Inventor Publisher
Welcome to Autodesk’s Inventor Publisher Forums. Share your knowledge, ask questions, and explore popular Inventor Publisher topics.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

FATAL SECURITY ISSUE with iPad viewer app

0 REPLIES 0
Reply
Message 1 of 1
training
362 Views, 0 Replies

FATAL SECURITY ISSUE with iPad viewer app

I'm writing a SWOT analysis of the end user security/deployment issues around A360 and deploying InvPub content to the iPAD/iPHONE, to get my head thru a wokable path to doing it thats not going to compromise our IP [im using this for sales and training]. This after reading the self agrandising security paper Autodesk have written about the back end security of A360. Well of course the back end is "secure", its the front end that they should sort out! 

 

When doing some more iPad testing I discover a worse security hole than the two I knew already existed: no app password to protect already downloaded files; and no way to remotely delete any previously downloaded data, incase it gets stolen. [I wont mention the undeletable demo content again].

 

---------

If you do what i did and login to download a file, and then hit the "Logout" button in the iPAD viewer [in theory you would think this would forget your login], so you have logged out with only one file on the app. 

If you then close and open the app about 3 times, you will find that it has logged itself in again!

This I discover after playing with it for 5 minutes. I really wonder if there is any testing of any of this at all. Its not fit for professional use.

---------

 

So not only does someone that gets your iPad, potentially have free access to already downloaded data, but its really easy for them to access all the files you had on your last login. [of course this relies on the iPad login, thats had lots of bugs and workarouds in the last few years.]

 

I'm intending to deploy interactive training and marketing content on the web and mobile versions but would love to hear of how other people have done it. I think the security issues around this are quite profound going forwards, and wonder how other people are managing the intellectual property issues around the 3D stuff? 

I cant seem to find any Autodesk information about best practice or use cases and am just trying to keep a lid on this as we are forced to use the cloud with no option to use our own servers. Our software supplier is little help on this either. 

 

Steve

Steven Dewar | STATS Group | 3D Animator

Win7Ent-64-SP1 | 32GB | Intel Core i7-4770CPU@3.40GHz | Quadro 4000 GPU
0 REPLIES 0

Can't find what you're looking for? Ask the community or share your knowledge.

Post to forums  

Autodesk Design & Make Report