Secure Coding mailing list archives
Re: Opinion re an interesting article on Linux security in Linux Journal
From: Richard Moore <rich () westpoint ltd uk>
Date: Wed, 10 Mar 2004 16:06:48 +0000
Michal Zalewski wrote: Uhh, with some new worms, you not only can't execute the rogue directly by just clicking on an attachment, but you need to enter a password to get access to it... you just need a userbase clueless enough to carry out even a fairly complicated action out of curiosity, and some social engineering. That's certainly true, though you can minimise such issues in KDE by using Kiosk mode to reduce the functionality available to users. I was responding however to Kenneth's point about how easy it was to open an attachment in it's respective app. I don't minimise the dangers - they are real, but I do think we're in a better poisiton in the unix desktop world than the current state of the windows desktop. Cheers Rich.
Current thread:
- Opinion re an interesting article on Linux security in Linux Journal Kenneth R. van Wyk (Mar 09)
- Re: Opinion re an interesting article on Linux security in Linux Journal Richard Moore (Mar 09)
- Re: Opinion re an interesting article on Linux security in Linux Journal Michal Zalewski (Mar 09)
- RE: Opinion re an interesting article on Linux security in Linux Journal Alun Jones (Mar 10)
- Re: Opinion re an interesting article on Linux security in Linux Journal Richard Moore (Mar 10)
- Re: Opinion re an interesting article on Linux security in Linux Journal Michal Zalewski (Mar 09)
- RE: Opinion re an interesting article on Linux security in Linux Journal Michael S Hines (Mar 09)
- Re: Opinion re an interesting article on Linux security in Linux Journal Ryan Russell (Mar 10)
- Re: Opinion re an interesting article on Linux security in Linux Journal ljknews (Mar 10)
- Re: Opinion re an interesting article on Linux security in Linux Journal der Mouse (Mar 10)
- <Possible follow-ups>
- Re: Opinion re an interesting article on Linux security in Linux Journal Bill Cheswick (Mar 10)
- Re: Application Sandboxing, communication limiting, etc. Jared W. Robinson (Mar 10)
- Re: Application Sandboxing, communication limiting, etc. ljknews (Mar 10)
- Re: Re: Application Sandboxing, communication limiting, etc. Jose Nazario (Mar 10)
- Re: Re: Application Sandboxing, communication limiting, etc. Crispin Cowan (Mar 13)
- Re: Re: Application Sandboxing, communication limiting, etc. Jared W. Robinson (Mar 16)
- Re: Application Sandboxing, communication limiting, etc. Jared W. Robinson (Mar 10)
- Re: Opinion re an interesting article on Linux security in Linux Journal Richard Moore (Mar 09)