Secure Coding mailing list archives
RE: Hypothetical design question
From: "Michael S Hines" <mshines () purdue edu>
Date: Wed, 28 Jan 2004 19:07:00 +0000
An interesting dialog appeared on the PLUG* mailing list this morning. A FreeBSD user was trying to execute the new macro virus circulating (MyDOOM) and couldn't seem to replicate the problem the Windows users were seeing. Another AlphaVMS user was having the same problem. Which is to say - it does seem to be an Operating System design flaw, to me - not necessarily a mail client issue. Consider - why do we have a Java Sandbox, and allow other executable files to run 'in the wild' (without contraints for authorizaion or authentication). Click and run is the mistake... I think. Why would a user be allowed to execute a program they wouldn't be allowed to install on their machine, otherwise (if proper controls are in place)? This is a flaw in the security mechanism of the OS. Mike Hines *PLUG = Purdue Linux Users Group ----------------------------------- Michael S Hines [EMAIL PROTECTED]
Current thread:
- Hypothetical design question Kenneth R. van Wyk (Jan 27)
- Re: Hypothetical design question Paco Hope (Jan 27)
- Re: Hypothetical design question Andreas Saurwein (Jan 28)
- RE: Hypothetical design question Dave Paris (Jan 28)
- RE: Hypothetical design question Andreas Saurwein (Jan 28)
- RE: Hypothetical design question Dave Paris (Jan 28)
- RE: Hypothetical design question Michael S Hines (Jan 28)
- Re: Hypothetical design question Kenneth R. van Wyk (Jan 29)
- Re: Hypothetical design question Andreas Saurwein (Jan 28)
- Re: Hypothetical design question Paco Hope (Jan 27)
- Re: Hypothetical design question Paco Hope (Jan 28)
- Re: Hypothetical design question Dave Aronson (Jan 28)
- Re: Hypothetical design question Andreas Saurwein (Jan 28)
- RE: Hypothetical design question Michael S Hines (Feb 02)
- Re: Hypothetical design question Louis Solomon [SteelBytes] (Feb 03)
- RE: Hypothetical design question Jason Wilcox (Feb 03)
- <Possible follow-ups>
- RE: Hypothetical design question Robert Shields (Jan 28)