Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ActiveX and RISKS
From: "Paul D. Robertson" <proberts @ clark . net>
Date: Tue, 19 Nov 1996 18:33:25 -0500 (EST)
To: Doug Wellington <doug @ sun1paztcn . wr . usgs . gov>
Cc: Peter da Silva <peter @ baileynm . com>, firewalls @ GreatCircle . COM
In-reply-to: <9611192128 . AA13263 @ sun1paztcn . wr . usgs . gov>

On Tue, 19 Nov 1996, Doug Wellington wrote:

> Previously:
> >Netscape won't install a plugin without the user saying so.
> 
> IE is the same...

No, it's not the same.  The level of effort is significantly less.  I had
some figures a year or so ago about the percentage of the user population
that would actually install a helper application.  It's the same with
plug-ins, I'd hazard, where Active-X is *much* easier to install.  This
_is_ an issue.


> a limited (Java?) VM or a more limited browser such as Mosaic.  Of course,
> while we're considering that direction, we should also consider X terminals,
> or maybe even going back to VT100 or 3270 terminals attached to a mainframe.
> Then we could really protect the users from themselves!  That's the direction
> of the Network Computer - take the responsibility away from the user.  But if
> we trust our users, then they should be allowed to choose for themselves...

If we trusted our users to enforce our security policies every day, we
wouldn't *need* firewalls.  They'd all install and maintain secure hosts.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
proberts @
 clark .
 net      which may have no basis whatsoever in fact."
                                                                     PSB#9280



References:
Indexed By Date Previous: Re: ActiveX and RISKS
From: Ken Hardy <ken @ bridge . com>
Next: RE: /Real/ Experience with Catapult?
From: Sven Dowideit <SvenDowideit @ cit . com . au>
Indexed By Thread Previous: Re: ActiveX and RISKS
From: Doug Wellington <doug @ sun1paztcn . wr . usgs . gov>
Next: Re: ActiveX and RISKS
From: carson @ lehman . com

Google
 
Search Internet Search www.greatcircle.com