What are the dangers of installing the R2R root certificate?

Discussion in 'Software' started by TylerPage, Jul 30, 2022.

  1. TylerPage

    TylerPage Newbie

    Joined:
    Jul 30, 2022
    Messages:
    8
    Likes Received:
    0
    Hey,

    I've seen it being talked about a bit here and there already. But no one has really said what the actual dangers are of "blindly" trusting r2r and installing there root certificate that is needed for Cubase? Im on the edge on if I should install it or go with the TC release of Cubase. I trust r2r but I dont want to open too many doors. Are MIM attacks possible or worse? Looking forward to someone who could shine some light onto this topic. Thank you in advance.
     
    • Agree Agree x 1
    • Funny Funny x 1
    • Interesting Interesting x 1
    • List
  2.  
  3. DanielFaraday

    DanielFaraday Platinum Record

    Joined:
    May 20, 2015
    Messages:
    625
    Likes Received:
    247
    Location:
    Ukraine
    Best Answer
    It needs for installers only. If you're not downloading pseudo releases from weird sites - everything will be ok.
     
    • Winner Winner x 3
    • Agree Agree x 2
    • Like Like x 1
    • List
  4. iw

    iw Producer

    Joined:
    Sep 24, 2019
    Messages:
    222
    Likes Received:
    98
    The certificate is for code protection only. :)


    P.S. And the resale of R2R releases
     
    Last edited: Jul 30, 2022
  5. Stevie Dude

    Stevie Dude Audiosexual

    Joined:
    Dec 29, 2020
    Messages:
    2,195
    Likes Received:
    1,923
    Location:
    Near Nyquist
    that's the beauty of it! nobody knows! It's always better to live dangerously and die young.
     
  6. TylerPage

    TylerPage Newbie

    Joined:
    Jul 30, 2022
    Messages:
    8
    Likes Received:
    0
    Yes while its true that its needed mostly for the installation you have to keep it on your pc for the program to work. Im also not talking about what other people could do with it but more so what r2r (IF they had malicious intent) could do with such access to my pc.
     
  7. TylerPage

    TylerPage Newbie

    Joined:
    Jul 30, 2022
    Messages:
    8
    Likes Received:
    0
    Yes Ive read already that its used mostly to be able to identify the right releases and check that its a legitimate r2r release and not something that has been tempered with. For the cubase release you have to have it on your pc however. And Ive read that if they have a root certificate on your pc that they can read and redirect your internet traffic. Im just worried and interested in what r2r (if they had malicious intent) could do with such access.
     
  8. TylerPage

    TylerPage Newbie

    Joined:
    Jul 30, 2022
    Messages:
    8
    Likes Received:
    0
    Lol, wise words to live by.

    Also realizing now I should have used the multiquote tool.
     
  9. iw

    iw Producer

    Joined:
    Sep 24, 2019
    Messages:
    222
    Likes Received:
    98
    If you think that after so much free software, R2R will do something to your computer, you should not install it..
     
    • Agree Agree x 3
    • Like Like x 1
    • Winner Winner x 1
    • Interesting Interesting x 1
    • List
  10. DanielFaraday

    DanielFaraday Platinum Record

    Joined:
    May 20, 2015
    Messages:
    625
    Likes Received:
    247
    Location:
    Ukraine
    You can turn on firewall. In most cases Their software actually blocked from network access.
     
  11. iw

    iw Producer

    Joined:
    Sep 24, 2019
    Messages:
    222
    Likes Received:
    98
    V.R also install certificate. But it installed silently without you knowing.
     
  12. DoubleTake

    DoubleTake Audiosexual

    Joined:
    Jul 16, 2017
    Messages:
    2,194
    Likes Received:
    1,151
    It is all about knowing who to trust, in what ways, and to what degrees.
    I trust people to be human and try to avoid unfair expectations.
    I trust r2r with software.
    Do i trust them with my girlfriend?
    Maybe not...
     
    • Like Like x 3
    • Funny Funny x 2
    • Agree Agree x 1
    • List
  13. DoubleTake

    DoubleTake Audiosexual

    Joined:
    Jul 16, 2017
    Messages:
    2,194
    Likes Received:
    1,151
  14. Genoveva Bernhard

    Genoveva Bernhard Producer

    Joined:
    Jan 31, 2022
    Messages:
    135
    Likes Received:
    124
    I was curious myself, so I did some snooping around on the interweb. From what I saw, Trusted Root Certificates should only be activated, under Intended Purposes, for one or a few things only, unless it's Microsoft then it can say <All>. I hadn't realized TeamVR had installed a certificate. Not only that, but it said <All>! That would give the bearer of the certificate free rein to worm its way through your computer as it saw fit, that's why an outgoing firewall is important. I use Tiny Wall. R2R's certificate is R2RCA and, under Intended Purposes, it says Code Signing alone. That puts my mind at ease.

    To access the trusted root page on Windows: Windows key + R, Trusted Root Certification Authorities, Certificates.
     
    • Like Like x 1
    • Useful Useful x 1
    • List
  15. iw

    iw Producer

    Joined:
    Sep 24, 2019
    Messages:
    222
    Likes Received:
    98
    V.R
     
    • Useful Useful x 2
    • Interesting Interesting x 1
    • List

    Attached Files:

  16. BlackHawk

    BlackHawk Producer

    Joined:
    Nov 28, 2021
    Messages:
    196
    Likes Received:
    100
    Wrong question. Do you trust your girlfriend is the right question.
     
    • Funny Funny x 2
    • Like Like x 1
    • Agree Agree x 1
    • List
  17. Zenarcist

    Zenarcist Audiosexual

    Joined:
    Jan 1, 2012
    Messages:
    3,928
    Likes Received:
    2,503
    Location:
    Planet Earth
    Bankruptcy.
     
    • Funny Funny x 1
    • Interesting Interesting x 1
    • List
  18. TylerPage

    TylerPage Newbie

    Joined:
    Jul 30, 2022
    Messages:
    8
    Likes Received:
    0
    This is very very useful information. I didnt realize it had only signing as the written intended purpose. But it also looks like this field doesnt really matter to what the certificate really does. Couldnt you just put whatever in there and then use it to decrypt internet traffic? I never installed TeamVR and I realized that the TC release is similar to the VR one? Atleast people in the comments have been saying that.

    I dont doubt that r2r wont use it maliciously but at the same time my mind just is not at ease as long as I dont exactly know what can be done with a root certificate. I saw a paper that talked about it making unlegitimate software look like legitimate one to the user of the pc but that wouldnt really matter as much. Ive also read that it can decrypt and read your traffic but then there is also difference between browser root certificates and machine ones. Its all super confusing.
     
  19. TylerPage

    TylerPage Newbie

    Joined:
    Jul 30, 2022
    Messages:
    8
    Likes Received:
    0
    That came before already :rofl:.
     
  20. TylerPage

    TylerPage Newbie

    Joined:
    Jul 30, 2022
    Messages:
    8
    Likes Received:
    0
    Yes that has some truth to it. Especially since it would probably be much easier to hide something in the software itself then letting the user install a root certificate.
     
  21. Riddim Machine

    Riddim Machine Rock Star

    Joined:
    Jul 3, 2021
    Messages:
    510
    Likes Received:
    420
    Location:
    Jamaica
    I trust R2R more than Facebook and Google. Damn, man... all those apps installed at your computer and cellphone are doing sh*t to your privacy, so i suggest stop using those algorithms and start making keygen music
     
    • Agree Agree x 2
    • Funny Funny x 1
    • List
Loading...
Similar Threads - dangers installing root Forum Date
ex-Googler Mo Gawdat Talks about Dangers of AI. Must See Lounge Jun 5, 2023
Hackintosh: Dangers? Mac / Hackintosh Aug 16, 2017
Installing Maschine along with NI cracked plugins. Maschine Mar 23, 2024
Installing Waves from scratch Software Mar 4, 2024
Issue reinstalling bobdule kontakt 7.7 (library tool not working) Kontakt Feb 15, 2024
Loading...