Allow disabling "Devolutions Send" to stop disproportionately simple mass exfiltration of passwords
0 vote
On March 5th, 2024 (Version 2024.1.5.1) the password sharing service "Devolutions Send" has been added to the Remote Desktop Manager.
In short, it is a service that allows you to share passwords from your datasource with users who do not have access to this datasource. It is a good alternative to emails and chats, as Devolutions Send is using end to end encryption, but there is a major caveat:
It is enabled by default and can't be turned off.


We don't know how Devolutions did not see the potential to use this as a mass exfiltration tool for malicious users, and their support team leader told us we're the first and only customer to mention this, and we should therefore create a feature request... A feature request for a fundamental safety precaution... alongside 3900 other feature requests (130 pages with 30 posts each) that have been lying around here for 15 years. It's wonderful to see what kind of service you get as a paying customer.
The only workaround they've provided is revoking the "View Password" permission for all users, which makes copying and using a password outside of the RDM impossible. It would be a trivial fix to introduce a database-level setting to control Devolutions Send or to introduce a new permission.
942964e0-b305-49ac-b75d-c2110185d81a.png
43e15deb-5e84-4758-a460-9182353ab2d9.png
17073de4-fb65-4963-8436-b4db1b1a1018.png
7f950c8e-0d60-472a-a079-62decb9bd280.png
Hello,
Thank you for reporting this issue.
We have notified the development team about this issue and will be addressing it as a high priority.
If you are using Devolutions Server, there is already an option to disable this feature, but it isn't handled properly by RDM. This will be corrected.
If you are using SQL, a system setting will be implemented to disable the feature.
Regards,
Mathieu Morrissette
Hello,
I have received news from the development team,
They have implemented a system setting and a GPO policy to disable Devolutions Send.
It will be available in the next Remote Desktop Manger release (2024.1.26).
Best regards,
Mathieu Morrissette