Announcements
Security Notices
Advisory ID: ZSL-2020-5595
1min
oct 20, 2020 this page outlines how not following the recommended security policies can expose users to vulnerabilities including zsl 2020 5595 https //www zeroscience mk/en/vulnerabilities/zsl 2020 5595 php the brightsign player security docid\ ecb hwei2wjvvcqlxpd1x statement is intended to explain the tradeoffs between accessibility and security that users of brightsign players need to consider for various different applications generally speaking, more accessible players are less secure and less accessible players are more secure when the local diagnostic web server is turned on and is not password protected, the player is at it's most accessible while this is the recommended configuration for development and lab applications where accessibility is preferred and often critical for troubleshooting issues and bugs, this accessibility also means that a potential bad actor have full access to storage, the runtime, the networking interface and other aspects of the system consequently, any security testing that does not follow our security recommendations are not cause for action by brightsign please be sure to refer to brightsign player security docid\ ecb hwei2wjvvcqlxpd1x for further details