The odd saga of CVE-2012-5639
The odd saga of CVE-2012-5639
Posted Jan 10, 2024 13:23 UTC (Wed) by Wol (subscriber, #4433)In reply to: The odd saga of CVE-2012-5639 by smoogen
Parent article: The odd saga of CVE-2012-5639
Driven by the assumption that "resource is not finite". I can't remember the details, but I remember trying to point Windows at a network resource. It didn't work (very well). All the help documentation (including MS's own) said "you should cache this on your local hard drive". Didn't it cross anybody's mind that caching a terabyte resource from a server is rather hard when your laptop has a 250GB drive ... ??? (I think it was caching my home directory or something.)
And then there's Windows habit of downloading and caching the resources for every user who's ever logged onto a shared computer. So if you're not admin (and most people using computers like that aren't) the hard drive rapidly fills up with OTHER PEOPLES' crud. Which you can't even see, let alone delete to free up space!
This is all down to that "War of the Workstations" stuff - do you do things the MIT way - get it right, or the New Jersey way - get it out the door. If you really want security, you NEED to do it the MIT way, and not only that, the MIT way tends to *prevent* technical debt building up!
Cheers,
Wol
