Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
CCIA Report is Bad Medicine
Tim Mullen, 2003-10-13

The proposed cure for the Internet's security woes might help Microsoft competitors, but it would only make our security problems worse.

Comments Mode:
Maybe it's intended as a threat? 2003-10-13
Anonymous
One part spot on, ocmplexity... 2003-10-13
Nicholas Weaver
Yet another bad article from our resident MS apologist 2003-10-13
Hay guys I'm lolling on THE INTERNET! (6 replies)
Yet another bad article from our resident MS apologist 2003-10-14
Anonymous (1 replies)
Yet another bad article from our resident MS apologist 2003-10-15
Anonymous (4 replies)
Yet another bad article from our resident MS apologist 2003-10-16
Anonymous (1 replies)
"If you compromise a process on windows, you've rooted the box"

Huh? NT, 2K, XP has a unix-alike model: you get the permissions it was running as, same as on unix.

"True, launching executable attachments in windows isn't a fault per-se of windows, but opening an e-mail message, or visiting a web site and having things done without user intervention is *their fault*."

Yeah, but that's the point of the article - this will likely happen on unix too. If you force people to write and deploy new software for linux desktops, they'll have the same incidences of exploitable bug - you're not gaining anything by moving them off Windows.

"The last time I checked, running an executable on unix from an attachment wasn't something that just happens. You have to save the file and then give it execute permission."

And for a few years Outlook has made you save files before you can run them, with big warnings too.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/190/23174#23174
Truly, you can't be serious.... 2003-10-16
Axe-2-Grind
CCIA Report is Bad Medicine 2003-10-13
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous
What free market? 2003-10-14
Anonymous (1 replies)
What free market? 2003-10-15
Anonymous
THANK YOU 2003-10-13
KGW (2 replies)
THANK YOU 2003-10-15
Ben
THANK YOU 2003-10-16
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-21
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-16
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-16
Anonymous
CCIA Report is Bad Medicine 2003-10-15
Anonymous
What is author's suggestion? 2003-10-14
Anonymous (1 replies)
What is author's suggestion? 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous (1 replies)
IPSec != Firewall 2003-10-14
Anonymous (3 replies)
IPSec != Firewall 2003-10-15
Anonymous
IPSec != Firewall 2003-10-15
Anonymous
IPSec ~= Firewall 2003-10-15
Did my research (2 replies)
IPSec ~= Firewall 2003-10-20
Anonymous
IPSec vs. IPChains 2003-10-14
Anonymous (2 replies)
IPSec vs. IPChains 2003-10-15
Anonymous
IPSec vs. IPChains 2003-10-15
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Chris Caydes (1 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Matthew Murphy (1 replies)
CCIA Report is Bad Medicine 2003-10-15
Anonymous
CCIA Report is Bad Medicine 2003-10-15
blacklight
CCIA Report is Bad Medicine 2003-10-15
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-15
Anonymous
Mellen doesn't get it 2003-10-15
Anonymous (1 replies)
Mellen doesn't get it 2003-10-15
Anonymous (1 replies)
Mellen doesn't get it 2003-10-17
Anonymous
CCIA Report is Bad Medicine 2003-10-15
DBrown
Actually, Tim... 2003-10-15
Penguinisto (1 replies)
Actually, Tim... 2003-10-16
blacklight
Attachments? 2003-10-15
Anonymous
Conveniently glossed right over the whole point 2003-10-15
A no no miss (2 replies)
Conveniently glossed right over the whole point 2003-10-15
Anonymous (1 replies)
That's all well and good 2003-10-17
Anonymous (1 replies)
That's all well and good 2003-10-20
Anonymous
CCIA Report is Bad Medicine 2003-10-15
Richard Rager
Not about economics 2003-10-15
Anonymous (1 replies)
Not about economics 2003-10-15
Anonymous
CCIA Report is Bad Medicine 2003-10-15
Anonymous
Not bad medicine, just bad.... 2003-10-16
Anonymous
CCIA Report is Bad Medicine 2003-10-17
Outraged
CCIA Report is Bad Medicine 2003-10-17
Anonymous
CCIA Report is Bad Medicine 2003-10-17
Paul Kosinski (1 replies)
CCIA Report is Bad Medicine 2003-10-21
Anonymous
Tim Mullin is Bad Journalism 2003-10-18
SNMPGuru (1 replies)
Tim Mullin is Bad Journalism-Why? 2003-10-21
Anonymous
Attacks: 2003-10-22
Anonymous
CCIA Report is Bad Medicine 2003-10-23
Anonymous
Reader Comments 2003-10-23
R. Lambert
CCIA Report is Bad Medicine 2003-10-24
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus