Feast of Egos
Tim Mullen, 2004-09-07

Eager to tarnish Microsoft's shiny new Service Pack 2, the security press managed to spin the most thin and marginal issues into "gaping holes" and "security craters."

Comments Mode:
Feast of Egos 2004-09-07
Beryllium Sphere LLC (1 replies)
Feast of Egos 2004-09-13
Anonymous
Feast of Egos 2004-09-08
Todd Knarr (2 replies)
Feast of Egos 2004-09-09
Troll (2 replies)
Feast of Egos 2004-09-10
Todd Knarr (2 replies)
Running a program via the command prompt is trivial: drag the program on top of the command-prompt icon and drop it. As I said, users are already known to be willing and able to jump through more hoops than that to run malware. If you want to protect users you need to be at least current with the curve, not a year or more behind it.

As for the security center, yes code would have to have run. You only get to use that excuse if you haven't left holes through which code can be run, though. And if that code which you've left holes for can diddle the security-center settings, all the malware needs to do is convince the user that this one little alert that won't happen again is something they should just ignore. Easy enough to do when users have become accustomed to such ignorable alerts over the years (eg. the ubiquitous "unsigned driver" alert).

Bottom line: SP2 does a lot of technical things right, but it misses aspects of user behavior and fundamental system design that are at the roots of the malware problem on Windows.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/265/28400#28400
Feast of Egos 2004-09-13
Anonymous
Feast of Egos 2004-09-14
Angus (1 replies)
Feast of Egos 2004-09-16
Anonymous
Feast of Egos 2004-09-13
Ed
Feast of Egos 2004-09-14
Anonymous
Feast of Egos 2004-09-08
Anonymous
Feast of Egos 2004-09-08
Mat, CISSP
Feast of Egos 2004-09-08
Anonymous (1 replies)
Feast of Egos 2004-09-08
Anonymous
Feast of Egos 2004-09-08
Problem Updates (1 replies)
Feast of Egos 2004-09-14
Anonymous
I Agree 2004-09-08
Lucas
Feast of Egos 2004-09-09
Some Hacker (3 replies)
Feast of Egos 2004-09-14
Anonymous (1 replies)
Feast of Egos 2004-09-19
Anonymous
Feast of Egos 2004-09-14
Brutal Dictator
Feast of Egos 2004-09-14
Angus (1 replies)
Feast of Egos 2004-09-19
AWKz
SP2 = MS-hyped Snake Oil 2004-09-14
Matthew Murphy
Feast of Egos 2004-09-14
Anonymous
Feast of Egos 2004-09-17
Anonymous


 

Privacy Statement
Copyright 2010, SecurityFocus