SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : Microsoft Corp. - Moderated (MSFT)
MSFT 411.29-2.8%3:59 PM EST

 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext  
To: Jordan A. Sheridan who wrote (64)8/7/2002 8:09:54 AM
From: dybdahl   of 19790
 
Basically, the flaw is that there is no internal security on Windows. Microsofts answer is that they know, and that Microsoft recommends to its customers not to trust the internal security systems in Windows, and instead protect the computer from intrusion from the outside.

Unfortunately, history has shown that internal security is important. Not only because it is easy to make Windows users run programs, that come from untrusted sources (human errors), but also because simple exploits can give administrator rights to the intruder if the internal security isn't good enough.

But in some sense you are right: Most security experts do not trust Windows to be secure internally - all effort is being put into making it impossible to intrude in the first place, even though many programs and scripts running on exposed systems are not secure.

So basically this is just another way to get administrator rights once you got in, that has to be added to the list. There is not much new about it, and Microsoft can't fix this one either without breaking compatibility.

Dybdahl.
Report TOU ViolationShare This Post
 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext