Don’t be so pushy! When there is a new version, there will be a new topic on the forum.
As long as there is no new version, there will be no announcement.
That is how it is with MikroTik.
(also, with MikroTik it is common that new versions are posted late on friday afternoon their local time)
Problem that was also present in 3.22 with the display of the window when clicking on a certificate crl. The window is not resizable and exceed the size of the winbox window.
I keep resizing the windows in Winbox 3.23 64 on Windows 10 64. More than half of the time I am resizing windows to a smaller size instead of working in Winbox on the settings. It really a PITA this way.
Update: I was working on three routers using the same profile and I am now trying to have for each router a separate profile for Winbox.
It is only Thursday today, so we do not know yet.
On the other hand, MikroTik are closed tomorrow and monday so indeed likely no release tomorrow.
However, I can assure you that posting messages like that will do absolutely nothing to change it.
I recommend you to go back to a release that works OK. For me that is 3.21 but I do not use scaling at all.
Newer versions that tried to improve things for users that use scaling have introduced far worse problems.
I noticed files called viw???.tmp littering the folder that winbox.exe lives. These files has IP, username and passwords in them. Winbox does not clean up these files on exit. I have also noticed that it keeps the ip username and password of the first connection made. This happens even if save password is unchecked. Can we get a cleanup process that removes these?
Looks like Winbox needs an adequate beta test program. What it has now doesn’t even pretend to qualify. This sort of thing should have been nipped in the bud prior to release. Now we can’t get rid of it.
Hey guys - any chance of getting a checksum for the WinBox downloads too? Wary of downloading an EXE file without any confirmation it’s safe to work with. Thanks in advance.
Checksum is not an reliable way of validating file authenticity - i.e. if it was modified after publishing. If an attacker can tamper the executable, then he can almost always tamper the provided checksum. Checksums are good to validate file’s integrity - i.e. if the file wasn’t broken while downloading for example.
What you should look at is digital signature. This is the way of validating file’s both integrity and authenticity. Digital signature is finally provided to Winbox executables since version 3.13. You can validate it by going to file properties, then to the “Digital signatures” tab and double clicking the line with “Mikrotikls SHA256 ”. Then in the new window you will see if digital signature is OK or not.
Although the attached digital signature is a good way of validating file authenticity - it’s not perfect. There are many problems with PKI in general and that’s why MikroTik should definitely sign Winbox executable and RouterOS packages with own GPG signature. But keeping in mind that - sorry to say that - they don’t care about software security and quality as they should, so we probably won’t see it in a long time - if at all. Also keep in mind that Winbox digital signature came way to late. I was requesting it in year 2015 [1], 2016 [5], then it was requested in March of 2018 [2] and we’ve finally got it in April 2018 [3] - most probably because of the emerge of Slingshot APT (malware) [4], which could impact company’s image. Keep in mind, that such security measure should be present since the beginning of Winbox.
The lack of dedicated software quality engineers and software security professionals is one of the things that prevents MikroTik hardware from being installed in sensitive installations. As they were serving mainly WISP in the beginning, then it was not noticed (from my experience, the ISP operators - generally speaking - don’t know what they are doing, but everything is fine as long as money comes up). But now they are aspiring to be in the range of Enterprise hardware/software vendors, so such topics must receive top priority. But it requires the fundamental change in mindset, hiring more people and paying for work which doesn’t directly translates to profits in a visible way. This is one of the things that makes difference between amateurs, money-hungry managers and real professionals. And I guess this is true all around the world.
You are right in what you’re saying and you can be sure, that MikroTik’s software has a lot more basic security problems which are there. But when you tell them about it, then you are treated like a kid who found a misspelling in the “About” window of the program. I have been treated personally like that many times, but this is not the way you treat security people.
Unfortunately they are just aspiring to get into the enterprise sector. They don’t actually try to.
I can’t imagine any big enterprise that can wait for over 6 years for fixes/optimizations in BGP, or newer kernel.
Even WISPs that made MikroTik who they are, are switching to other vendors because of terrible wireless support, even since 802.11n.
Nstreme is dead. NV2 is terrible compared to pretty much every other TDMA implementation out there. 802.11ac wave 2? What is that? MikroTik still lives in pre-2016 era
In the meantime MikroTik has dedicated tons of resources to useless features in a futile attempt to appeal to the SOHO market, such as internet detect, kids control, quickstart, smartphone apps etc.
Even MikroTik doesn’t appear to know which is their target group anymore…
WISPs cannot get the best out of their available frequencies when using MikroTik.
Enterprises cannot rely on “beta” software and tons of unfullfilled promises of eveyrhing will be fixed in v7 (which got released without a routing package - A Router OS without routing. It’s like taking the latest car model, for a test drive that doesn’t have an engine released yet - need I say more?)
Home users simply don’t understand networking - MikroTik has no business in homes with their current OS - unless they design something akin to TP-Link or Netgear so non-technical people can use. Hell, even cisco guys many times cannot use ROS, and they are supposed to understand networking.
Not to mention customer support. Imagine a big ISP having Cisco gear, but no support from Cisco.
That’s MikroTik in the Datacenter/Enterprise.
So considering all that, digital signatures and other security features apparently are fine print…
Enterprises cannot rely on “beta” software and tons of unfullfilled promises of eveyrhing will be fixed in v7 (which got released without a routing package