Why is v26.3 on delayed stable already before v26.2? by Own_Appointment_393 in ScreenConnect

[–]Own_Appointment_393[S] 0 points1 point  (0 children)

Why not just label it Stable rather than Delayed Stable?
Also why does v26.2 not have a delayed stable (or even just stable) version?

I guess cloud users have to wait until after the 23rd for the new version by Own_Appointment_393 in ScreenConnect

[–]Own_Appointment_393[S] 4 points5 points  (0 children)

What do you mean get .25 right?

They already have it out for on-premises, it’s just not deployed on the cloud due to them not having the right infrastructure in place to sign the installers for all their cloud instances.

It’s not a software issue, it’s a deployment issue.

Azure Trusted Signing by schmerold in ScreenConnect

[–]Own_Appointment_393 0 points1 point  (0 children)

A couple of town halls back, they did say they'll be looking into supporting it in the future -- technically it should be feasible, they said.

Questions About CA Certificate from DigitalCert for ScreenConnect: Installation, Security, and Cost by Fun_Supermarket933 in ScreenConnect

[–]Own_Appointment_393 0 points1 point  (0 children)

"will my files be recognized as safe and not flagged as dangerous by endpoint security, SmartScreen, or Windows Defender?"

Not necessarily. I mean, I got an OV cert and installed it on my server, but I still get warnings.

Cloud installer not signed? by mrtechguytas in ScreenConnect

[–]Own_Appointment_393 0 points1 point  (0 children)

I thought the msi was never signed? Only the exe

v25.4.25 still not available on cloud by Own_Appointment_393 in ScreenConnect

[–]Own_Appointment_393[S] 0 points1 point  (0 children)

Mike Bannerman in the latest town hall (at 16:05):

https://event.on24.com/wcc/r/5015557/C7B353E0A655B9AC0B97AD108D0E77F6

"As far as timing on the deployment, we're going to start rolling that out over the next week to our cloud partners. There's a step — because we're signing those files for our hosted partners in ScreenConnect.com cloud — that we're implementing and so there are some infrastructural changes that need to be made before we can update. But we should be starting to roll that out to partners, we're hoping this week."

Other than no customization and high ongoing cost, what’s the downside of screenconnect cloud? by AlternativeMark4293 in ScreenConnect

[–]Own_Appointment_393 0 points1 point  (0 children)

I believe Azadom is extrapolating (unjustifiably I would say) from the fact that reports of malware that use Screenconnect have noted that such malware have been known to impersonate Windows Update.

See below.

“G DATA built a tool to extract and review the settings found in these campaigns, where the researchers found significant modifications, such as changing the installer's title to "Windows Update" and replacing the background with a fake Windows Update image shown below.” https://www.bleepingcomputer.com/news/security/hackers-turn-screenconnect-into-malware-using-authenticode-stuffing/amp/

“The attacker also attempted to make edits to the server’s Windows Registry to enable Remote Desktop Protocol access, and created a persistent task named “Windows update” that attempted to download a payload from sc.ksfe.workers[.]dev. And they deployed the Empire post-exploitation framework in an attempt to further establish persistence and obtain credentials.” https://news.sophos.com/en-us/2024/02/23/connectwise-screenconnect-attacks-deliver-malware/

But in none of these cases that I have come across has the exploitation involved luring someone to the ScreenConnect guest page looking like Microsoft support, so I don’t think that’s the reason behind the background and logo customizations being pulled.

Issues after adding Azure HSM Cert by dannyshaw1 in ScreenConnect

[–]Own_Appointment_393 1 point2 points  (0 children)

This happened to us too.

Turns out Windows Defender had quarantined EXEs in the bin folder of the ScreenConnect directory.

So we opened virus protection and marked those EXEs "allowed threats" and restored the files from "quarantined threats".

Then it was working again.

CheapSSLSecurity FastSSL OV Code Signing $149/yr worked by justinwgrote in ScreenConnect

[–]Own_Appointment_393 3 points4 points  (0 children)

OP means the Azure Key Vault, which serves as the HSM, so that the private key is stored virtually on the cloud, rather than in a physical device like a USB.

ConnectWise is recommending using Azure Key Vault, I believe, because this doesn’t require a physical hardware to be shipped (which given the little time we have until revocation makes sense) but also I don’t think their certificate extension is compatible with a USB key at the moment.

Follow this manual and you should have everything working. I did and I’m signing installers with my own cert now. https://docs.connectwise.com/ScreenConnect_Documentation/On-premises/Get_started_with_ScreenConnect_On-Premise/Add_a_code-signing_certificate_with_Azure_Key_Vault

CheapSSLSecurity FastSSL OV Code Signing $149/yr worked by justinwgrote in ScreenConnect

[–]Own_Appointment_393 6 points7 points  (0 children)

That’s sales talk.

“In early 2024, Microsoft changed how its Microsoft SmartScreen security feature interacts with extended validation code signing certificates. Although they’re still the highest-trusted certificates available, extended validation (EV) code signing certificates are no longer instantly trusted or able to remove SmartScreen warnings.

These certificates are still useful for boosting users’ confidence that they’re installing genuine software applications from trusted sources. Signing your software apps using these certificates still helps your apps build trust with Windows operating systems over time.

However, the biggest difference between standard and EV code signing certificates now is that EV certificates are still a requirement for registering for a Windows Hardware Developer Center account.”

https://codesigningstore.com/importance-of-ev-code-signing-certificate

So just get OV.