On Sat, 20 Sep 2003 05:45:36 -0700, Mark Jones wrote: ...
Quoted message said:This isn't a Microsoft coding problem. This is someone trying to get you to open an email and run
a program. Microsoft is not responsible if someone were to run format.com on their computer. It is
up to you personally to decide which programs you want to run.
Whether or not this is a Microsoft problem depends on semantics, it is a direct result of Microsoft
software architecture, design, and and marketing. Some of these problems could be fixed by
Microsoft, others cannot.
Users should not "Own" the machine. Unix (including Mac OS-X) include a root login that is allowed
to change the machine. Each use then has a user login that only allows them access to their own
data. In a Windows machine you need a server or professional level OS to do this. This would greatly
diminish the damage a worm or virus could do.
At a more technical level, the architecture of Windows allows programs to inter-operate too tightly
making it very hard to hide the private parts of programs that should not be accessed. An example of
this it the IE cannot be removed from Windows by us mortals so all of its security holes are still
available to rouge programs.
To make it easy for users, Microsoft turn on features by default. How many computers need a database
interface? (Very few.) How many people need a database interface open to the Internet? (Nobody.)
Keep things turned off unless actually needed.
Untrusted program should run in sandboxes. A sandbox is a special execution environment with very
restricted capabilities. Java has this capability, but MS refuses to use Java as they do not own or
control it. This could also be added to Windows, especially to .net, but MS has not done so.
Instead, MS has disabled embedded executables in email (which is just a well as email is usually
considered a text format). With this capability an email worm could do any damage.
Another problem that Windows has is that Windows has been marketed to novices as easy to use so we
have a lot of clueless users who don't know the basics of computer security. (Suggestions for the
clueless follow.)
Windows runs on 90% of all personal computers making them the biggest target. Be less of a target by
installing Linux or switching to a Mac with OS-X. (Note transition from pitch to call to action.)
If you must run Windows then:
- Install a firewall between your computer and DSL or cable modem. A hardware firewall is around
$50. Close incoming ports, close most outgoing ports (except email, HTTP, and whatever else you
need), and CHANGE THE PASSWORD of the firewall. If you use a dial-up or cannot get firewall then
install a software firewall such as zone-alarm (www.zonelabs.com). There is a free version.
- Loose Outlook. There is a free version of Eudora (www.eudora.com). Other email clients are
available.
- Loose IE. Netscape is now an open source browser called Mozilla (www.mozilla.org). It is improving
rapidly and probably has already surpassed IE in capabilities. If you have to use IE then use the
security settings to limit what can be run.
- Keep your machine up to date, use the update feature build into Windows.
Or better yet, loose Windows.
If your install of Windows is not licensed then be a legal cheapskate and install Linux.
Mandrake Linux has a good reputation for beginners, see www.mandrakelinux.com/en/. Red Hat is harder
to use, but has great emails about when to use their easy update system.
If you are reading this you already know how to read Usenet so you can get help and advice. Laptops
are a little trickier, check before install on a laptop. If you need to stay in service while you
figure out linux then install a dual boot system. You can get information on Linux install, dual
booting, and hardware compatibilities on the web or at local Linux user groups. Start with
www.lixux.org for pointers to both. Linux is not bug free, especially the latest stuff (often
referred to as bleeding-edge). You still need to apply updates and configure your system, but you
won't be part of the biggest target on the internet.
The internet is World-wide and speed-of-light. Your system security is the only protection for your
computer and the data stored on it. On the internet are crackers (black hat hackers), spammers,
thieves, scammers, spammers, organized crime, and terrorists in places ranging from Russia and the
old Eastern Block, the Middle East, China and Asia, South America, and even the US. These groups
will work together. A cracker breaks into a machine to launch other attacks, send spam email, and
steal any valuable data. Spam email includes scams to try and get credit card number and personal
data. Personal data is used for identity theft. Credit card numbers are sold to thieves. Terrorists
also use card numbers to finance their attacks.
Richard "Red Hat 7.3 migrating to Gentoo Linux" Kaiser