?
Solved

Is bonjour secure?

Posted on 2010-09-19
3
Medium Priority
?
1,040 Views
Last Modified: 2012-05-10
I want to run an app on my iPad that needs bonjour to sync to a file on my desktop.  Is bonjour secure enough to run in an enterprise environment? Thanks.
0
Comment
Question by:Mike London
3 Comments
 
LVL 8

Accepted Solution

by:
hello_everybody earned 1000 total points
ID: 33710990
This is from Wikipedia .


"Bonjour  is sometimes misunderstood to make services on a personal computer (for  instance, file sharing) available to the public Internet, which could  be considered a security risk. In fact, Bonjour does not provide any  extra access to services, even on the same local area network (LAN); it  merely announces ("advertises") their existence. For example, a user can  browse a list of nearby computers which share files—Bonjour on these  computers has told the user that the service is available—but he or she  must still provide a password to access any protected files on these  machines. Additionally, Bonjour works only in a close range; by default,  its messages only reach users of the same link. Thus, the security  impact of Bonjour is that advertised services are no longer protected by  security through obscurity on the local network. If the services are  protected through a means other than obscurity, they will remain  protected. However, given the security ability of the general user, this  may represent a significant change in the user's security level."                                                            
0
 

Author Comment

by:Mike London
ID: 33711005
I did see that, thanks.  I was just looking for further confirmation that this is correct and that there are no other security implications.

Thanks.
0
 
LVL 20

Assisted Solution

by:woolnoir
woolnoir earned 1000 total points
ID: 33714348
As the first expert commented on it does nothing more than announce services - this is often OK, but there is logic in not doing that from a security point of view. Annoying something makes it visible & proves a degree if information as to what system/OS/patches something is running - or certainly provides a prompt to check. On a enterprise INTERNAL network such as yours i wouldn't be TOO worried about it .. there shouldnt be any attackers in general as the perimeter/edge security systems shoudl secure you to a degree.

I'm not sure if you are IT within your company ( the fact you have the permissions to install software suggests maybe ? ) either way, make sure no policies exist which prevent this, or make it against policy to do so... if in doubt ASK....
0

Featured Post

Upgrade your Question Security!

Add Premium security features to your question to ensure its privacy or anonymity. Learn more about your ability to control Question Security today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick guide on how to use Group Policy to create a custom power plan and set it active on Windows 7.
On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
This Micro Tutorial will teach you the basics of configuring your computer to improve its speed. It will also teach you how to disable programs that are running in the background simultaneously. This will be demonstrated using Windows 7 operating…
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.
Suggested Courses
Course of the Month17 days, 4 hours left to enroll

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question