Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ActiveX and RISKS
From: peter @ baileynm . com (Peter da Silva)
Date: Tue, 19 Nov 1996 12:15:56 -0600 (CST)
To: Russ . Cooper @ RC . on . ca (Russ)
Cc: lists @ reflections . mindspring . com, firewalls @ GreatCircle . COM
In-reply-to: <2191B2309F33D0118F7000A02458D19C000000017DF7 @ ns . rc . on . ca> from "Russ" at Nov 18, 96 07:11:41 pm

> Don't think I'm missing the dry wit in your message, but anyone could 
> have written a malicious NetScape plug-in if they wanted to and it 
> would have had a far greater impact than any ActiveX object in today's 
> browser arena,

It would have been no different than any other trojan horse (virus, etc).
You can't build a web page that automatically downloads and installs a
plug-in.

> ActiveX object has. And please don't tell me that you 
> have to install a plug-in

Why not? It's the truth. You can hit a malicious page with a single click
with no intent whatsoever of being curious or engaging in risky behaviour.

> Besides, you can't control the installation 
> of Netscape plug-ins any better than you can control the installation 
> of ActiveX objects.

But you can. Netscape won't install a plugin without the user saying so.

Even if there was a plugin with a security hole, (and there no doubt
are) you can resolve the problem by saying "don't install Hotshit Elite"
like you can say "don't install pkzip 3.00". When the browser goes ahead
and downloads "Kludgescript 13" because it's got a signature the browser
likes without asking you, you've got a problem from now until Microsoft
comes up with some way of revoking certificates.

> Of course, the fact that ActiveX objects "today" 
> are only risking Windows machines (the machines with Microsoft's 
> operating system), means their only shooting themselves in the foot, 
> not all the people running Unix, aren't they?

This isn't a UNIX versus MS thing (even ignoring WinDD, Softwindows, and
so on). This is a simple security issue. 


Follow-Ups:
References:
Indexed By Date Previous: Re: name "Firewall" (also cited in 1975 paper)
From: mckenney @ smiley . mitre . org (Brian W. McKenney)
Next: Re: Microsoft Proxy 1.0/ Firewall-1
From: "Martin C. Walker" <martinw @ epcorp . com>
Indexed By Thread Previous: RE: ActiveX and RISKS
From: Russ <Russ . Cooper @ RC . on . ca>
Next: Re: ActiveX and RISKS
From: Doug Wellington <doug @ sun1paztcn . wr . usgs . gov>

Google
 
Search Internet Search www.greatcircle.com