Saturday, July 31, 2010    
Home My Books Blog ColdFusion About Me Back    

Calendar
<< Jul 2010 >>
S M T W T F S
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
             

Search

Categories
 • Acrobat (5) [RSS]
 • Adobe (96) [RSS]
 • AdobeMAX06 (45) [RSS]
 • AdobeMAX07 (59) [RSS]
 • AdobeMAX08 (66) [RSS]
 • AdobeMAX09 (39) [RSS]
 • AdobeMAX10 (7) [RSS]
 • AIR (233) [RSS]
 • Appearances (198) [RSS]
 • Books (78) [RSS]
 • CFEclipse (15) [RSS]
 • ColdFusion (1409) [RSS]
 • ColdFusion Builder (9) [RSS]
 • Data Services (36) [RSS]
 • Fish Tank (5) [RSS]
 • Flash (248) [RSS]
 • Flex (513) [RSS]
 • Home Automation (5) [RSS]
 • Jobs (119) [RSS]
 • JRun (14) [RSS]
 • Labs (47) [RSS]
 • LiveCycle (35) [RSS]
 • MAX (238) [RSS]
 • Mobile (138) [RSS]
 • Regular Expressions (18) [RSS]
 • RIA (21) [RSS]
 • SQL (42) [RSS]
 • Stuff (543) [RSS]
 • Tips (CF Studio) (80) [RSS]
 • Tips (CF) (795) [RSS]
 • Tips (Dreamweaver) (91) [RSS]
 • Tips (Flex Builder) (2) [RSS]
 • Using CF (164) [RSS]

Other BLOGs
 • Charlie Arehart
 • Lee Brimelow
 • Ray Camden
 • Christophe Coenraets
 • Sean Corfield
 • Mihai Corlan
 • Cornel Creanga
 • Mark Doherty
 • John Dowdell
 • Danny Dura
 • Enrique Duvos
 • Steven Erat
 • Kevin Hoyt
 • Serge Jespers
 • Adam Lehman
 • Duane Nickull
 • Miti Pricope
 • Andrew Shorten
 • Ryan Stewart
 • James Ward
 • Greg Wilson
 • Full As A Goog

RSS Feeds
 • Feed
 • Subscribe

Join my mailing list and find out about new books and other topics of interest.

Thoughts, ideas, tips, musings, and pontifications (not necessarily in that order) by Ben Forta ...
NOTE: This is my personal blog, and the opinions and statements voiced here are my own.

Viewing By Entry / Main
September 8, 2005

Damon Cooper: RDS For CFEclipse In The Works

As blogged back in June, we announced at CFUNITED that the ColdFusion team would be working with and supporting the CFEclipse project. As noted in that keynote, RDS support is the most requested CFEclipse enhancement, and today Damon Cooper blogged that this feature is indeed in the works, one way that we are contributing to this community effort.

Comments
Since I couldn't find a way to post a comment on Damon's site I'm asking here.

Will the RDS code be part of CFEclipse codebase? Or will Macromedia only contribute closed source RDS library? Will MM go open source or protect it's proprietary protocol?
# Posted By Erki Esken | 9/9/05 1:51 AM
Erki, we'll know as we work that one through. But, my gut feel is that it would not be a good idea to fully expose the source for RDS as that may create potential security problems. But that is just my opinion. We'll know for sure once we're done.
# Posted By Ben Forta | 9/9/05 10:01 AM
Hasn't "security by obscurity" been debunked? Isn't the idea that open source--Linux, Firefox, etc.--is more secure because more people can examine the code for security flaws? Macromedia may have valid business reasons for keeping the RDS protocol proprietary (which may make some open source people unhappy), but don't use security as an excuse.
# Posted By anonymous | 9/9/05 11:08 AM
anonymous = coward = you don't get a response
# Posted By Ben Forta | 9/9/05 11:15 AM
Ben I agree with the anonymous guy there.

Your surly familiar with the saying security by obscurity is not security at all.

I can understand why MM might not want to release the source code for business reasons - but I'm quite surprised you cite security reasons.

I think it would be in the benefit of the community to further explain that statement.
# Posted By Pete Freitag | 9/9/05 11:42 AM
While it is good to see that Macromedia is taking first steps with CFEclipse, I was hoping for something more impactful.

It's my opinion that RDS is inherently insecure and unless there are changes to CFMX 7+ (signficant ones), there's really no point in using it.

How about we instead incorparate the database features and the component features that RDS provides in CFEclipse without relying on RDS and just forget the thing exists...

Resource access through a single password = very bad in my opinion.
# Posted By Calvin Ward | 9/9/05 12:48 PM
Whoa, slow down. I did not suggest that obscurity would secure anything. Nor did I say that fully exposing RDS would expose security vulnerabilities. Nor did I say that we'd not do so, and that if not that that would be the reason we'd not.

What I did say was that my gut feel on this one tells me that RDS has always served a very limited and restricted role, and one that we've controlled both ends of the pipe of. And when you do control both ends of the pipe the connection is easier to secure. That is not suggest that if we did not control both ends that it would not be secure, but I am suggesting that before we did open it up we'd need to really think through what the potential security implications may be, if there are any. It's not that I think there will be issues, it's that I don't know that we know there won't be any.

As I said in the opening words of my comment, we'll know as we work it through.
# Posted By Ben Forta | 9/9/05 2:18 PM
Hi Ben,

It seems to me that there are at least two meanings associated with RDS. One is the ability to browse the file system or a remote database, and add/edit files. The other has to do with the ability to deploy files to remote servers. For example, in Homesite+ selecting a file and right clicking on it allows you to access a deployment option. That option brings up a dialog box that allows you select any RDS or FTP server one has defined and deploy the file. This is very powerful for those of us that deploy code to dev, qa, and integration environments during the development life cycle. I appreciate the concern about security above, but what I would like to know is this, does RDS support include the remote deployment functionality we know in Homesite+?
# Posted By john | 11/9/05 6:40 PM

  © Copyright 1997-2009 Ben Forta, All Rights Reserved