Secure Coding mailing list archives

Re: Opinion re an interesting article on Linux security in Linux Journal


From: Richard Moore <rich () westpoint ltd uk>
Date: Wed, 10 Mar 2004 16:06:48 +0000


Michal Zalewski wrote:


Uhh, with some new worms, you not only can't execute the rogue directly by
just clicking on an attachment, but you need to enter a password to get
access to it... you just need a userbase clueless enough to carry out even
a fairly complicated action out of curiosity, and some social engineering.


That's certainly true, though you can minimise such issues in KDE by 
using Kiosk mode to reduce the functionality available to users. I was 
responding however to Kenneth's point about how easy it was to open an 
attachment in it's respective app.


I don't minimise the dangers - they are real, but I do think we're in a 
better poisiton in the unix desktop world than the current state of the 
windows desktop.


Cheers

Rich.




Current thread: