<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Script from unknown users - security risk? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175835#M29307</link>
    <description>&lt;P&gt;You’ve heard of &lt;A href="https://en.wikipedia.org/wiki/Linux" target="_self"&gt;Linux&lt;/A&gt;, right?&lt;BR /&gt;It ultimately came from a bunch of random people on the Internet.&lt;BR /&gt;Yet, so much of our modern technology landscape is possible because of Linux.&lt;/P&gt;
&lt;P&gt;One of the ways trust is built is by publishing source code.&lt;BR /&gt;That along with the licensing allowed for wide adoption, reuse, and…trust.&lt;/P&gt;
&lt;P&gt;One of the requirements for inclusion in Toolbox is publishing of source code.&lt;BR /&gt;This gives you the confidence to see for yourself what’s being done before you decide to use it.&lt;/P&gt;
&lt;P&gt;For scripts and the like, you can see what’s being done for yourself easily enough.&lt;BR /&gt;The SmartConsole Extensions are a little trickier because of how they are implemented (require a web server stood up).&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2023 21:59:47 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-03-22T21:59:47Z</dc:date>
    <item>
      <title>Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175667#M29287</link>
      <description>&lt;P&gt;Many interesting scripts and SmartConsole extensions can be found in the &lt;A href="https://community.checkpoint.com/t5/CheckMates-Toolbox/ct-p/CheckMatesToolbox" target="_self"&gt;CheckMatesToolbox.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;In the last few weeks I have been reading the comments of users again and again, should you execute scripts from unknown users on a firewall. This has been a fundamental question for me for years. &lt;BR /&gt;&lt;BR /&gt;From my point of view, this should not be done, as there is a considerable risk on a productive firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I personally write my scripts in such a way that everyone can read the source code cleanly. &lt;BR /&gt;This gives everyone the chance to analyse the script code.&lt;/P&gt;
&lt;P&gt;Checkmates, what do you think about this topic?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 07:02:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175667#M29287</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2023-03-22T07:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175670#M29289</link>
      <description>&lt;P&gt;I agree with you.&lt;/P&gt;&lt;P&gt;Here we should think about the following:&lt;BR /&gt;Are millions of lines of Linux code not also a security risk?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 07:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175670#M29289</guid>
      <dc:creator>SATO_SOG</dc:creator>
      <dc:date>2023-03-22T07:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175680#M29290</link>
      <description>&lt;P&gt;Here we should think about the following: Are humans basically a security risk?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 08:19:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175680#M29290</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-22T08:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175782#M29297</link>
      <description>&lt;P&gt;Thats called whataboutism.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 14:58:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175782#M29297</guid>
      <dc:creator>Bärbel</dc:creator>
      <dc:date>2023-03-22T14:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175786#M29299</link>
      <description>&lt;P&gt;Actually,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;has a point &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Humans are the main reason cyber security has so many threats &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 15:17:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175786#M29299</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-22T15:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175829#M29305</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;.&lt;BR /&gt;Software is only so secure as the human mind behind it.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 20:54:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175829#M29305</guid>
      <dc:creator>MAlter</dc:creator>
      <dc:date>2023-03-22T20:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175833#M29306</link>
      <description>&lt;P&gt;If some admin would like to have extension installed on the management, the extension should be first checked by experienced colleague who will give a green light if such a features are safe to be deployed. Tested in lab, of course.&lt;/P&gt;
&lt;P&gt;Each and every extension should be available offline (locally present on management by selecting the json file), not downloaded from public internet.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 21:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175833#M29306</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-03-22T21:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175835#M29307</link>
      <description>&lt;P&gt;You’ve heard of &lt;A href="https://en.wikipedia.org/wiki/Linux" target="_self"&gt;Linux&lt;/A&gt;, right?&lt;BR /&gt;It ultimately came from a bunch of random people on the Internet.&lt;BR /&gt;Yet, so much of our modern technology landscape is possible because of Linux.&lt;/P&gt;
&lt;P&gt;One of the ways trust is built is by publishing source code.&lt;BR /&gt;That along with the licensing allowed for wide adoption, reuse, and…trust.&lt;/P&gt;
&lt;P&gt;One of the requirements for inclusion in Toolbox is publishing of source code.&lt;BR /&gt;This gives you the confidence to see for yourself what’s being done before you decide to use it.&lt;/P&gt;
&lt;P&gt;For scripts and the like, you can see what’s being done for yourself easily enough.&lt;BR /&gt;The SmartConsole Extensions are a little trickier because of how they are implemented (require a web server stood up).&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 21:59:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175835#M29307</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-22T21:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175840#M29308</link>
      <description>&lt;P&gt;Well, thats true, but considering AI is taking over the world, humans wont even be needed to do much work soon lol&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 22:43:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175840#M29308</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-22T22:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175841#M29309</link>
      <description>&lt;P&gt;To me, personally, like everything in life, it all comes down to really one single word...TRUST. As my late grandfather always used to say "If you trust someone only 99%, thats not good enough". I think thats a very good point.&lt;/P&gt;
&lt;P&gt;Just my take on it.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 22:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175841#M29309</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-22T22:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Script from unknown users - security risk?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175874#M29310</link>
      <description>&lt;P&gt;No, this is not an argument - it was only meant as a parody of &lt;SPAN class="UserName lia-user-name lia-user-rank-Explorer lia-component-message-view-widget-author-username"&gt;&lt;A id="link_855895ea89f06f_5" class="lia-link-navigation lia-page-link lia-user-name-link" style="color: #c23563;" href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/89161" target="_self" aria-label="View Profile of SATO_SOG"&gt;&lt;SPAN class=""&gt;SATO_SOG&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;s nonsense 8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 08:45:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Script-from-unknown-users-security-risk/m-p/175874#M29310</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-23T08:45:58Z</dc:date>
    </item>
  </channel>
</rss>

