sandboxie-plus / Sandboxie

Sandboxie Plus & Classic
https://Sandboxie-Plus.com
GNU General Public License v3.0
13.98k stars 1.56k forks source link

Secure way to share Sandboxie.ini #2768

Open DavidXanatos opened 1 year ago

DavidXanatos commented 1 year ago

Discussed in https://github.com/sandboxie-plus/Sandboxie/discussions/2735

Originally posted by **mysteriously** March 6, 2023 Hello, We need more secure way to share Sandboxie.ini. Is it possible to limit access to at least contributors?
DavidXanatos commented 1 year ago

I'll add an option to export the ini to one of the next builds, which informations would we want to redact? also I would add an option to eider export to file or upload to server, what do you think?

ghost commented 1 year ago

I thought about limiting pastebin links to config files access to contributors directly via github feature. I am not sure if such feature exists though. This way allows the OP to have control over the original link, as he can delete the paste anytime, make it unlisted on pastebin or set up paste expiration time

bastik-1001 commented 1 year ago

I'll add an option to export the ini to one of the next builds, which informations would we want to redact? also I would add an option to eider export to file or upload to server, what do you think?

If that is still considered, since the original requester turned into a ghost. 1) the EditPassword value isn't needed, maybe that it has been set can be relevant for some issues, but not what the stored hash is. Depending on the issue, all other settings can be relevant to it. Maybe a user name could be replaced with a fixed string, but overall all path can be relevant. 2) To post it in a forum or within an issue, an export to file or clipboard seems to be helpful. Maybe that could be exported per box, so that the export includes the global settings and only the box the issue is supposed to be about. Uploading the file to a server, can be helpful, too, like for users that want to give you and collaborators information, they feel like not being able to share publicly.

When it just comes to copy and paste, my guess is that people can do that on their own, but then again, for some it might be something that is not that easy.