there's still "Start OpenVPN directly"

https://github.com/OpenVPN/openvpn-gui/blob/master/openvpn.c#L724

in such case admin rights are still required for routes manipulation.


maybe we should release two installers (or make a checkbox in installer?)

1) regular mode (with highest priv manifest)
2) paranoya mode (without highest priv)


those who really care will choose whatever they want to


2016-02-08 0:27 GMT+05:00 Gert Doering <g...@greenie.muc.de>:

> Hi,
>
> On Sun, Feb 07, 2016 at 09:00:28PM +0500, ???????? ?????????????? wrote:
> > if you mean interactive service, keep in mind that people sometimes start
> > openvpn as a child of openvpn-gui, not as a service
>
> Interactive Service is running openvpn.exe under control of openvpn-gui,
> and you won't notice anything different - except that it magically works
> even if the user has no permissions to set routes, and the "want admin!"
> flag is not set on the GUI.
>
> And, of course, that bugs in openvpn-gui or openvpn will not lead to a
> privilege breach anymore.
>
> gert
> --
> USENET is *not* the non-clickable part of WWW!
>                                                            //
> www.muc.de/~gert/
> Gert Doering - Munich, Germany
> g...@greenie.muc.de
> fax: +49-89-35655025
> g...@net.informatik.tu-muenchen.de
>

Reply via email to