Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Stop Being a Victim
Tim Mullen, 2004-04-27

An influential newspaper columnist blames "contemptuous techies" for allowing users to fall prey to viruses and spyware. But don't some users deserve a little contempt?

Comments Mode:
Stop Being a Victim 2004-04-28
Clownface (2 replies)
Stop Being a Victim 2004-04-28
Matthew Murphy
Stop Being a Victim 2004-04-28
Curt (1 replies)
Stop Being a Victim 2004-04-30
Anonymous (3 replies)
Stop Being a Victim 2004-05-02
Eu (1 replies)
Stop Being a Victim 2004-05-07
Anonymous
Stop Being a Victim 2004-05-03
Anonymous
Stop Being a Victim 2004-05-06
zaster (1 replies)
Re: Stop Being a Victim 2005-07-10
Harold
Stop Being a Victim 2004-04-28
Anonymous (1 replies)
Cost to be a victim 2004-04-29
Ed (1 replies)
Re: Cost to be a victim 2005-07-10
Harold
Stop Being a Victim 2004-04-28
Ivan
Stop Being a Victim 2004-04-28
Anonymous
Un-tech-friendly people 2004-04-28
iago (1 replies)
Un-tech-friendly people 2004-04-29
AnonYmousE
Stop Being a Victim 2004-04-28
Paul (2 replies)
Stop Being a Victim 2004-05-01
Anonymous
Stop Being a Victim 2004-05-07
Anonymous
Stop Being a Victim 2004-04-28
Bob Beck
Stop Being a Victim 2004-04-28
It's not MY Fault
Another d00zie from Mellon... 2004-04-28
Linux Sux (1 replies)
Another d00zie from Mellon... 2004-04-28
iago (2 replies)
Another d00zie from Mellon... 2004-04-29
Anonymous
Another d00zie from Mellon... 2004-05-01
Anonymous
Stop Being a Victim 2004-04-28
Anonymous (2 replies)
Stop Being a Victim 2004-04-28
Anonymous
Stop Being a Victim 2004-04-28
Micheal
Stop Being a Victim 2004-04-28
Anonymous (1 replies)
Stop Being a Victim 2004-04-29
Anonymous
Stop Being a Victim 2004-04-28
Anonymous (4 replies)
Stop Being a Victim 2004-04-28
contemptuoustechie
Stop Being a Victim 2004-04-28
Anonymous
Stop Being a Victim 2004-04-28
Anonymous
Stop Being a Victim 2004-04-28
Anonymous (1 replies)
Stop Being a Victim 2004-05-08
Anonymous
The truth lies somewhere in between 2004-04-28
incongruity
Stop Being a Victim 2004-04-28
A non-ymoose
Stop Being a Victim 2004-04-29
DocB
Failure of the application to provide a safe environment 2004-04-29
David Mohring (1 replies)
http://www.google.com/groups?threadm=slrn8j2cen.pns.heretic@
localhost.localdomain
QUOTE
Human nature being as it is, relying on users to follow a strict protocol when dealing with incoming email[, web pages] or other Office documents via the internetis doomed to failure. Love letter from whom? The temptation to open the attachments is too great even for the most security conscious person. To quote Mark Twain "You can fool some of the people all of the time, and all of the people some of the time ...". When presented with a dialog window with Yes/No buttons, a LOT of users click yes without even reading the dialog.
UNQUOTE

Any application used for viewing Email, web pages and documents that can invoke embedded or linked scripted code and executable code must have an obligation to safely view the content without it putting the system and user at risk from hostile code.

People in business tend to send each other email's, links to wepgages and attached Microsoft Office documents all the time. It's often part of their every day business. Sending native executables back and forth is not. Why should any such email,browser or other client viewers run an untrusted unrestricted executable?

Downloading and/or extracting and installing executables on the local system should be performed by a dedicated client. This can insure that all the executable are pre-scanned before use and that the origin of the file is not on a hostile blacklist.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/236/26000#26000
Victim !!? 2004-04-29
Mandar
Stop Being a Victim 2004-04-29
HiVeloCT
I don't think people get it ... 2004-04-30
Robert Escue
Be careful what you wish for... 2004-04-30
Anonymous
COMPLETE NONSENSE 2004-04-30
I Have Google Shares (2 replies)
COMPLETE NONSENSE 2004-05-04
Anonymous
COMPLETE NONSENSE 2004-05-04
Anonymous
Stop Being a Victim 2004-05-03
Anonymous
Getting End-Users to Wake Up 2004-05-03
I'mNotThatSmart
Little Gain in Finger Pointing 2004-05-03
Anonymous (1 replies)
Little Gain in Finger Pointing 2004-05-04
Anonymous (1 replies)
Little Gain in Finger Pointing 2004-05-05
Anonymous
User Certification 2004-05-04
gnot a gnome
Stop Being a Victim 2004-05-04
Anonymous
Stop Being a Victim 2004-05-04
Anonymous
Stop Being a Victim 2004-05-05
Anonymous
Stop Being a Victim 2004-05-05
BrinH
What next? 2004-05-06
Anonymous
Stop Being a Victim 2004-05-07
Jeroen
Stop Being a Victim 2004-05-08
blacklight
Half working 'solutions' 2004-05-10
Anonymous
Fantastic 2004-05-10
mind-ops.com (James Carter)
Stop Being a Victim 2007-08-08
Afterfreeze







 

Privacy Statement
Copyright 2008, SecurityFocus