Allow disabling "Devolutions Send" to stop disproportionately simple mass exfiltration of passwords

Implemented

Allow disabling "Devolutions Send" to stop disproportionately simple mass exfiltration of passwords

0 vote

avatar

On March 5th, 2024 (Version 2024.1.5.1) the password sharing service "Devolutions Send" has been added to the Remote Desktop Manager.

In short, it is a service that allows you to share passwords from your datasource with users who do not have access to this datasource. It is a good alternative to emails and chats, as Devolutions Send is using end to end encryption, but there is a major caveat:

It is enabled by default and can't be turned off.

7f950c8e-0d60-472a-a079-62decb9bd280

17073de4-fb65-4963-8436-b4db1b1a1018

43e15deb-5e84-4758-a460-9182353ab2d9

We don't know how Devolutions did not see the potential to use this as a mass exfiltration tool for malicious users, and their support team leader told us we're the first and only customer to mention this, and we should therefore create a feature request... A feature request for a fundamental safety precaution... alongside 3900 other feature requests (130 pages with 30 posts each) that have been lying around here for 15 years. It's wonderful to see what kind of service you get as a paying customer.



The only workaround they've provided is revoking the "View Password" permission for all users, which makes copying and using a password outside of the RDM impossible. It would be a trivial fix to introduce a database-level setting to control Devolutions Send or to introduce a new permission.

942964e0-b305-49ac-b75d-c2110185d81a.png

43e15deb-5e84-4758-a460-9182353ab2d9.png

17073de4-fb65-4963-8436-b4db1b1a1018.png

7f950c8e-0d60-472a-a079-62decb9bd280.png

All Comments (2)

avatar

Hello,

Thank you for reporting this issue.

We have notified the development team about this issue and will be addressing it as a high priority.

If you are using Devolutions Server, there is already an option to disable this feature, but it isn't handled properly by RDM. This will be corrected.
If you are using SQL, a system setting will be implemented to disable the feature.

Regards,

Mathieu Morrissette

avatar

Hello,

I have received news from the development team,

They have implemented a system setting and a GPO policy to disable Devolutions Send.
It will be available in the next Remote Desktop Manger release (2024.1.26).

Best regards,

Mathieu Morrissette