Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Stop Being a Victim
Tim Mullen, 2004-04-27

An influential newspaper columnist blames "contemptuous techies" for allowing users to fall prey to viruses and spyware. But don't some users deserve a little contempt?

Comments Mode:
Stop Being a Victim 2004-04-28
Clownface (2 replies)
Stop Being a Victim 2004-04-28
Matthew Murphy
Stop Being a Victim 2004-04-28
Curt (1 replies)
Stop Being a Victim 2004-04-30
Anonymous (3 replies)
Stop Being a Victim 2004-05-02
Eu (1 replies)
Stop Being a Victim 2004-05-07
Anonymous
Stop Being a Victim 2004-05-03
Anonymous
Stop Being a Victim 2004-05-06
zaster (1 replies)
Re: Stop Being a Victim 2005-07-10
Harold
MS Windows has been brilliant for backward compatibility, but it's also one of its achilles heels, and it makes the OS quite baroque (and at times broke). We're talking third millenium technology built on top of 1990's built on top of 1980's built on top of 1970's tech. It's like a modern city built around cow paths.

Unix was built as a multi-process multi-user operating system with security from the beginning. The MacOS has not focussed as highly on backward compatibilty as it has advanced, which enabled it to migrate to a Unix kernel and thus inherited it's original design benefits around security issues.

It's not just sheer numbers that makes the Microsoft OS vulnerable, it's been endemic to the design.

Another problem that has made Windows vulnerable has been the attempt to enable all programs to do *everything*. For example, the ActiveX software was intended to be like Java, but it basically openned the door for Internet Explorer to do things like shut your computer down. I saw a demo in 1997 or 1998 where just by loading a URL, a hacker could get into the user's computer, make debits from his bank accounts, and shut down his computer. It was extremely dangerous, and thank goodness ActiveX downloads never caught on.

On the email side, MAPI and MS Outlook openned a back door to email automation that creates unexpected things from happening, like sending an email to all your addressbook when you open an email.

Such designs aren't very good software hygiene, or at least, it makes it hard to have good software hygiene. But on the other hand, Mr. Bill does seem to have a knack for moving his company and operating system around to cover the issues that weren't there in the design in the first place. So the world is safer now with Windows XP (though I do feel safer running Firefox as a browser than Internet Exploder on my Windows box). But the Mac/Open Source people aren't just envious of Microsoft's Imperial Domain over the PC OS Market.

Harold Shinsato

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/236/32144#32144
Stop Being a Victim 2004-04-28
Anonymous (1 replies)
Cost to be a victim 2004-04-29
Ed (1 replies)
Re: Cost to be a victim 2005-07-10
Harold
Stop Being a Victim 2004-04-28
Ivan
Stop Being a Victim 2004-04-28
Anonymous
Un-tech-friendly people 2004-04-28
iago (1 replies)
Un-tech-friendly people 2004-04-29
AnonYmousE
Stop Being a Victim 2004-04-28
Paul (2 replies)
Stop Being a Victim 2004-05-01
Anonymous
Stop Being a Victim 2004-05-07
Anonymous
Stop Being a Victim 2004-04-28
Bob Beck
Stop Being a Victim 2004-04-28
It's not MY Fault
Another d00zie from Mellon... 2004-04-28
Linux Sux (1 replies)
Another d00zie from Mellon... 2004-04-28
iago (2 replies)
Another d00zie from Mellon... 2004-04-29
Anonymous
Another d00zie from Mellon... 2004-05-01
Anonymous
Stop Being a Victim 2004-04-28
Anonymous (2 replies)
Stop Being a Victim 2004-04-28
Anonymous
Stop Being a Victim 2004-04-28
Micheal
Stop Being a Victim 2004-04-28
Anonymous (1 replies)
Stop Being a Victim 2004-04-29
Anonymous
Stop Being a Victim 2004-04-28
Anonymous (4 replies)
Stop Being a Victim 2004-04-28
contemptuoustechie
Stop Being a Victim 2004-04-28
Anonymous
Stop Being a Victim 2004-04-28
Anonymous
Stop Being a Victim 2004-04-28
Anonymous (1 replies)
Stop Being a Victim 2004-05-08
Anonymous
The truth lies somewhere in between 2004-04-28
incongruity
Stop Being a Victim 2004-04-28
A non-ymoose
Stop Being a Victim 2004-04-29
DocB
Victim !!? 2004-04-29
Mandar
Stop Being a Victim 2004-04-29
HiVeloCT
I don't think people get it ... 2004-04-30
Robert Escue
Be careful what you wish for... 2004-04-30
Anonymous
COMPLETE NONSENSE 2004-04-30
I Have Google Shares (2 replies)
COMPLETE NONSENSE 2004-05-04
Anonymous
COMPLETE NONSENSE 2004-05-04
Anonymous
Stop Being a Victim 2004-05-03
Anonymous
Getting End-Users to Wake Up 2004-05-03
I'mNotThatSmart
Little Gain in Finger Pointing 2004-05-03
Anonymous (1 replies)
Little Gain in Finger Pointing 2004-05-04
Anonymous (1 replies)
Little Gain in Finger Pointing 2004-05-05
Anonymous
User Certification 2004-05-04
gnot a gnome
Stop Being a Victim 2004-05-04
Anonymous
Stop Being a Victim 2004-05-04
Anonymous
Stop Being a Victim 2004-05-05
Anonymous
Stop Being a Victim 2004-05-05
BrinH
What next? 2004-05-06
Anonymous
Stop Being a Victim 2004-05-07
Jeroen
Stop Being a Victim 2004-05-08
blacklight
Half working 'solutions' 2004-05-10
Anonymous
Fantastic 2004-05-10
mind-ops.com (James Carter)
Stop Being a Victim 2007-08-08
Afterfreeze







 

Privacy Statement
Copyright 2009, SecurityFocus