home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.amiga.programmer,comp.sys.amiga.networking
- Path: mozart.unx.sas.com!jamie
- From: jamie@cdevil.unx.sas.com (James Cooper)
- Subject: Re: Best Mail Program for use with SLIP, SMTP, POP, AmiTCP?
- Originator: jamie@cdevil.unx.sas.com
- Sender: news@unx.sas.com (Noter of Newsworthy Events)
- Message-ID: <DLLJzr.Kp7@unx.sas.com>
- Date: Mon, 22 Jan 1996 19:11:51 GMT
- Distribution: inet
- X-Nntp-Posting-Host: cdevil.unx.sas.com
- References: <jdjiviqtgtf.fsf@neppari.cs.hut.fi> <1264.6579T945T2649@ipacific.net.au> <4crjnb$gr8@redstone.interpath.net> <54422@babylon.pfm-mainz.de> <4d8toc$nta@redstone.interpath.net> <jdjlon9z1m1.fsf@hyppynaru.cs.hut.fi>
- Organization: SAS Institute Inc.
-
-
- In article <jdjlon9z1m1.fsf@hyppynaru.cs.hut.fi>, Osma.Ahvenlampi@hut.fi (Osma Ahvenlampi) writes:
- >In article <4d8toc$nta@redstone.interpath.net> jamie@jamie.interpath.net (Jim Cooper) writes:
- >>In article <54422@babylon.pfm-mainz.de> rbabel@babylon.pfm-mainz.de (Ralph Babel) writes:
- >>> .... will disable onopen, onclose, rx, rxs, and system.
- >>
- >>Yep, and make AmigaGuide a lot less useful.
- >>
- >>I think I'll just go disable all the Open/Write entry points in my system,
- >>so nobody can possibly do anything bad to the data I have...
- >>
- >>There *is* such as thing as over-reacting, Ralph.
- >>
- >>It is possible to abuse anything, but if you hadn't posted just *how* to
- >>do that to the ENTIRE WORLD, it might have gone unnoticed - now its a lot
- >>*more* likely that this very thing will happen to someone. :-(
- >
- >I have to disagree. Executing commands from documents without
- >verifying them with the user first is a very serious security risk,
- >and must be addressed. Security through obscurity, ie. keeping quiet
- >about security holes, has never worked, and never will. It is better
- >that everyone learns about problems and ways to protect themselves
- >than that the holes are only known by a few people. The people who are
- >likely to exploit those holes will learn about them anyway, as is
- >obvious from the fact that (dangerous) viruses exist.
- >
- >The proper way to address this problem is to make command execution
- >optional by makeing AmigaGuide default to a no-execute mode. If the
- >user so wishes, (s)he can enable that mode on a per-application basis.
-
- How hard would it be to make it on a "per guide" basis? In other words,
- the feature is so neat, its a shame to lock it out when that isn't
- necessary. Instead, it could only do the lockout if one of the "unsafe"
- commands is used...
-
- --
- ---------------
- Jim Cooper
- (jamie@unx.sas.com) bix: jcooper
-
- Any opinions expressed herein are mine (Mine, all mine! Ha, ha, ha!),
- and not necessarily those of my employer.
-
- I'm NOT Politically Correct, but that's because I'm "Sensitivity Challenged."
-