Open main menu

Linux and Unix Users Group at Virginia Teck Wiki β

Changes

DyKnow

300 bytes added, 22:01, 10 February 2012
no edit summary
'''DyKnow Vision''' is proprietary classroom software made by Dynamic Knowledge Transfer, LLC and used by the [[College of Engineering]] at Virginia Tech. It is mostly written in C# but has many native components and cannot be run with [[Mono]]. Attempts to run it under [[w:Wine (software)|Wine]] have been unsuccessful. Both DyKnow Vision and DyKnow Monitor are known to contain malware-style features allowing for remote screen capture and forced full-screen.
==Malware Features==
Occasionally, professors have enabled the malware features of DyKnow Vision in class, forcing full-screen mode and spying on students. More specific information regarding this would be informative. In earlier versions of DyKnow, certain key combinations could easily break the forced full-screen mode. Unless students give consent to have their privacy invaded by merely showing up to class and running required software, the malware functionality breaks the [http://www.vt.edu/about/acceptable-use.html Virginia Tech Acceptable Use Policy], but to date, this hasn't seem to have garnered any attention.
DyKnow Monitor, which comes bundled in some versions of DyKnow Vision, includes malware-style features such as application and URL blocking, remote opening and closing of programs and displays of student screens. <ref>[http://www.dyknow.com/wp-content/uploads/2011/05/monitor54.pdf]</ref> DyKnow Monitor can be prevented from installing by editing the MSI to set a DONT_INSTALL_MONITOR flag. In the current version of DyKnow provided by Virginia Tech, the DONT_INSTALL_MONITOR flag is set by default. However, DyKnow Vision retains many malware features, such as forced full-screen mode and remote screen-capture.
DyKnow Monitor will continue to run even after DyKnow Vision is closed if it is not properly stopped by the instructor.<ref>[http://www.ahs.dcps.org/its/resources/dyknow.htm]</ref>
==Running the Proprietary Software=====Virtual Machines===
DyKnow runs fine in virtualized environments such as [[w:VirtualBox|VirtualBox]]. Using a virtual machine is a nice way to soften the effects of its malware capabilities.
===Making the Installer Skip Dependencies===
The web-based dependency installer is broken under wine, but if you trick it into skipping dependencies, you can at least get DyKnow Vision installed. To do so, you'll need to run the DyKnow installer with Wine then delete the dependency entries from a temporary folder in <code>c:\windows</code>.
==Security==
In the spring of 2009, the [[gp:IT Security Office|IT Security Office]] and DyKnow were alerted that the login process was unsafe. Passwords are sent by DyKnow over the wire as an [[w:MD5|MD5 hash]] with a static [[w:Salt (cryptography)|salt]] and symmetrically encrypted with [[w:Advanced Encryption Standar|AES]]. While the salted MD5 hash is invulnerable to standard [[w:Rainbow table|precomputation attacks]], the symmetric encryption was performed with key information shared between all clients, allowing for simple decryption if the traffic can be intercepted. Within a month of notification, the issue was worked around at Virginia Tech. Users were instructed to enable SSL for transactions and unencrypted access to the server was shut off. No response from DyKnow on this issue is known of.
If it is preferable for the traffic to remain unencrypted for some time, using [[socat]] as a [[Socat#Cleartext_to_SSL_Tunnel_for_DyKnow|plaintext-to-SSL proxy]] allows the final end of the connection to be encrypted but the initial segment to remain unencrypted.
==Patents==
DyKnow has been granted three [[w:Software patent|software patents]].
* [http://www.google.com/patents/about?id=yY94AAAAEBAJ US 7003728]
* [http://www.google.com/patents/about?id=0AC6AAAAEBAJ US 7508354]
==References==<references/> ==External Links==
* [http://schoolcomputing.wikia.com/wiki/DyKnow DyKnow entry on the School Computing wiki]
* [[gp:Learning Technologies#Online Course Systems|Online Course Systems]] [http://www.edtech.vt.edu/ocs/dyknow/index.shtml DyKnow support page]
Anonymous user