Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Very sad, what is happening in here... :(Very sad, what is happening in here... :(
Previous
 
Next
New Post
1/17/2014 1:32 PM
 
The Update Service has been in the DNN platform since 2006. It's purpose is to provide a service to our users to let them know when a new version of the software is available. This is especially important when a security issue is discovered, as there is often a short window of opportunity to upgrade your site to ensure it is adquately protected from malicious intent. We have always been careful to restrict the information passed to those items which are important to the Update Service so that it can provide the appropriate upgrade recommendations to your site. When we released 7.2 in December we introduced a new ability for a user to opt in to our Newsletter during the installation or upgrade process. Folks who opt-in will receive the monthly Community Newsletter which contains a variety of helpful information about products and community support. The mechanism used by the software to capture the email address entered is the Update Service, as it was the best method to ensure the user was added to the newsletter mailing list ( ie. it did not require us to add additional callbacks to the platform ). Users can decide to disable the Update Service at any time either before or after installation - there is a web.config setting that can be used, or it can be done through Host Settings.

My comments are my own and are offered WITHOUT PREJUDICE

Shaun Walker
http://www.siliqon.com
 
New Post
1/17/2014 7:09 PM
 
So what you are saying is that there is no reason that this email should be repeatedly sent back to the update server ... While some may still be dubious about the intent ... It should be a very simple matter ... I would think maybe one line of extra code ... In the update url creation module to remove the email address from the hostings database after it's been sent the first time ... I expect this will be in the next security patch update ... Because well a url passing private email details in clear text with not even the simplest of masking or encryption seems like a pretty obvious security exposure.

Westa
 
New Post
1/23/2014 1:37 PM
 
Have DNN Corp. sunk to a new low?
While visiting Codeplex a few times recently due to the false start launch of 7.2.1 I was surprised to see in one of the comments that one of the COMMUNITY members had submitted a new feature to DNN Corp for inclusion into DNN Community Edition only to find that this submission has been taken and included ONLY into EVOQ when it's obvious, to me anyway from reading the relevant comment, that the author had submitted it with the intention of being included into the Community Edition and for the good of the Community and is NOT very happy about it.
If this is the case then I'm amazed at the cheek of these people. I hope at least they're paying the author of this new feature a royalty out of the profits they make from the huge price of EVOQ. Somehow I feel this is not the case.
Can things get any worse than this?
If I have misunderstood this action by DNN then I will gladly take back what I have said. If not then I do wonder where the incentive is to take any active part within this community anymore and whether the people responsible at DNN Corp. have ANY morals at all.
 
New Post
1/23/2014 1:50 PM
 
Could you please provide more detail, I cannot locate that comment in 7.2.0/7.2.1 reviews. I also looked at the patches list in codeplex (though we don't accept patches submitted via codeplex, we require them to be submitted via pull requests) and cant see anything applicable. FYI the only team who accept patches currently is the platform team, and we always apply them to the platform (i.e. what used to be called community edition) -on occasion the evoq teams may get code from a support ticket raised by a customer but that's done via our private customer support network.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
1/23/2014 2:02 PM
 

Hi Cathal

https://dotnetnuke.codeplex.com/releases/view/117545#ReviewsAnchor

The 4th comment down.If you read all, there aren't that many, then you will see it.

As I tried to explain, I am posting about a comment from somebody else that I have read so cannot be sure about it's  believability which is why I brought it up here so that a DNN representative, such as you, could comment and clear up any confusion.

I'm also aware that English is not the first language for many of us and that can lead to texts being unclear on their meaning.

I really do hope this is just a misunderstanding on my part.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Very sad, what is happening in here... :(Very sad, what is happening in here... :(


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out