Now to fix archivers
Posted Feb 27, 2009 18:23 UTC (Fri) by
hppnq (subscriber, #14462)
In reply to:
Now to fix archivers by liljencrantz
Parent article:
Desktop malware risk gets raised and patched
I am afraid you do not really understand what I mean. I was asking how many times you expect users to go through what could be easily perceived as a pointless dialog, and what exactly is accomplished by going through this dialog.
Those who believe that we can use the execute bit to indicate a certain level of trust are indeed forced to also take into account previously completely unrelated things, like permissions of archived files. Remember the security problem addressed here is about a kind of file that used to only be meaningful in a desktop environment. By requiring that desktop launchers be actual executables we have not really solved the actual problem at all, but I am all of a sudden stuck with a whole bunch of executables and a security policy that says "You trust all your executables".
There is no dialog on earth that could repair this.
So how would your dialog handle malicious RPM scripts?
(
Log in to post comments)