Dismiss Notice
We would like to remind you that we’re updating our login process for all 3CX forums whereby you will be able to login with the same credentials you use for the Partner or Customer Portal. Click here to read more.

Privacy issue in 3CX hosted: Block users on a different instance to see information of users on othe

Discussion in 'Ideas' started by Chib@voip, Apr 18, 2016.

  1. Chib@voip

    Joined:
    Feb 25, 2016
    Messages:
    21
    Likes Received:
    0
    3CX v14 Hosted has this option: Generate Support Info enabled for all users on all instances.

    Generate Support Info shows information for all instances on the server, not just the one you are logged into.
    This means that a user on instance 1 can download this support info and see names and extension info of users on instance 2,3,4 etc.

    We do not want to have our customers on instance 1 seeing the information of users on other instances.

    Things that can be seen of users on other instances:
    1.Full Name (if filled in),
    2. their Extension number,
    3. their local IP address,
    4. WAN IP address,
    5. Phone type and Firmware,
    6. SIP port,
    7. Hostname

    and probably more if you dig a little deeper.

    This kind of information should never be revealed to any other users on a different instance.

    I`m afraid that this can even become a legal issue in certain countries.

    We would like to see this option "Generate Support Info" being disabled by default on all instances, or at the least being made optional by the server admins.
     
  2. Chib@voip

    Joined:
    Feb 25, 2016
    Messages:
    21
    Likes Received:
    0
    Because I think this is a pretty serious issue, please UPVOTE this idea so this things will get added/changed asap.
     
  3. Anonymous

    Anonymous Guest

    I found extension numbers and IPs for other Instances in a single the Extralogging\tcxSystemEvents_**NumberString**.CSV file. This was evening using a limited account to look at the config page. I agree, this is troubling.
     
  4. Chib@voip

    Joined:
    Feb 25, 2016
    Messages:
    21
    Likes Received:
    0
    Privacy of users is at stake.
    This could get the 3CX hosting provider as well as 3cx in trouble.
     
  5. Chib@voip

    Joined:
    Feb 25, 2016
    Messages:
    21
    Likes Received:
    0
    Bump. I hope this security feature (disabling Generate Support Info) is going to be implemented in V15. Anybody knows?

    I don`t think we should rely on votes to take this privacy "idea" seriously.
     
  6. Chib@voip

    Joined:
    Feb 25, 2016
    Messages:
    21
    Likes Received:
    0
    Update:

    I am now testing on a V15 (virtual) machine and when I select Generate Support info, the admins are getting an e-mail notification with a downloadable Zip file. Not the user!

    3CX V15 has implemented this idea.. thanks!
     
  7. Nick Galea

    Nick Galea Site Admin

    Joined:
    Jun 6, 2006
    Messages:
    1,971
    Likes Received:
    280
    The MULTI TENANT version has been retired. The best way to host is now using a virtual dedicated instance of 3CX
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. Chib@voip

    Joined:
    Feb 25, 2016
    Messages:
    21
    Likes Received:
    0
    Thats probably why then. Thanks for clarifying