How secure is Opera Unite?

By Scott M. Fulton, III | Published June 16, 2009, 2:15 PM

(continued from previous page)

Opera Unite Services appears in a separate menu in Opera 10.  (Courtesy Opera Software)

If a Unite widget is designed the way Opera intends, it should enroll itself in a menu clearly labeled "Opera Unite Services," accessible from the left side toolbar, as indicated in this screenshot from Opera Software. But that's if it's intentions are completely honorable. Since a Unite widget is essentially a widget with some extra inclusions in its config.xml file, it appears feasible on the surface for a malicious user to craft an Opera widget that purports to be just a local widget, but which ends up leveraging the Unite protocol to deliver a harmful payload...or to wreak havoc on the user's file system.

Opera's spokesperson tells Betanews today that the company itself will protect against this possibility by pre-screening all Unite widgets and certifying their developers' claims.

"We make sure that any service uploaded on http://unite.opera.com only does what it claims and informs the users about," the spokesperson said. "Any faulty/malicious services will not be approved. As such, we encourage our users to download services only from http://unite.opera.com -- this repository offers services absolutely free and is open to all developers."

As Firefox users are already well aware, Mozilla's servers aren't the only place in the world to download add-ons -- oftentimes their developers do their own distribution. So when Opera's servers see traffic from Unite widgets, how will they know for certain that these widgets are what they say they are, and being operated on the authority of legitimate users? This is another extremely important point because, as outlined in the Opera widget security model which pre-dates Unite, a widget can conceivably communicate using a secure protocol using authentication -- such as SSL -- but doing so is completely voluntary.

Opera's spokesperson told Betanews today that authentication takes place between the widget and Opera's proxy servers not using SSL (with the https:// protocol identifier) but one of its own: "The authentication between the Opera Unite client and the Opera proxy happens via http://auth.opera.com which is our secure authentication server. This is the same server that is used to authenticate all our services, like Opera Link."

Introduced in September 2007, Opera Link is a storehouse for user information, originally designed to enable users to transport their bookmarks, "Speed Dial," personal notes, and other browser data between desktop and mobile platforms. It's maintained by the "My Opera" server network, which is operated by the Opera Community as opposed to the company. While contributors have responded to user concerns by pointing out that link synchronization -- moving those assets between desktop and mobile platforms -- is done using encryption protocols, logging into the system itself is not.

In a discussion thread on My Opera last January launched by a user who wondered why Opera Link logins are not secured, initial responses came from folks who claimed protocols were pointless anyway because computers at public hotspots tend to use keyloggers. The thread was closed with a comment from a My Opera contributor essentially saying anyone that concerned about having his logon intercepted, probably shouldn't be using the Internet in a public place anyway.

But that was several months before the Opera Link system would be used to authenticate traffic for services that potentially have indirect, and perhaps even undirected, access to users' system folders. During this initial testing phase for Unite, one can probably bet safe money on the likelihood that someone -- perhaps a well-meaning security researcher, perhaps someone else -- will experiment with the notion of just how accessible the "My Documents" directory may be, for anyone who uses Unite to post a blog.

← Previous Page | 1 | 2

Comments

View comments by with a score of at least

There are several severe errors in this article:

* The services can not select a folder to share. They can suggest a range of folders, but the users have full control over which folder they want to share.
* The proxy has absolutely nothing to do with the mount points.
* The auth.opera.com authentication server has always been, and still is, secure, using TLS

Score: 1

|

It still seems you need to trust Opera. What if someone there went rogue?

Score: -1

|

I just installed the new Opera Unite and what I think about security is that once again we fall in the same "its up to you" discussion, finally... its up to you to decide whom you send the personal address Unite gives you, on the other hand it comes really handy for those of us with a Laptop, I dont wanna pay for a fixed IP address and I dont know how to setup a VPN anyway, so I just have to call home and tell whoever answers "turn on the PC for me", and I get the access I want to my files, no problem so far. Again it is a matter of personal criteria. It works for me, I can transfer all my music, photos and files in an easy way.

Score: 2

|

All that has been possible for more than a decade now with other services? Are you seriously suggesting it took a browser plug-in in 2009 for you to get remote capability to your laptop?

Score: -1

|

Not really up to you at all, sadly.

The d-bags mentioned earlier can easily snoop, trojan, and worm the information out of your PC without you ever knowing about it. ;)

Score: -1

|

Yes, Firefox and security...
http://my.opera.com/rejz...e-in-firefox-and-chrome

At least Opera does this right...

Score: 0

|

local access to x and you are pretty much compromised, it doesn't matter what OS you use.

Score: 0

|

lock your damn computer when you're not seated in front of it, at least

Score: 0

|

why with this being all of an innovation, you make a first talk of it getting alarmed about security?... you must love Firefox, don't you?

Score: 1

|

its not exactly innovation, the "new" features are just now available within the operas browser using their own service, big deal really... and no avg person will use these features, so i'm at a loss for what opera is trying to accomplish lol

personally i think Mozilla and Microsoft? of all companies are the only ones that 'get it' when it comes to browsers, Mozilla more so of course, but i can see them easily going astray the standards of what a browser should and should not do as well in the future... sadly

Score: -1

|

a web server, in a browser? not that secure lol the fact that its now even being talked about means its less secure

Score: -1

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.