home *** CD-ROM | disk | FTP | other *** search
- Path: nntp.hut.fi!usenet
- From: Osma.Ahvenlampi@hut.fi (Osma Ahvenlampi)
- Newsgroups: comp.sys.amiga.programmer,comp.sys.amiga.networking
- Subject: Re: Best Mail Program for use with SLIP, SMTP, POP, AmiTCP?
- Date: 15 Jan 1996 21:42:14 +0200
- Organization: What, me, organised?
- Sender: oahvenla@hyppynaru.cs.hut.fi
- Distribution: inet
- Message-ID: <jdjlon9z1m1.fsf@hyppynaru.cs.hut.fi>
- References: <jdjiviqtgtf.fsf@neppari.cs.hut.fi>
- <1264.6579T945T2649@ipacific.net.au>
- <4crjnb$gr8@redstone.interpath.net> <54422@babylon.pfm-mainz.de>
- <4d8toc$nta@redstone.interpath.net>
- NNTP-Posting-Host: hyppynaru.cs.hut.fi
- Mime-Version: 1.0
- Content-Type: text/plain; charset=US-ASCII
- In-reply-to: jamie@jamie.interpath.net's message of 13 Jan 1996 18:30:36 GMT
- X-Newsreader: Gnus v5.1
-
- In article <4d8toc$nta@redstone.interpath.net> jamie@jamie.interpath.net (Jim Cooper) writes:
- >In article <54422@babylon.pfm-mainz.de> rbabel@babylon.pfm-mainz.de (Ralph Babel) writes:
- >> .... will disable onopen, onclose, rx, rxs, and system.
- >
- >Yep, and make AmigaGuide a lot less useful.
- >
- >I think I'll just go disable all the Open/Write entry points in my system,
- >so nobody can possibly do anything bad to the data I have...
- >
- >There *is* such as thing as over-reacting, Ralph.
- >
- >It is possible to abuse anything, but if you hadn't posted just *how* to
- >do that to the ENTIRE WORLD, it might have gone unnoticed - now its a lot
- >*more* likely that this very thing will happen to someone. :-(
-
- I have to disagree. Executing commands from documents without
- verifying them with the user first is a very serious security risk,
- and must be addressed. Security through obscurity, ie. keeping quiet
- about security holes, has never worked, and never will. It is better
- that everyone learns about problems and ways to protect themselves
- than that the holes are only known by a few people. The people who are
- likely to exploit those holes will learn about them anyway, as is
- obvious from the fact that (dangerous) viruses exist.
-
- The proper way to address this problem is to make command execution
- optional by makeing AmigaGuide default to a no-execute mode. If the
- user so wishes, (s)he can enable that mode on a per-application basis.
- --
- foo
-