Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ General ⇒ Announcements :: Archives ⇒ CPG-CS Certified Secure™ :: Archived


CPG-CS Certified Secure™ :: Archived
General announcements from the Dragonfly CMS Team.
Go to page Previous  1, 2, 3, 4
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Announcements

Topic Archived View previous topic :: View next topic  
Author Message
RedGerry
Silver Supporter
Silver Supporter

Offline Offline
Joined: Jun 29, 2004
Posts: 480
Location: Fishcross, Scotland
PostPosted: Sun Sep 18, 2005 2:09 pm
Post subject: Re: CPG-CS Certified Secure™

So is this concept dead in the water then?

_________________
gerry @ redgerry.com
redgerry.com
clacks.co
123v.com
copseygroup.com

RedGerry's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Suse11.4 - LAMP on zypper - ISPConfig 3
Back to top
View user's profile Visit poster's website MSN Messenger
Śyama_Dāsa
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 2048
Location: Dragonfly CMS Tribe
PostPosted: Thu Dec 08, 2005 8:15 pm
Post subject: Re: CPG-CS Certified Secure™

Sorry i did not see this post before RG

The best way to contact the staff and I, regarding this program is though PM-ing me.

_________________
AKA Akamu / Read these and your life will be successful | Find a Repair
--
Mods and Professional Support via YIM

Śyama_Dāsa's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
win32 / Apache 1.3.33 / MySQL 4.1.16/PHP 4.4/CPG-CVS ( browsers: Mozilla 1.7.x / IE6 / Opera 8.0)
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
BrokenCrust
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Sep 06, 2004
Posts: 503

PostPosted: Mon Mar 20, 2006 9:36 am
Post subject: Re: CPG-CS Certified Secure™

Is this programme going ahead at all?

There seems to be no formalised way to get a Certified Secure status. I have PM'd Śyama_Dāsa over a month ago about certifying one of my modules and was told I'd get a price for it in a few days. This didn't happen and I've received no replies to follow up posts to see what's going on.

Is this program just for certain dev's or are you actually going to have an ongoing programme to review module code? Right now it looks like an invited list and therefore amounts to little more than self gratification and of no real use, either to people looking for secure modules or for authors wanting to ensure that their code is any good. Right now it looks like all CPG dev's code is all nice and secure and certified and everyone else's is a hopeless hacker feast.


BrokenCrust please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Mon Mar 20, 2006 2:01 pm
Post subject: Re: CPG-CS Certified Secure™

I've also received no response from my efforts to get a module certified.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
musox
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 325

PostPosted: Mon Mar 20, 2006 2:16 pm
Post subject: Re: CPG-CS Certified Secure™

I'll chime in with I've have submitted my module, received a quote, paid the quote, received first set of responses and waiting on the second set.

It has been a very long process as I sent the first response back in 8/12/05. The second response has been waiting since 02/06.

I don't mind paying the big price, but it has been frustrating with the time frame of getting responses. I'll give Syama some slack as I have not stated my opinions to him in a PM, but the fact that it has been seven months now...

The information that I did get from him on the first round was VERY helpfull and has helped my DF coding skills greatly.

- MusOX

_________________
../musox.com
Hosted by: Site5.com

musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
Back to top
View user's profile Visit poster's website Photo Gallery
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Mon Mar 20, 2006 2:19 pm
Post subject: Re: CPG-CS Certified Secure™

Imagine if I completed a theme 7 months after someone paid me. I'd get sued.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
BrokenCrust
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Sep 06, 2004
Posts: 503

PostPosted: Mon Mar 20, 2006 5:12 pm
Post subject: Re: CPG-CS Certified Secure™

This whole process lacks transparency.

The programme should be open and formal, not just via an adhoc PM request. There also should be documentation on what secure means in the context of "certified secure" and also for that matter what is checked to meet this security.

The program should be about encouraging better coding especially WRT security. It would be helpful to set out the basic minimum security coding standards for common functions, including examples of secure and insecure coding. That way we could do that up front and the code would be more easily checked and the dev experience put to looking at more complex functions.

Also, in fact, "certified" is misleading, since it isn't certified in any way at all. It is still released under the "no warrantee, no comeback" GPL license and like the core code not actually certified as fit for any purpose whatsoever legally.

What it means right now is:

"I paid a CPG-Nuke DEV a bunch of cash to check my code and he said it was all right security wise".

This is fine, and IMO, still useful for the first module checked. I pay to benefit from their experiences, however this would become old real quick after 3 or 4 modules and going forward it would be of dubious value. I mean, I match all my competitors on price as it is, so I don't stand to make a lot more from sales by getting the tins stamped "Real Meat". Smile

Also how does this work with upgrades? Version 1.0 certified secure, then I release 1.1. Do I need to get it recertified? What about bug fixes (say in the formatting).

In any case, doesn't this all end up about as useful as "Contents Hot" on a coffee cup - true enough to scold your privates when you buy it but just wait a bit a it's a total lie.


BrokenCrust please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Announcements
Page 4 of 4
All times are GMT
Go to page Previous  1, 2, 3, 4

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

Детальніше...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy