|
|
Log in / Subscribe / Register

The odd saga of CVE-2012-5639

The odd saga of CVE-2012-5639

Posted Jan 10, 2024 13:15 UTC (Wed) by pizza (subscriber, #46)
In reply to: The odd saga of CVE-2012-5639 by smurf
Parent article: The odd saga of CVE-2012-5639

> I want my office programs to not even think of talking to the network unless specifically directed to do so. I also want them to save documents locally instead of fetching bits and pieces (which might vanish at any time) from somewhere else.

For most corporate deployments of office programs, "talking to the network" is a mandatory feature that is routinely used. Heck, I'd argue that this is probably also routine in personal settings as well.

This "problem" seems to be an example of "there is no objectively correct default" for all user types.

(Personally I'd be in favor of "block remote resources by default with a warning bar across the top", with a pop-up UI to view the hostnames/etc as well as the allow/deny lists, as there's already other LO precedent for that sort of thing. But I also recognize that 98.3711% of the time the answer will be "allow, of course" leading to muscle memory allowing malicious content through)


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds