Page 2 of 3

Re: CarotDAV

Posted: Mon Sep 22, 2014 8:14 am
by giulia
Hi
may i ask you if it's stealth?
i give a short test and looks stealth
i noticed that some users asked it

thanks

Re: CarotDAV

Posted: Fri Nov 21, 2014 11:46 am
by Ruby
A note about Security/Privacy - from the main download page (at bottom)

About Security
By default, passwords are saved with no encryption.
- In the setting file, there are login IDs and raw passwords. By default, it is not encrypted. If you want to avoid risk, use master password.

WebDAV server doesn't support user authentication or SSL/TLS.
- Since WebDAV server of CarotDAV is designed for local use, it becomes dangerous if the settings are wrong. Use loopback address(127.0.0.1) to prevent access from others.

During OAuth procedure, CarotDAV shows the other site.
- Some services needs HTTPS server during OAuth. Since this site doesn't support HTTPS, CarotDAV use this page instead. I assure that site is safe in the same way as CarotDAV.

About Privacy
CarotDAV accesses version file to confirm update on boot. Below informations are logged on the server at that time.

- Current version of CarotDAV you use.
- Access Time.
- IP Address.
I keep these logs not to be seen from others as possible. I might use or public these information after statistical processing. I might show these logs to public institution if they claim.

CarotDAV and I collect no other information.

~Ruby

Re: CarotDAV

Posted: Fri Nov 21, 2014 5:26 pm
by webfork
During OAuth procedure, CarotDAV shows the other site.
- Some services needs HTTPS server during OAuth. Since this site doesn't support HTTPS, CarotDAV use this page instead. I assure that site is safe in the same way as CarotDAV.

I keep these logs not to be seen from others as possible. I might use or public these information after statistical processing. I might show these logs to public institution if they claim.
Wish I knew what any of this meant. So he has logs that he'll share if he's asked to? The HTTPS uses what page?

Not very encouraging. Thanks for pointing out, Midas.

Re: CarotDAV

Posted: Fri Nov 21, 2014 10:44 pm
by SYSTEM
webfork wrote:So he has logs that he'll share if he's asked to?
I think he's saying that he'll share the logs if he's legally required to do so.
webfork wrote:The HTTPS uses what page?
This page: https://reito.securesite.jp/oauth.html. The words "this page" are a link in the download page.
webfork wrote:Not very encouraging. Thanks for pointing out, Midas.
You mean Ruby. :P

Re: CarotDAV

Posted: Sat Nov 22, 2014 7:25 pm
by Midas
SYSTEM wrote:You mean Ruby. :P
  • Indeed. :mrgreen:

Re: CarotDAV

Posted: Sat Nov 22, 2014 7:48 pm
by webfork
SYSTEM wrote:You mean Ruby. :P
Hehe :) yep sorry

Re: CarotDAV

Posted: Thu Dec 18, 2014 9:15 am
by sinilill
I'm always getting this error, but it uploads successfully!
Image

Re: CarotDAV

Posted: Fri Mar 13, 2015 5:00 am
by Joe
I need some help with CarotDAV. Ever since I upgraded to version 1.11.13 I can't connect to my Box.com account anymore. Not being able to connect is one thing but what really has me concerned is the error message I get from Box (see below).

Image

Now I'm not technical enough to understand everything but when I try to re-authorize the connection with Box I do see that it appears to be redirecting to https://reito and that is what has me concerned. Should I be worried?

Re: CarotDAV

Posted: Fri Mar 13, 2015 6:06 am
by I am Baas

Re: CarotDAV

Posted: Fri Mar 13, 2015 7:56 am
by Joe
Thank you Baas. V14 does allow me to connect to Box once again. However, what about the redirecting to https://reito . Should I be worried?

BTW, I don't understand the purpose of this "Pronama-chan" feature. Clicking on it opens a big manga character on my screen which blocks whatever is underneath. This stupid manga character also remains on top no matter what I do.

Image

Right-clicking that manga figure brings up a context menu. If I click on one of the connection options I have to enter my master password again even though I entered my password to start CarotDAV in the first place! OK, so I go ahead still and enter my password yet again and now it opens another instance of CarotDAV! Another option opens my web browser on some Japanese website for Pronama-chan but it has nothing to do with CarotDAV!! Also, there's a manga figure on the CarotDAV interface now and it makes it more difficult to see certain information.

Image

What the heck is going on? This Pronama-chan feature or whatever-you-may-call-it is completely useless to me. Instead of enhancing my experience this crap is driving me crazy! I really have to dump CarotDAV and find a better solution. Thanks for nothing Carot.

[EDIT]
OK. I figured out how to get rid to of the manga figure that's obscuring information on the interface (see the last image in this post). For the benefit of anyone wishing to do the same here's what to do:
  • 1. Go to the folder/directory where you have CarotDAV.
    2. Look for a file named pronama.png.
    3. Right-click pronama.png and rename it to something else. E.g. I renamed mines to pronama_backup.png. (Note: You could also delete the file but I prefer to rename it in case I want to restore it later).
    4. Open an image editor and create a new image that's 270 pixels wide by 165 pixels high. (I used GIMP to create the image, but heck, you could use MS Paint for that matter).
    5. Save the image as pronama.png in CarotDAV's folder.
    6. Start CarotDAV - ta da, no more manga figure.
    7. Remind yourself NOT to click on Pronama-chan.
Enjoy! :wink:

Re: CarotDAV

Posted: Fri Mar 13, 2015 8:58 am
by Checker
I am Baas wrote:@Joe

See if http://rei.to/CarotDAV1.11.14.portable.zip fixes that?
Thanks ... and updated :wink:

Re: CarotDAV

Posted: Sat Mar 14, 2015 1:02 am
by rei
you can remove background manga-charactor by deleteting "pronama.png" in the CarotDAV folder.

Re: CarotDAV

Posted: Sat Mar 14, 2015 1:36 am
by SYSTEM
Joe wrote:Thank you Baas. V14 does allow me to connect to Box once again. However, what about the redirecting to https://reito . Should I be worried?
That was already discussed in this thread.
CarotDAV download page wrote: During OAuth procedure, CarotDAV shows the other site.

Some services needs HTTPS server during OAuth. Since this site doesn't support HTTPS, CarotDAV use this page instead. I assure that site is safe in the same way as CarotDAV.
In other words, you don't need to be worried. :)

Re: CarotDAV

Posted: Sat Mar 14, 2015 8:47 am
by Joe
SYSTEM wrote:In other words, you don't need to be worried. :)
Thank you. Somehow I missed that. :oops:

Re: CarotDAV

Posted: Sat Mar 14, 2015 12:14 pm
by webfork
rei wrote:you can remove background manga-charactor by deleteting "pronama.png" in the CarotDAV folder.
Added to main entry. What an annoying UI choice.