Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Finjan Surfin Gate Review
From: Adam Shostack <adam @ homeport . org>
Date: Sat, 8 Nov 1997 16:03:38 -0500 (EST)
To: peter @ baileynm . com (Peter da Silva)
Cc: jerry @ us . esafe . com, sjbrown @ bellsouth . net, firewalls @ GreatCircle . COM
In-reply-to: <9711080227 . AA15340 @ baileynm . com> from Peter da Silva at "Nov 7, 97 08:27:51 pm"

I'll mention that Security-7 (www.security7.com) has a product that
will look through the Java classes or ActiveX controls and allow you
to block things that you don't like.  (Thus, you could block all Java
that calls the file io classes.)

Adam


Peter da Silva wrote:
| > Protection from vandal applets is a new technology which is still being
| > defined...any thoughts?
| 
| Use the approach in HTML: don't allow the applets the ability to perform
| dangerous acts. If you want to do more, then explicitly download and
| install a plugin. That way you have control and you have to perform an
| explicit install before you're exposed.
| 
| The only applet technology I know of that does this is the Tk plugin, which
| actually removes all dangerous commands from the interpreter before running
| the applet, so even if it's hostile it has no access to anything outside the
| sandbox.
| 


-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume




Follow-Ups:
References:
Indexed By Date Previous: Security certification (Was: Re: [ANNOUNCE] NASA Computer ...)
From: Jyri Kaljundi <jk @ stallion . ee>
Next: Re: Private web-based email with SSL secure???
From: "Alexis Zephrides" <azephrides @ hotmail . com>
Indexed By Thread Previous: Re: Finjan Surfin Gate Review
From: Peter da Silva <peter @ baileynm . com>
Next: Re: Finjan Surfin Gate Review
From: Peter da Silva <peter @ baileynm . com>

Google
 
Search Internet Search www.greatcircle.com