Secure Coding mailing list archives

Re: Hypothetical design question


From: Ken Goldman <kgold () watson ibm com>
Date: Thu, 29 Jan 2004 22:52:24 +0000

the user community has grown very fond of some of the very
features that viruses and worms thrive on (e.g., file attachments
that can be executed with a single/double click of a mouse)

I don't think this is quite true.  I think most users want to __view__
attachments, either pictures or text.  They expect the viewer to be
Word, Powerpoint Paint, etc.  They don't expect, when they click on an
attachment, to __execute__ it.

Most virus attachments disguise themselves as text or pictures.  The
accompanying teaser text says "look at this cool picture" or "here's
the document you asked for".  The teaser text never says "here's the
program I want you to execute."

So my improved email client would say, "clicking an attachment can
pass it's contents to this approved list of viewers, but it will never
just execute the attachment."

-- 
Ken Goldman   [EMAIL PROTECTED]   914-784-7646








Current thread: