View Single Post
  #12  
Old October 14th, 2003, 07:51 PM
Harlan Grove
external usenet poster
 
Posts: n/a
Default Message to MICROSOFT - URGENT

"Chrissy" wrote...
...
But nothing about MY almost TOTALLY MS system is vulnerable BECAUSE it
is MS. All it takes to protect one's self are a few basic rules which one
should follow regardless of OS used.


Such as knowing that *previewing* e-mail is unsafe if the e-mail previewer (such
as Outlook Express's) is capable of rendering HTML, which means it can run some
embedded scripts. Such as knowing that picture files don't have .SCR extensions
(but, PITA, they could have .MIM extensions - because Windows systems still use
filename extensions to determine file types, which itself is a nasty security
hole).

Sophisticated Windows users can safeguard their systems. Unsophisticated Windows
users usually don't because they haven't got a clue that's it's necessary to do
so much less how to do it. So, given this, is out-of-the-box functionality a
problem? Yes. Have most of the people who open e-mail attachments changed any of
their system settings? Very unlikely. So there's something about the system
default settings that most of these people are operating with that, er, don't
contribute to system security.

You mentioned novice users - no wonder we have a problem when we put a
powerful tool in the hands of someone who does not know how to use it.
In many countries it would be considered inappropriate (or even illegal) for a
company to give a powerful tool (which could cause millions of dollars
damage) to a totally untrained staff member but it is done all the time with
computers then we wonder why so much mayhem is caused.


There are legal remedies. Either sue the fools who open e-mail attachments
(that'd be politically popular!) or sue the companies most responsible for
providing the infrastructure that makes these viruses so easy to propagate.
Let's see if we can name one of the latter . . .

--
Never attach files.
Snip unnecessary quoted text.
Never multipost (though crossposting is usually OK).
Don't change subject lines because it corrupts Google newsgroup archives.