Sweet! Works good! Thanks!*) make up/down keys select previous/next entry in address/neighbors list in connect window while login name or password fields are in focus;
*) make mouse wheel work anywere in connect window if login or password fields are in focus;
Nice to see a focus on security! Does the "new style authentication" in 6.43 include router/host verification so that man in the middle attacks are no longer possible?What's new in v3.14:
*) added support for new style authentication and encryption for connections to RouterOS v6.43;
*) make all connections in secure mode (all data is encrypted with AES128-CBC-SHA);
*) make winbox self upgrade check .exe signature;
It doesn't. It's just new way of password hashing SSH checks hosts.Does the "new style authentication" in 6.43 include router/host verification so that man in the middle attacks are no longer possible?
I just tested this.. it checks for a signature, but not Mikrotik's signature! I sign it myself and winbox blindly runs it*) make winbox self upgrade check .exe signature;
Is that really certificate based ? Or simply some MD5 hash ? In the later case this should not be called signature as this has nothing to do with a secure feature.I just tested this.. it checks for a signature, but not Mikrotik's signature! I sign it myself and winbox blindly runs it*) make winbox self upgrade check .exe signature;
https://imgur.com/7k8e09p
It checks that the .exe has authenticode signature (certificate based), but doesn't care who the signer is. It should verify that the Mikrotik public key is used.Is that really certificate based ? Or simply some MD5 hash ? In the later case this should not be called signature as this has nothing to do with a secure feature.I just tested this.. it checks for a signature, but not Mikrotik's signature! I sign it myself and winbox blindly runs it*) make winbox self upgrade check .exe signature;
https://imgur.com/7k8e09p
Yes, but to be honest, I can't imagine which other legitimate organisation would go to the trouble of using their Extended Validation certificate to sign Winbox It's not like it is simple to obtain.It checks that the .exe has authenticode signature (certificate based), but doesn't care who the signer is. It should verify that the Mikrotik public key is used.Is that really certificate based ? Or simply some MD5 hash ? In the later case this should not be called signature as this has nothing to do with a secure feature.I just tested this.. it checks for a signature, but not Mikrotik's signature! I sign it myself and winbox blindly runs it*) make winbox self upgrade check .exe signature;
https://imgur.com/7k8e09p
Nice. Can we see SRP in API login?Man in the middle attack is not possible, because
*) WinBox now uses ECSRP for key exchange and authentication (requires new winbox version),
both sides now verify that other side knows password (no man in the middle attack is possible anymore);
+1 for dark mode. Its very useful when you are on site and laptop batery is <50%Add dark mode please
Sent from my C6833 using Tapatalk
+1Nice. Can we see SRP in API login?Man in the middle attack is not possible, because
*) WinBox now uses ECSRP for key exchange and authentication (requires new winbox version),
both sides now verify that other side knows password (no man in the middle attack is possible anymore);
I used a regular non-EV certificate to sign the example, those are easy to get and easy to buy on dark web too. A lot of malware abuses code signing certificates these days.Yes, but to be honest, I can't imagine which other legitimate organisation would go to the trouble of using their Extended Validation certificate to sign Winbox It's not like it is simple to obtain.It checks that the .exe has authenticode signature (certificate based), but doesn't care who the signer is. It should verify that the Mikrotik public key is used.Is that really certificate based ? Or simply some MD5 hash ? In the later case this should not be called signature as this has nothing to do with a secure feature.I just tested this.. it checks for a signature, but not Mikrotik's signature! I sign it myself and winbox blindly runs it*) make winbox self upgrade check .exe signature;
https://imgur.com/7k8e09p
Same problem was also with previous version 3.13.I winbox to RB751U-2HnD and RB751G-2HnD via rb751gr2(romon), there is no wireless menu.
What problem do you mean? Tell me the version of OS you have used, and how the issue manifests itself.Normis - could You tell me when will be solved problem witl Log display at WinBox and high resolution screens (with WinBox Windows scaling)?
For example, MacOS, 120 dpi instead of 96: The same is in WindowsWhat problem do you mean? Tell me the version of OS you have used, and how the issue manifests itself.
We have many many retina MacOS devices here, also Linux.For example, MacOS, 120 dpi instead of 96:What problem do you mean? Tell me the version of OS you have used, and how the issue manifests itself.
Screen Shot 2018-05-30 at 11.16.18.png
The same is in Windows
How about checking actual HiDP Displays, not trying to simulate something that isn't taking place ?I just went to winecfg, Graphics, and increased Screen Resolution
Has nothing to do with DPI, the log column sizing is a different question.
Does this let us get Radius with pap work later on for winbox login (I am using OTP-Tokens there simply is nothing to do chap on so now it's impossible to login to winbox in my more secure way) Question about to be able to have setting for pap/chap in Ros has been sent to Support since a long time back. This notice makes me think there could be an openings for this later on in development cycles.What's new in v3.14:
*) added support for new style authentication and encryption for connections to RouterOS v6.43;
Windows removed display options from control panel, leaving only scaling in new settings. There are no problems with increased scaling:
works fine here with winbox 3.14 to RB962 running ROS 6.42.3the wireless menu not show and not work with this winbox
RoMON? Known and will be fixedthe wireless menu not show and not work with this winbox
ERROR: could not fetch index
Winbox 3.14, but also all older versions:
How to edit such dialog window, when screen is so small? Scroll does not work.
Why aren't interfaces sorted by name?
People have long asked to increase the size of the fields in the log by only a few pixels....Windows removed display options from control panel, leaving only scaling in new settings. There are no problems with increased scaling:
winbox-dpi.png
Like shown in the examples, there is no problem with any monitor settings. If you have a problem, maybe it is caused by something else in your PC.People have long asked to increase the size of the fields in the log by only a few pixels....Windows removed display options from control panel, leaving only scaling in new settings. There are no problems with increased scaling:
winbox-dpi.png
You offer them to change the usual settings of their monitors.
It's not logical to change what you're used to.
..Normis
Winbox uses IP as unique ID and just replace logins and notes in saved sessions. Can you just make a checkbox in winbox settings like "use Note column as primary key" or something simular? It can be disabled by default.
I have no problem changing the settings.Like shown in the examples, there is no problem with any monitor settings. If you have a problem, maybe it is caused by something else in your PC.People have long asked to increase the size of the fields in the log by only a few pixels....Windows removed display options from control panel, leaving only scaling in new settings. There are no problems with increased scaling:
winbox-dpi.png
You offer them to change the usual settings of their monitors.
It's not logical to change what you're used to.
Like shown in the my examples, the problem exists.Like shown in the examples, there is no problem with any monitor settings. If you have a problem, maybe it is caused by something else in your PC.
"application" disables all Windows scaling settings and only use the app developer's setting (winbox will appear in its original size) or ones with altered DPIs by other means (which of course will give weird appearance).Like shown in the my examples, the problem exists.Like shown in the examples, there is no problem with any monitor settings. If you have a problem, maybe it is caused by something else in your PC.
Yes. "System (Enhanced)" is better than "System". But "application" is better than "System (Enhanced)". In "application" font is more delicate, clear, pleasant and standard for Windows than the font in "System (Enhanced)".Choose the right settings. "System (Enhanced)" and in system->display->advanced scaling settings "Let windows try to fix apps so they're not blurry"
If you remember the first beta 3.x you made it possible to change the size of the fields in the log.You will not get the same look because of image scaling and post processing.
Not happened to me with version 3.13Same problem was also with previous version 3.13.I winbox to RB751U-2HnD and RB751G-2HnD via rb751gr2(romon), there is no wireless menu.
Regards,
I have seen the same issueI have problem with "Reconnect" button after the connection was lost: after clicking it, the Winbox window disappear. According to log, login to router was successful, but automatically disconnected after 30 seconds. (never happened in 3.13)
Check that hotspot package is installed and enabled in System -> Packages.hello, help me find the hotspot on the gui? if i login with romon i can't find the /ip hotspot on the gui.
What's new in v3.13:
*) abandoned support for connecting to older RouterOS versions (older than v6), no DLLs will ever be downloaded;
*) make all connections in secure mode (all data is encrypted with AES128-CBC-SHA);This version 3.14 works very slowly before connecting to the router. In version 3.13 or 3.12 is connect very fast to riuter
This also means you should rotate your passwords if you haven't been using secure mode, anyone on the network could have intercepted them.*) make all connections in secure mode (all data is encrypted with AES128-CBC-SHA);This version 3.14 works very slowly before connecting to the router. In version 3.13 or 3.12 is connect very fast to riuter
so it requires more CPU processing power from both sides and more information exchange.
+1 - this is very annoying, please help.whoever has a vertical screen resolution of 768 and below is faced with the No scroll issue. CLI is a work around, but it is still an issue in winbox