Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Faith No More
Tim Mullen, 2004-02-02

Microsoft can end the scourge of e-mail viruses by ending its support for old software, and the clueless users who refuse to upgrade.

Comments Mode:
Faith No More 2004-02-02
Kudos (2 replies)
Faith No More 2004-02-05
Anonymous (1 replies)
It's about time... 2004-02-05
Matthew Murphy (1 replies)
It's about time... 2004-02-08
Anonymous
Off The Mark... 2004-02-02
Anonymous (4 replies)
Off The Mark... 2004-02-02
Anonymous
Off The Mark... 2004-02-02
Jim (hi tim!)
Off The Mark... 2004-02-04
Greg
Off The Mark... 2004-02-09
Anonymous
Faith No More 2004-02-02
Anonymous CISSP
Faith No More 2004-02-02
Anonymous (1 replies)
Faith No More 2004-02-03
rolaids0 (1 replies)
Faith No More 2004-02-03
Anonymous (1 replies)
Faith No More 2004-02-07
Anonymous
Faith No More 2004-02-02
Anonymous
Faith No More 2004-02-02
Anonymous
Faith No More 2004-02-02
Anonymous
Faith No More 2004-02-02
Chris Caydes (1 replies)
Faith No More 2004-02-02
Anonymous
Nice article but... 2004-02-02
Anonymous (1 replies)
Nice article but... 2004-02-03
Anonymous
Build a better OS, and I will buy it... 2004-02-02
Unca Xitron (5 replies)
Be a better sysadmin and you would... 2004-02-03
Anonymous (1 replies)
Interesting, vitriolic response... 2004-02-05
Unca Xitron
Great article 2004-02-03
Anonymous
Build a better OS, and I will buy it... 2004-02-03
Anonymous (1 replies)
Education is the key 2004-02-05
Dan (1 replies)
Education is NOT the key 2004-02-13
Anonymous
Faith No More 2004-02-02
Anonymous (1 replies)
Faith No More 2004-02-03
Andres Alla
Faith No More 2004-02-02
Anonymous (3 replies)
Faith No More 2004-02-03
Anonymous
Faith No More 2004-02-03
Anonymous (1 replies)
try again 2004-02-03
OOOoook
PEBKAS 2004-02-03
Anonymous
Faith No More 2004-02-03
Who is clueless?!? (1 replies)
Faith No More 2004-02-03
Jeff
Faith No More 2004-02-03
Paul
Faith No More 2004-02-03
Ant
Faith No More 2004-02-03
Kevin
Faith No More 2004-02-03
Anonymous
Tim's whole argument for getting people to shell out "time and money" (his own words) to upgrade both their hardware and their software is so they get the Outlook feature which prevents them from executing attachments (as another reader has pointed out, the Novarg virus circumvented this very feature by sending itself as a ZIPfile).

But this is missing the point, and thereby, failing to address the underlying issues.

The problem is the "security context" in which Microsoft Windows executes attachments. Simply put, the attachments are executed in the context of the user, and thus have all the rights and access of the user (eg. ability to write to drive C:, ability to use internet). Alternative operating systems can execute code in a restricted "sandbox" which is completely insulated from the rest of the machine. Even if a virus executes in the sandbox, it does not infect the entire machine - the sandbox simply does not have the access.

So until Microsoft Windows actually has this built-in support for isolating potentially hostile code, there's no reason to upgrade. It's no more secure than Windows 3.1!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/217/24750#24750
Hell yeah!!! 2004-02-03
Anonymous
Faith No More 2004-02-03
Peter (1 replies)
Faith No More 2004-02-04
Anonymous
hilarious 2004-02-03
Anonymous
Faith No More 2004-02-03
Anonymous
Imagination 2004-02-03
Anonymous
Good enough? 2004-02-03
Anonymous
Faith No More - Common Sense Isn't Common 2004-02-03
Anonymous (1 replies)
Faith No More 2004-02-03
Anonymous
Faith No More 2004-02-03
Anonymous
Faith? Blind anyhow 2004-02-03
Techie
Clueless Commentator 2004-02-03
Anonymous
Faith No More 2004-02-03
Anonymous
Hilarious ! 2004-02-03
Jake
Faith No More 2004-02-03
Anonymous
Nothing but Microsoft FUD here... Move along 2004-02-03
John the Kiwi (3 replies)
Can't agree more... 2004-02-04
Anonymous
Why was mydoom so sucsessful? 2004-02-03
Anonymous (4 replies)
Why was mydoom so sucsessful? 2004-02-04
Anonymous
Why was mydoom so sucsessful? 2004-02-04
Anonymous (3 replies)
Why was mydoom so sucsessful? 2004-02-04
John the Kiwi
Why was mydoom so sucsessful? 2004-02-05
Anonymous
Why was mydoom so sucsessful? 2004-02-05
Anonymous (1 replies)
Multi Layers is the Key 2004-02-06
Mato Lek
Why was mydoom so sucsessful? 2004-02-05
Frank B.
SPAM, that's why 2004-02-05
Anonymous
Old OS's/software stink, but... 2004-02-04
Anonymous
Faith No More 2004-02-04
User point of view (?)
Faith No More 2004-02-04
Smiorgan
When did MS start paying you?? 2004-02-04
Anonymous
Forced Patches 2004-02-04
Anonymous
Crappy Code 2004-02-04
Anonymous
Who's responsibility is security? 2004-02-04
Answer Within...
Faith No More 2004-02-04
<mtrahara@rcn.com>
Faith No More 2004-02-05
Anonymous
Faith No More 2004-02-05
Anonymous
Faith No More 2004-02-05
Anonymous
Spelling Error! 2004-02-05
Robert
Faith No More 2004-02-05
Anonymous
Faith No More 2004-02-05
Thilo
Faith No More 2004-02-05
AICS
Faith No More 2004-02-05
Mark Brabson
What 's you're problem!? 2004-02-05
Anonymous
Faith No More 2004-02-05
blacklight (1 replies)
Faith No More 2004-02-06
`
Faith No More 2004-02-07
Anonymous
I still use windows 98... 2004-02-08
Anonymous
Hardware requirements 2004-02-09
Anonymous
Remarkable 2004-02-09
Jeff H (a different one from the previous Jeff)
YEAH UP GRADE YOU CHEAP BASTARDS 2004-02-11
Anonymous
Once bitten, twice sny 2004-02-13
Art Marriott







 

Privacy Statement
Copyright 2009, SecurityFocus