I too also have a special place of hate for Rekordbox. However I'm somewhat confused by this vulnerability, isn't plug n play unauthenticated file access essentially a core feature of "PRO DJ LINK"? The security mitigation, and best practice, being to have the involved devices connected on a entirely private LAN. I've never tried connecting them to a "public" network.
The feature definitely does what it says it does, but I think that the mount is generally accessible outside the software may be where the “surprise” lies.
I definitely would not have used this feature on a public network or exposed the mount to the open internet as well.
You and crtasm both make an excellent point about where the problem lies. I suffered from a critical imagination failure by never considering the implications of running the link on anything other then a controlled and isolated network.
Comments
I too also have a special place of hate for Rekordbox. However I'm somewhat confused by this vulnerability, isn't plug n play unauthenticated file access essentially a core feature of "PRO DJ LINK"? The security mitigation, and best practice, being to have the involved devices connected on a entirely private LAN. I've never tried connecting them to a "public" network.
The feature definitely does what it says it does, but I think that the mount is generally accessible outside the software may be where the “surprise” lies.
I definitely would not have used this feature on a public network or exposed the mount to the open internet as well.
You and crtasm both make an excellent point about where the problem lies. I suffered from a critical imagination failure by never considering the implications of running the link on anything other then a controlled and isolated network.
Access to files in your rekordbox library yes, but this sounds like it may be allowing access to any file on your computer/USB stick.