Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security related questions #207

Closed
pacquiaowright opened this issue Mar 26, 2024 · 12 comments
Closed

Security related questions #207

pacquiaowright opened this issue Mar 26, 2024 · 12 comments
Labels
question ❔ An issue just asking some question

Comments

@pacquiaowright
Copy link

I serve as a member of the Information Security Team for Burns & McDonnell. There has been a request by one or more of my colleagues to start using this tool, and I was looking for the best point of contact who would be open to answering a few security-related questions, thank you.

@Nice3point
Copy link
Collaborator

Hi @pacquiaowright what problems?

@jeremytammik
Copy link
Owner

dear @pacquiaowright , this is the point of contact right here. please raise your questions right here. thx.

@pacquiaowright
Copy link
Author

pacquiaowright commented Mar 27, 2024 via email

@Nice3point Nice3point added the question ❔ An issue just asking some question label Mar 27, 2024
@jeremytammik
Copy link
Owner

jeremytammik commented Mar 28, 2024

dear michael, none of the above is applicable to RevitLookup. It does not collect any data, it does not store any data, and it does not transfer any data anywhere. it works purely locally in real-time, enabling interactive navigation of the Revit BIM database and displaying results to the local user on the screen. in detail:

  1. Who has access to BMcD data

nobody. the local user can view Revit BIM data on the screen, but nothing is stored, transferred, or made available to anyone else.

  1. Security controls in place, based on whether the application is cloud-based or a local install

this is a local install.

  1. Applicable terms & conditions and/or end user license agreement (EULA)

MIT license.

  1. Development timeline & roadmap

no roadmap available. no support for third-party integration.

@pacquiaowright
Copy link
Author

pacquiaowright commented Mar 28, 2024 via email

@jeremytammik
Copy link
Owner

i do not think this discussion has much sense. i also do not see any screen snapshot to refer to, just a description saying "[A screenshot of a computer Description automatically generated]". RevitLookup has no security relvant aspects that i am aware of, or at least no more than any other locally run desktop app, e.g., Windows Notepad app.

@pacquiaowright
Copy link
Author

pacquiaowright commented Mar 28, 2024 via email

@jeremytammik
Copy link
Owner

please realise that this conversation feels like a huge waste of time to me. RevitLookup is open source, and you can analyse al of the aspects you ask about for yourself if you care. i don't know the details about all of the above, but my tendency would be to answer "no' to most or all of them. check it out for yourself if you care. it is all open for your inspection, afaik.

@pacquiaowright
Copy link
Author

To my best knowledge, I am not able to view the settings above without the assistance of a Contributor such as yourself.
If you or another Contributor who is familiar with these settings is able to respond I would appreciate it.

Please understand, I respect your time and the effort by you and all the contributors to make this a useful plugin that is in demand across the globe. I do not want to waste your time by any means. The purpose of my line of enquiry is so I can establish a level of confidence with my colleagues and our clients that the contributors for the RevitLookup plugin are following industry best practices with regards to the management of code security and vulnerabilities that could pose a threat to sensitive data if exploited by an adversary that does not have our best interests in mind.

@jeremytammik
Copy link
Owner

jeremytammik commented Mar 28, 2024

the best way to achieve the purpose you describe is to fork this directory, grab the code that is of use and interest to you, and create your own add-in from the paerts that you need. why trust a third party with anything whatsoever? i prefer to avoid doing so myself. :-)

@Nice3point
Copy link
Collaborator

RevitLookup does not contain any code that would violate the user's privacy. You won't find any known vulnerabilities here, we only use tested and reliable dependencies from Microsoft. These security questions don't make any sense, we don't collect metrics or other things

@pacquiaowright
Copy link
Author

@jeremytammik and @Nice3point thank you both for your responses.

@jeremytammik I will investigate your suggestion. I appreciate your patience and consideration.

I'll close this comment for now. If I have additional questions, I'll open a new thread. Thank you both.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question ❔ An issue just asking some question
Projects
None yet
Development

No branches or pull requests

3 participants