Solved

Is bonjour secure?

Posted on 2010-09-19
3
909 Views
Last Modified: 2012-05-10
I want to run an app on my iPad that needs bonjour to sync to a file on my desktop.  Is bonjour secure enough to run in an enterprise environment? Thanks.
0
Comment
Question by:Mike London
3 Comments
 
LVL 8

Accepted Solution

by:
hello_everybody earned 250 total points
ID: 33710990
This is from Wikipedia .


"Bonjour  is sometimes misunderstood to make services on a personal computer (for  instance, file sharing) available to the public Internet, which could  be considered a security risk. In fact, Bonjour does not provide any  extra access to services, even on the same local area network (LAN); it  merely announces ("advertises") their existence. For example, a user can  browse a list of nearby computers which share files—Bonjour on these  computers has told the user that the service is available—but he or she  must still provide a password to access any protected files on these  machines. Additionally, Bonjour works only in a close range; by default,  its messages only reach users of the same link. Thus, the security  impact of Bonjour is that advertised services are no longer protected by  security through obscurity on the local network. If the services are  protected through a means other than obscurity, they will remain  protected. However, given the security ability of the general user, this  may represent a significant change in the user's security level."                                                            
0
 

Author Comment

by:Mike London
ID: 33711005
I did see that, thanks.  I was just looking for further confirmation that this is correct and that there are no other security implications.

Thanks.
0
 
LVL 20

Assisted Solution

by:woolnoir
woolnoir earned 250 total points
ID: 33714348
As the first expert commented on it does nothing more than announce services - this is often OK, but there is logic in not doing that from a security point of view. Annoying something makes it visible & proves a degree if information as to what system/OS/patches something is running - or certainly provides a prompt to check. On a enterprise INTERNAL network such as yours i wouldn't be TOO worried about it .. there shouldnt be any attackers in general as the perimeter/edge security systems shoudl secure you to a degree.

I'm not sure if you are IT within your company ( the fact you have the permissions to install software suggests maybe ? ) either way, make sure no policies exist which prevent this, or make it against policy to do so... if in doubt ASK....
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Dell Precision 5510 Downgrade to Windows 7 Pro 5 97
Command prompt flashing when starting PC 16 74
Tethering question 5 19
Non admin needs to install programs 17 32
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
By default the complete memory dump option is disabled in windows . If we want to enable the complete memory dump for a diagnostic purpose, we have a solution for it. here we are using the registry method to enable this.
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question