Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: [NTSEC] ActiveX, MSIE and Quicken
From: peter @ baileynm . com (Peter da Silva)
Date: Sun, 2 Feb 1997 18:35:37 -0600 (CST)
To: beck @ obtuse . com (Bob Beck)
Cc: peter @ baileynm . com, Russ . Cooper @ RC . on . ca, firewalls @ GreatCircle . COM
In-reply-to: <199702022158 . OAA02338 @ snouts . obtuse . com> from "Bob Beck" at Feb 2, 97 02:58:52 pm

> 	Banning ActiveX at the firewall is hardly taking away the MS
> desktops. It's still viable inside the firewall as long as you're
> talking about a relatively trusted environment. If you aren't talking
> about a relatively trusted environment inside you probably shouldn't
> be running an MS desktop anyway.

Oh, definitely. Russ's comment about it not being the whole OLE environment
but rather the web-enabled part of it being the poroblem is right on. The
terminology war, however, is lost... the phrase "ActiveX" is going to be
forever associated with applets, because that's the obvious technology
difference between OLE and ActiveX.

> 	Not all that inconcievable.  There are perfectly viable
> alternatives to an MS desktop for anyone who feels like using
> them.

Unfortunately, no. Not if you want to be able to effectively do business
in America today. Microsoft's file formats are everywhere, and they work very
hard at making sure that nothing but their products can use them effectively.

> 	Microsoft's desktop will always be completely unable to
> provide any useful security for the exact same reasons as we've seen
> for years and years with Sendmail.

It's worse than sendmail. Eric Allman isn't trying to make Sendmail do
everything (there's no http and nntp in there, for example), and Eric
*is* concerned about security. It's not at the top of the list, but at
least it's *on* the list.


References:
Indexed By Date Previous: NTBugTraq now available
From: Russ <Russ . Cooper @ RC . on . ca>
Next: Re: Optimal Throughput for NAT
From: Martin_Khoo/SIN/Lotus @ lotus . com
Indexed By Thread Previous: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Bob Beck <beck @ obtuse . com>
Next: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Mike Shaver <shaver @ neon . ingenia . ca>

Google
 
Search Internet Search www.greatcircle.com