security issues with macros
Posted Mar 17, 2006 10:17 UTC (Fri) by
kingdon (subscriber, #4526)
In reply to:
Novell goes for the desktop by paulmfoster
Parent article:
Novell goes for the desktop
My thoughts too. This is probably fixable, though.
There needs to be some distinction between "installing
software" and "opening a document", with the former
needed to run the macros (no, I haven't thought hard
about how this should be done, but the concept is
something we've seen before on the Linux desktop -
for example in terms of whether to autorun a program
on a CD when it is inserted). Even a dialog box
saying "this document contains macros? do you want
to run them?", which might not be the ideal user
interface, would still be better than nothing.
In addition, or instead, there might be an issue
of sandboxing the macros somehow (I don't know
enough about how they work to comment intelligently
on how feasible that is).
(
Log in to post comments)