to understand a bit what they do. I can use xar or ark to open the pkg archive under Linux.

    点赞 评论 复制链接分享
  • weixin_39789979 weixin_39789979 2021-01-02 07:01

    Ok it works with "7z x torrentsTime-download.pkg": Bom PackageInfo Payload Scripts [TOC].xml

    [gouessej torrentsTime]$ more PackageInfo

    
    <pkg-info format-version="2" identifier="com.torrentstime.plugin" version="1.0.6.0" overwrite-permissions="false" install-location="/" auth="root">
    <payload installkbytes="30425" numberoffiles="6"></payload>
    <scripts>
        <postinstall file="./postinstall"></postinstall>
    </scripts>
    </pkg-info>
    
    点赞 评论 复制链接分享
  • weixin_39796152 weixin_39796152 2021-01-02 07:01

    -Ray

    Exactly. It's mainly for profit project.

    点赞 评论 复制链接分享
  • weixin_39717026 weixin_39717026 2021-01-02 07:01

    At least on OS X, it installs an NaCl executable, which presumably talks to a helper process /Library/PrivilegedHelperTools/com.torrents-time.helper started by launchd.

    Unfortunately, this helper process aborts under Darling on Linux after talking to 5.79.65.173 and then doing some socket operations (opening and closing a socket several times). I did not investigate further.

    点赞 评论 复制链接分享
  • weixin_39960019 weixin_39960019 2021-01-02 07:01

    Without open-sourcing the actual plugin, I see no point in trusting this project.

    点赞 评论 复制链接分享
  • weixin_39796152 weixin_39796152 2021-01-02 07:01

    Kaspersky.

    点赞 评论 复制链接分享
  • weixin_39717026 weixin_39717026 2021-01-02 07:01

    The helper process now seems to run under Darling (I'll commit fixes later).

    I don't know how to enable the NaCl (pexe) part though. So if somrone is eager to run proprietary binaries on Linux, there is probably a way :-D

    点赞 评论 复制链接分享
  • weixin_39796152 weixin_39796152 2021-01-02 07:01

    Not this one. No packer or obfuscator will generate code with network syscalls. You can pretty much get all what's going on from debugging it and looking at assembler code - that's how reverse engineering works.

    点赞 评论 复制链接分享
  • weixin_39960019 weixin_39960019 2021-01-02 07:01

    Interesting, though something as simple as an update check would generate that as well, no?

    Could you share a decompilation?

    点赞 评论 复制链接分享
  • weixin_39724009 weixin_39724009 2021-01-02 07:01

    Hey guys

    Sorry for the late response, we are very busy.

    I'm sorry, but I can't quite understand the concerns you've mentioned. There is nothing suspicious in our technology! It's straight forward, efficient and honest. Yes, Honest with a capital H.

    It is a state of the art craftsmanship made to stream torrents from your browser and then to be able to convert them to a streamable format and play them with our video player. It has absolutely no other hidden aspects.

    We'll be happy to answer any specific professional concern.

    点赞 评论 复制链接分享
  • weixin_39627665 weixin_39627665 2021-01-02 07:01

    And they deleted my comment so yet again

    http://blog.andrew.im/post/139084882590/torrents-time-security-issues

    点赞 评论 复制链接分享
  • weixin_39796152 weixin_39796152 2021-01-02 07:01

    It's really pathetic to delete comments that show bugs in your software... It shows what kind of people are developing this.

    点赞 评论 复制链接分享
  • weixin_39930671 weixin_39930671 2021-01-02 07:01

    I'm sorry, but I can't quite understand the concerns you've mentioned.

    This is very sad…

    点赞 评论 复制链接分享
  • weixin_39789979 weixin_39789979 2021-01-02 07:01

    If you're honest, why don't you simply release the source code of your plugin? It would show that you're transparent, that you have nothing to hide and it would help some developers to improve it too. Plugins are going to become unsupported in major web browsers (and yours still doesn't work under GNU Linux), why not accepting some help to move to a plugin-free solution?

    点赞 评论 复制链接分享
  • weixin_39796152 weixin_39796152 2021-01-02 07:01

    It's obvious why it's closed source, because it's FOR PROFIT solution/plugin.

    点赞 评论 复制链接分享
  • weixin_39686353 weixin_39686353 2021-01-02 07:01

    Their website mentions they want to implement advertising solutions inside the player. That's why it's closed source. I can't imagine a better way to get indicted by the govt.

    点赞 评论 复制链接分享
  • weixin_39686353 weixin_39686353 2021-01-02 07:01

    Very good article. As described, there is absolutely no reason to use this application as long as it's not being improved upon by an open source community.

    点赞 评论 复制链接分享

相关推荐