Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Is ActiveX Microsoft's undoing?

0 views
Skip to first unread message

dee...@cu-online.com

unread,
Nov 20, 1996, 3:00:00 AM11/20/96
to

This article is an attempt to expand on the points that Wired Magazine
raised in its article "Will ActiveX Threaten National Security?",
available at http://www.wired.com/news/ .

In the article, Mr. Garfinkel argues that since ActiveX allows arbitrary
executables to be executed on a user's machine *without the user's
knowledge or consent*, and since at least one branch of the military
has adopted MSIE (an ActiveX enabled browser) as its standard, Microsoft
is compromising national security.

These points are pretty obvious to anyone with even novice-level
knowledge of the way computers work. Running strange programs on a
network-enabled computer is clearly dangerous; what is particularly
chilling is the fact that Microsoft, in its eagerness to conquer the
Internet, ignored the danger and not only implemented such a scheme,
but is giving it away and giving people financial incentives to adopt
its browser.

Would you like to know what kinds of things a hostile program can do
to your computer? Well, just imagine that I had, instead of posting
this article, referred you to a web page. And that your web browser
of choice is Microsoft Internet Explorer. Then right now, through
a hostile program, I could be using your computer to:

* Send a death threat to the president of the United States.
* Email me all your confidential letters, and using the data therein
to blackmail you.
* Scramble all the documents on your hard drive. This is even worse
that formatting your hard drive, because there's no way to
"unscramble" documents.

Of course, I wouldn't do such a thing. But are you willing to bet your
computer that *nobody* will ever do such a thing? As Fred McLain has
demonstrated, a single ActiveX control (called, appropriately, "ActiveX
Exploder") can shut down your computer. The source code for the ActiveX
Exploder control is available, and it's only a matter of time before
a malicious person creates a version that does something like what I've
described above, or even worse.

Proponents of ActiveX have pointed out that there are two obstacles
to people using ActiveX maliciously.

The first obstacle is that MSIE won't automatically download an ActiveX
control unless it has been digitally signed by Verisign. Since the
only way to get a Verisign signature is to agree "not to use the
signature for malicious purposes", this will supposedly stop people
from doing anything dangerous with it.

However, the flaw in this scheme is that criminals don't obey contracts.
Sure, they'll "agree" to the contract, and then go ahead and write
viruses anyway. So the Verisign signature is worthless.

The second obstacle is that it takes resources to run a web site.
Someone who can afford to run a reasonably popular web site will have
too much to lose by putting viruses on his web page. Therefore, you
are "safe" as long as you only go to web sites owned by large
corporations. (A point that Garfinkel made, by the way.)

But suppose someone hacks a popular website? Suppose a million users
come to visit Yahoo one morning, and get their hard disks formatted as
a reward? Yahoo would undoubtedly be damaged from such an attack, and
might even go under in a flurry of lawsuits. Is any corporation willing
to take the risk of losing millions of dollars and all kinds of goodwill
just because someone hacked their web server? It could happen to
anyone...

Microsoft has made a mistake which cannot be undone. Millions of users
now own unsecured copies of Microsoft Internet Explorer, and those
users will be in danger for months, even years. And this means that
Microsoft has created an incentive for popular websites to actively
discourage the use of Microsoft Internet Explorer.

In addition, Microsoft is making ActiveX a first-class citizen in its
future operating systems. Not only will you be in danger every time
you visit a web site, you'll be in danger whenever you connect your
Windows system to a network.

The very concept of ActiveX demonstrates a dangerous naivete on
Microsoft's part. ActiveX is doomed, and it just might drag Microsoft
with it.

-- Jack Wilson, dee...@cu-online.com

ps. Be sure to read that article! http://www.wired.com/news/

-----------------------------------------------------------------------
This article was posted to Usenet via the Posting Service at Deja News:
http://www.dejanews.com/ [Search, Post, and Read Usenet News]

David LeBlanc

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

dee...@cu-online.com wrote:

>In the article, Mr. Garfinkel argues that since ActiveX allows arbitrary
>executables to be executed on a user's machine *without the user's
>knowledge or consent*,

Mr. Garfinkel is incorrect.

>and since at least one branch of the military
>has adopted MSIE (an ActiveX enabled browser) as its standard, Microsoft
>is compromising national security.

Quite a stretch to base such a conclusion on an incorrect premise.

>These points are pretty obvious to anyone with even novice-level
>knowledge of the way computers work.

This is about like saying that it is well known that the aliens will
take over the planet, so we are all doomed. If the premise isn't
correct, the conclusion is meaningless.

>Would you like to know what kinds of things a hostile program can do
>to your computer?

Do you have _any_ idea what I can do with setup.exe?

> * Send a death threat to the president of the United States.

Oooh. I'm really afraid. Probably more likely that the aliens will
take over.

> * Email me all your confidential letters, and using the data therein
> to blackmail you.

You don't need ActiveX for this - just Netscape! Plus you'd have to
know _where_ I keep my letters.

>As Fred McLain has
>demonstrated, a single ActiveX control (called, appropriately, "ActiveX
>Exploder") can shut down your computer.

Funny, I downloaded and ran it, and my computer didn't shut down.
Didn't do anything. Fred says it doesn't work on NT.

>The first obstacle is that MSIE won't automatically download an ActiveX
>control unless it has been digitally signed by Verisign.

It still won't automatically download a control unless you loosen the
security from default. Your premise is incorrect.

>It could happen to
>anyone...

The aliens could land in your bathroom, too. Be afraid. Very afraid.


David LeBlanc | We do not want computers that do more,
dleb...@mindspring.com | we want computers that do less.
| Oracle Chairman Larry Ellison


Richard M. Smith

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

> As Fred McLain has
> demonstrated, a single ActiveX control (called, appropriately, "ActiveX

> Exploder") can shut down your computer. The source code for the ActiveX
> Exploder control is available, and it's only a matter of time before
> a malicious person creates a version that does something like what I've
> described above, or even worse.

An interesting thing is that Microsoft has their own version of the
"Exploder"
control. Its called ActiveMovie. Its designed to play AVI movies within
Internet Explorer. It becomes an exploder control if it is told to play
a movie from the URL file:///AUX . This URL locks up ActiveMovie and
often crashes Windows 95.

The problem here is more then just malicous ActiveX controls. Standard
ActiveX controls can also be exploited by the "bad guys" to do malicous
things.

Richard

Jon A. Maxwell

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

David LeBlanc wrote:

] dee...@cu-online.com wrote:
]
] >In the article, Mr. Garfinkel argues that since ActiveX allows
] >arbitrary executables to be executed on a user's machine
] >*without the user's knowledge or consent*,
]
] Mr. Garfinkel is incorrect.

The Internet Explorer 3.0 in the lab has absolutely no checks (I
think you can turn ActiveX on/off, default is on, no "levels" of
security). How many others are still using the version before
Microsoft "fixed the bug"?

Regardless, many people will have it set to automatically get
ActiveX from sites such as www.microsoft.com or www.yahoo.com.
Simply hack into those sites and millions will be affected before
anybody fixes it. Months ago, the DOJ web sites were hacked into
and were made to deliver pictures of swastikas and nazi images
(this isn't end of discussion reference) so it can be done to
so-called secure sites.

] >Would you like to know what kinds of things a hostile program


] >can do to your computer?
]
] Do you have _any_ idea what I can do with setup.exe?

Oh yeah, and a million people will download and run setup.exe
every day by doing nothing other than web surfing. You obviously
don't understand the difference and never will as it has been
explained to you, Dave, many times.


] > * Email me all your confidential letters, and using the data therein


] > to blackmail you.
]
] You don't need ActiveX for this - just Netscape! Plus you'd have to
] know _where_ I keep my letters.

An ActiveX control can export your filesystem to my computer, or
open up a communication channel so that I can *tell it* what I
want from you.

BTW, security through obscurity is not a good thing, these days.

] >As Fred McLain has demonstrated, a single ActiveX control


] >(called, appropriately, "ActiveX Exploder") can shut down your
] >computer.

]
] Funny, I downloaded and ran it, and my computer didn't shut down.


] Didn't do anything. Fred says it doesn't work on NT.

I've written one (that I haven't released and don't plan on it)
that contains a primitive virus (it doesn't mutate or anything
fancy). I've demonstrated that it will infect NT, and it is
permissions-ownership aware so as to not look suspicious in logs.
What do you think I was learning NT for this semester?

Really tempting to put it on my web page or distribute it to the
hacker crowd ..

] David LeBlanc | We do not want computers that do more,


] dleb...@mindspring.com | we want computers that do less.
] | Oracle Chairman Larry Ellison

--
thur Mail Address: LordA...@vt.edu or jmax...@vt.edu
n r
a JAMax "You can fool all the people some of the time, and some
h o w of the people all the time, but you can not fool all
tan lle the people all of the time." --Abraham Lincoln


Des Herriott

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

In article <8485283...@dejanews.com>,

dee...@cu-online.com writes:
> This article is an attempt to expand on the points that Wired Magazine
> raised in its article "Will ActiveX Threaten National Security?",
> available at http://www.wired.com/news/ .

Pretty scary, really. I like the comment at the end:

So now you know what's wrong with ActiveX. If it's successful, the
only computers left on the Internet will be Intel-based PCs running
Windows 95 and Windows NT. And the only Web pages that people will
dare look at will be those published by major corporations, because
looking anywhere else on the Web will be too risky.

Although I'm not sure it's correct. If ActiveX is successful (and I
think it will be, but not because it's actually any good), then with
any luck the only computers left on the Internet will be non-Microsoft
machines because all the Microsoft machines will have had their hard
drives formatted.

Well, I can always hope :-)

--
Des Herriott
d...@corp.netcom.net.uk

Eugene O'Neil

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

>Would you like to know what kinds of things a hostile program can do
>to your computer? Well, just imagine that I had, instead of posting
>this article, referred you to a web page. And that your web browser
>of choice is Microsoft Internet Explorer. Then right now, through
>a hostile program, I could be using your computer to:
>
> * Send a death threat to the president of the United States.
> * Email me all your confidential letters, and using the data therein
> to blackmail you.
> * Scramble all the documents on your hard drive. This is even worse
> that formatting your hard drive, because there's no way to
> "unscramble" documents.

No, because when I'm browsing a web page of someone I don't even know, and
Explorer asks me "Do you want to load this ActiveX control?" I click no. It's as
simple as that.

I use Explorer under Windows because it is great at executing Java. I only
download ActiveX components sparingly, and then only from microsoft itself.
These scare-stories act as if you can't choose not to load ActiveX controls,
and that's simply not true. There is nothing to be afraid of, you just have to
be careful.

-Eugene

Eugene O'Neil

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

In article <01bbd759$722c7d00$a781...@tiac.net.tiac.net>, "Richard M. Smith" <r...@pharlap.com> wrote:
>
>> As Fred McLain has
>> demonstrated, a single ActiveX control (called, appropriately, "ActiveX
>> Exploder") can shut down your computer. The source code for the ActiveX
>> Exploder control is available, and it's only a matter of time before
>> a malicious person creates a version that does something like what I've
>> described above, or even worse.
>
>An interesting thing is that Microsoft has their own version of the
>"Exploder"
>control. Its called ActiveMovie. Its designed to play AVI movies within
>Internet Explorer. It becomes an exploder control if it is told to play
>a movie from the URL file:///AUX . This URL locks up ActiveMovie and
>often crashes Windows 95.
>
>The problem here is more then just malicous ActiveX controls. Standard
>ActiveX controls can also be exploited by the "bad guys" to do malicous
>things.

This is exactly equivilent to exploiting a hypothetical bug in Netscape's html
parser, that would cause the machine to crash. Or how about sending an enourmous
TCP packet at a machine, that clogs up the network software and takes the rest
of the machine down with it? Trusted code that contains bugs can be exploited
whether or not it is in ActiveX.

-Eugene

Rob Barris

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

In article <E18CG...@world.std.com>, eug...@cs.umb.edu (Eugene O'Neil) wrote:

> >Would you like to know what kinds of things a hostile program can do
> >to your computer? Well, just imagine that I had, instead of posting
> >this article, referred you to a web page. And that your web browser
> >of choice is Microsoft Internet Explorer. Then right now, through
> >a hostile program, I could be using your computer to:
> >
> > * Send a death threat to the president of the United States.
> > * Email me all your confidential letters, and using the data therein
> > to blackmail you.
> > * Scramble all the documents on your hard drive. This is even worse
> > that formatting your hard drive, because there's no way to
> > "unscramble" documents.
>
> No, because when I'm browsing a web page of someone I don't even know, and
> Explorer asks me "Do you want to load this ActiveX control?" I click no.
It's as
> simple as that.

Perhaps not as simple as that - the assertion has been made that it is
possible to "trick" controls which have been downloaded a long time ago
(and contain no code of malicious intent) to overwrite files, email files
from your machine back to the host, etc.
Thus a page can be constructed to exploit these code "flaws" and cause
you harm or hassle even though you never actually downloaded any new code
at all. It happened to a friend of mine.

Rob Barris
Quicksilver Software Inc.
rba...@quicksilver.com
* Opinions expressed not necessarily those of my employer *

Allan Peretz

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

Eugene O'Neil wrote:
> No, because when I'm browsing a web page of someone I don't even know, and
> Explorer asks me "Do you want to load this ActiveX control?" I click no. It's as
> simple as that.
>
> I use Explorer under Windows because it is great at executing Java. I only
> download ActiveX components sparingly, and then only from microsoft itself.
> These scare-stories act as if you can't choose not to load ActiveX controls,
> and that's simply not true. There is nothing to be afraid of, you just have to
> be careful.
>
> -Eugene


Eugene:

You're missing the point. In an enterprise, we are not only concerned
about
what *we* would do, but what are users will do. Anyone who works with
users
knows that they will invariably do things that could compromise the
network
due to lack of knowledge or lack of concern. This is where ActiveX is
dangerous.
Does you trust that your company's accounting staff really knows enough
about
the internet to understand the implications of ActiveX controls? Will
they
press "No" when asked whether or not to download a control from an
untrusted
source? What happens when your company's five year strategic plan slips
past
your firewall and onto your competitor's hard drive?

-Allan

Jon A. Maxwell

unread,
Nov 21, 1996, 3:00:00 AM11/21/96
to

Eugene O'Neil wrote:
] I use Explorer under Windows because it is great at executing

] Java. I only download ActiveX components sparingly, and then
] only from microsoft itself. These scare-stories act as if you
] can't choose not to load ActiveX controls, and that's simply
] not true. There is nothing to be afraid of, you just have to be
] careful.

What a hypocrite you are, Eugene! "There's nothing to be afraid
of" ... "I only download ActiveX components sparingly"

It seems like you *know* what threat ActiveX poses to your
computer. You just can't admit it.

] -Eugene

--
thur Mail Address: LordA...@vt.edu or jmax...@vt.edu
n r

a JAMax "Though it be long, the work is complete and finished
h o w in my mind. I take out of the bag of my memory what
tan lle has previously been collected into it." --Mozart


David LeBlanc

unread,
Nov 22, 1996, 3:00:00 AM11/22/96
to

jmax...@csugrad.cs.vt.edu (Jon A. Maxwell) wrote:

>David LeBlanc wrote:
>] dee...@cu-online.com wrote:

>] >In the article, Mr. Garfinkel argues that since ActiveX allows
>] >arbitrary executables to be executed on a user's machine
>] >*without the user's knowledge or consent*,

>] Mr. Garfinkel is incorrect.

>The Internet Explorer 3.0 in the lab has absolutely no checks (I
>think you can turn ActiveX on/off, default is on, no "levels" of
>security). How many others are still using the version before
>Microsoft "fixed the bug"?

You are quite mistaken, or just outright lying. Considering your past
performance in terms of credibility, it could well be either.

If you look under View, Options, and choose the security tab, you will
see toggles for:

Allow downloading of active content (toggles Java and ActiveX)
Enable ActiveX controls and plug-ins
Run ActiveX scripts
Enable Java Programs

Then, if you look in the Certificates section, it will show you the
certificates you have chosen as trusted. These can be set on a
personal, site, or company level.

I am running IE 3.0 (not patched). I've shown yet again that you don't
have the foggiest idea what you are talking about, and that Mr.
Garfinkel is indeed incorrect. You're really a discredit to UNIX
advocates - the vast majority of them seem to have a clue and know
what they are talking about.

>] Do you have _any_ idea what I can do with setup.exe?

>Oh yeah, and a million people will download and run setup.exe
>every day by doing nothing other than web surfing.

Sure they can. And do.

>] > * Email me all your confidential letters, and using the data therein
>] > to blackmail you.


>] You don't need ActiveX for this - just Netscape! Plus you'd have to
>] know _where_ I keep my letters.

>An ActiveX control can export your filesystem to my computer, or
>open up a communication channel so that I can *tell it* what I
>want from you.

Not my computer, you can't.

>What do you think I was learning NT for this semester?

So that you could play a dunce on USENET?

>Really tempting to put it on my web page or distribute it to the
>hacker crowd ..

I'm quite sure they can do much better.

David LeBlanc

unread,
Nov 22, 1996, 3:00:00 AM11/22/96
to

eug...@cs.umb.edu (Eugene O'Neil) wrote:

Yep - about the same as how the bug in gethostbyname() that cropped up
in Solaris just recently allows people to become root with a wide
variety of typical processes.

Stefan Bauch

unread,
Nov 22, 1996, 3:00:00 AM11/22/96
to

Allan Peretz wrote:
> the internet to understand the implications of ActiveX controls?
> Will they press "No" when asked whether or not to download a
> control from an untrusted source?

I am not the most advanced guy in computer security but I assure
you: There ain't such thing as a trusted host. At least not in
reality. Just think of the tampered CIA-page: The title was changed
to "Central Stupidity Agency"...

There aint' such thing as a free lunch either... :-)

Stefan.

--
Stefan Bauch -- SC Rechnungswesen/ Organisation und Datenverarbeitung
K703, 65926 Frankfurt am Main, Germany -- Tel. +49 69 305-18107
ba...@msmfrwd.frankfurt.hoechst-ag.d400.de / privat:ba...@RoBIN.de

--== Win16,Win32s,Win32c,Win32 - Which API do you want to go today? ==--

Larry Kilgallen

unread,
Nov 22, 1996, 3:00:00 AM11/22/96
to

In article <3294F2...@pobox.com>, Allan Peretz <pre...@pobox.com> writes:

> You're missing the point. In an enterprise, we are not only concerned
> about what *we* would do, but what are users will do. Anyone who works
> with users knows that they will invariably do things that could
> compromise the network due to lack of knowledge or lack of concern.
> This is where ActiveX is dangerous. Does you trust that your company's

> accounting staff really knows enough about the internet to understand


> the implications of ActiveX controls? Will they press "No" when asked
> whether or not to download a control from an untrusted source?

Particularly, will they decline the download if it offers considerable
assistance for completion of _their_ part of the organization's
workflow ?

Consider this as analogous to the question of how many Computer
Security professionals would decline to use truly great security
software which would really solve the organization's problems,
merely because it violated some other policy such as always
getting software from some favored vendor? Certainly the
answer is not 100%.

Larry Kilgallen

Jon A. Maxwell

unread,
Nov 22, 1996, 3:00:00 AM11/22/96
to

David LeBlanc wrote:
] jmax...@csugrad.cs.vt.edu (Jon A. Maxwell) wrote:
]
] >The Internet Explorer 3.0 in the lab has absolutely no checks

] >(I think you can turn ActiveX on/off, default is on, no
] >"levels" of security). How many others are still using the
] >version before Microsoft "fixed the bug"?
]
] You are quite mistaken, or just outright lying. Considering
] your past performance in terms of credibility, it could well be
] either.

Hmm, if I get my account and start using the IE in the lab it
will download and run ActiveX from anywhere without asking me
anything. But your are right I think about the levels of
security --it does have the so-called 'high, lo, whatever'
levels.

I forgot about that minor detail .. I don't use IE much as
being an educational site we get Netscape free (and free vs. free
Netscape still beats IE in my book).

[ Dave flying off into the land called Rant, cut ]

--JAM


Hasdi Rodzmann Hashim

unread,
Nov 23, 1996, 3:00:00 AM11/23/96
to

This is unbelievable. I remember the days when 99.99% of all program,
commercial or shareware has a disclaimer on it, relieving the producer all
damages that may result in the use of the software. Now Microsoft expects
someone to make some sort of a contract promising everyone that the
software (in this case, ActiveX controls) won't do anything malicious?
Even if it is not in the programmer's intent, the program could have bugs
that inadvertently that erases someone's harddisk. Java was designed from
beginning that this would not happen. It would be a legal nightmare.

Good luck Microsoft. You are going to need it.

Ian G Batten

unread,
Nov 25, 1996, 3:00:00 AM11/25/96
to

-----BEGIN PGP SIGNED MESSAGE-----

In article <573bf6$l...@camel2.mindspring.com>,


David LeBlanc <dleb...@mindspring.com> wrote:
> Yep - about the same as how the bug in gethostbyname() that cropped up
> in Solaris just recently allows people to become root with a wide
> variety of typical processes.

True, but that's a bug in Solaris, fixable by SunSoft, which does not in
its fixing break anything legitimate. The ActiveX issue is that the
architecture of the beast requires you to _trust_ unknown code. Java
has in principle a security model; any breaches in that are flaws in the
Java concept or implementation. ActiveX is the same, except its
security model is rather less strong (in my opinion).

ian

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQB1AwUBMpljXMoy0yij3IvtAQHgeAMAnglsSdBSsMi+1tXfotxJRA+9moLIimd0
uw/DwO4yIAqJcm8ot2gWPZ1YU8FQcklqNc7cLWDFiocomVCXFLc6XA0P2XidSjGr
6UKoBiLFQdMPEruJizOCKqZAqaO06rVJ
=lz06
-----END PGP SIGNATURE-----

Chris Cannon

unread,
Nov 25, 1996, 3:00:00 AM11/25/96
to

In article <8485283...@dejanews.com>, <dee...@cu-online.com> wrote:
>This article is an attempt to expand on the points that Wired Magazine
>raised in its article "Will ActiveX Threaten National Security?",
>available at http://www.wired.com/news/ .
>
>In the article, Mr. Garfinkel argues that since ActiveX allows arbitrary
>executables to be executed on a user's machine *without the user's
>knowledge or consent*, and since at least one branch of the military

>has adopted MSIE (an ActiveX enabled browser) as its standard, Microsoft
>is compromising national security.

Computers "behind the wall" (no, I don't mean an internet firewall)
are NOT on the internet. (At least not at my company).

--
--
=================
can...@netcom.com

David Collier-Brown

unread,
Nov 26, 1996, 3:00:00 AM11/26/96
to

Eugene O'Neil wrote:
> . I only
> download ActiveX components sparingly, and then only from microsoft itself.
> These scare-stories act as if you can't choose not to load ActiveX controls,
> and that's simply not true. There is nothing to be afraid of, you just have to
> be careful.


Well, that's clearly advantageous to Microsoft: if they
release a product that no-one will use with anyone else's software,
then it's a clear win. It's probably an accidental win, but
I wouldn't dount that some salespersons are right now doing the
Fear, Uncertainty and Doubt dance...

However, I hacen't seen the real problem discussed
thus far: the active-x application with be run **WITHOUT QUESTIONING THE
USER** if it has a verisign certificate.
The example exploder at
http://simson.vineyard.net/activex/Exploder.ocx was distributed
with a valid verisign certificate, on the grounds that it was a
non-malicious demonstration of a security problem...

How hard is it to steal a certificate from someone's
workplace?

--dave
--
David Collier-Brown, | Always do right. This will gratify some people
185 Ellerslie Ave., | astonish the rest. -- Mark Twain
Willowdale, Ontario | dav...@hobbes.ss.org, canada.sun.com
N2M 1Y3. 416-223-8968 | http://java.science.yorku.ca/~davecb

Gregory Junker

unread,
Nov 26, 1996, 3:00:00 AM11/26/96
to Olaf Titz

Olaf Titz wrote:
>
> > > available at http://www.wired.com/news/ .
> > Pretty scary, really. I like the comment at the end:
> > So now you know what's wrong with ActiveX. If it's successful, the
> > only computers left on the Internet will be Intel-based PCs running
> > Windows 95 and Windows NT. And the only Web pages that people will
>
> Now we know what's really wrong: That nobody can tell the difference
> between Internet and WWW any more.
>
> olaf
> --
> ___ Olaf...@inka.de or @{stud,informatik}.uni-karlsruhe.de ____
> __ o <URL:http://www.inka.de/~bigred/> <IRC:praetorius>
> __/<_ >> Just as long as the wheels keep on turning round
> _)>(_)______________ I will live for the groove 'til the sun goes down << ____

Is there a difference anymore?

Gosh, I miss the days when the neatest thing since sliced bread was
NcFTP, and Telnet with colors was unspeakably advanced....

TURN OFF THE IMAGES, AND UNCLOG THE PIPES!!!

(There, now I feel better... :-)
--
Gregory Junker - Systems Development
Federated Department Stores

David LeBlanc

unread,
Nov 27, 1996, 3:00:00 AM11/27/96
to

David Collier-Brown <dav...@canada.sun.com> wrote:

>However, I hacen't seen the real problem discussed
>thus far: the active-x application with be run **WITHOUT QUESTIONING THE
>USER** if it has a verisign certificate.
> The example exploder at
>http://simson.vineyard.net/activex/Exploder.ocx was distributed
>with a valid verisign certificate, on the grounds that it was a
>non-malicious demonstration of a security problem...

Would you care to explain why it is that my browser a) didn't run the
control, and b) asked me what I wanted to do with it?

tomp

unread,
Nov 27, 1996, 3:00:00 AM11/27/96
to

sure,

Verisign demanded the key be removed and it was.
Point is, while the key was there it worked.

tomp

In article <57g1i6$g...@camel4.mindspring.com>, dleb...@mindspring.com

David Collier-Brown

unread,
Nov 27, 1996, 3:00:00 AM11/27/96
to David LeBlanc

David LeBlanc wrote:
> Would you care to explain why it is that my browser a) didn't run the
> control, and b) asked me what I wanted to do with it?

Because the certificate was invalidate at Verisgn's insistance.

Eugene O'Neil

unread,
Nov 27, 1996, 3:00:00 AM11/27/96
to

In article <329AF8...@canada.sun.com>, David Collier-Brown <dav...@canada.sun.com> wrote:
> However, I hacen't seen the real problem discussed
>thus far: the active-x application with be run **WITHOUT QUESTIONING THE
>USER** if it has a verisign certificate.
> The example exploder at
>http://simson.vineyard.net/activex/Exploder.ocx was distributed
>with a valid verisign certificate, on the grounds that it was a
>non-malicious demonstration of a security problem...

I tried downloading that URL, and this is the message Explorer gave me:

This page contains active content that is not verifiably safe to
display. To protect your computer, this content will not be
displayed.

Choose Help to find out how you can change your safety settings
so that you can view potentially unsafe content.

[OK] [Help]

I clicked OK, the dialog dissapeared, and now I'm writing this message. It
didn't load the ActiveX control without my knowledge, and it certianly didn't
reboot my machine, as you claimed it would. Please refrain from spreading such
misinformation in the future. By praying apon the fear, ignorance and doubt of
the uninformed masses, you make yourself no better than the worst Microsoft
advocate.

-Eugene


Eugene O'Neil

unread,
Nov 27, 1996, 3:00:00 AM11/27/96
to

In article <57g1i6$g...@camel4.mindspring.com>, dleb...@mindspring.com (David LeBlanc) wrote:
>David Collier-Brown <dav...@canada.sun.com> wrote:
>
>>However, I hacen't seen the real problem discussed
>>thus far: the active-x application with be run **WITHOUT QUESTIONING THE
>>USER** if it has a verisign certificate.
>> The example exploder at
>>http://simson.vineyard.net/activex/Exploder.ocx was distributed
>>with a valid verisign certificate, on the grounds that it was a
>>non-malicious demonstration of a security problem...
>
>Would you care to explain why it is that my browser a) didn't run the
>control, and b) asked me what I wanted to do with it?

The http server sent it with the wrong MIME type. You actually need to load
it from http://simson.vineyard.net/activex/Exploder.html, which refers to the
control in a way that Explorer understands.

Once you go to that URL, Explorer will load the control (or not load it)
according to the security setup you have chosen. The default behaviour is to ask
if the control should be loaded: you may also choose to never load controls,
or always load them without asking. It is that last security option (which I
stress you have to set by hand) that these people would like you to think is an
unavoidable pitfall of ActiveX.

-Eugene

Andrew Harrison

unread,
Nov 28, 1996, 3:00:00 AM11/28/96
to

ActiveX will probably not be the undoing of MS. It will probably
be the undoing of any small sofware component company who relies
on it as the basis for developing product.

The reasons are fairly simple to understand.

The majority of analysts, pundits etc are advising corporations
that ActiveX is not secure and that if they must use it they
should only do so from signed named large "trustworthy suppliers".

So the list would be something like.

www.microsoft.com/
www.lotus.com/
www.corel.com/
www.oracle.com/
www.sybase.com/
www.ca.com/
www.informix.com/

Bzzzzt sorry little people you arn't on my approved suppliers
list of ActiveX conn trolls suppliers.

Regards

Andrew Harrison
Senior Consultant SunUK

Massimo Campostrini

unread,
Nov 28, 1996, 3:00:00 AM11/28/96
to

Andrew Harrison <andrew....@uk.sun.com> writes:

> Bzzzzt sorry little people you arn't on my approved suppliers
> list of ActiveX conn trolls suppliers.

===========

Is this Freudian or intentional? I like it!

--
Massimo Campostrini,
Istituto Nazionale di Fisica Nucleare, Sezione di Pisa.
WWW home page: http://www.difi.unipi.it/~campo/

Terje Bergesen

unread,
Nov 28, 1996, 3:00:00 AM11/28/96
to

Eugene O'Neil wrote:

[...]


> I tried downloading that URL, and this is the message Explorer gave me:
>
> This page contains active content that is not verifiably safe to

[...]


> I clicked OK, the dialog dissapeared, and now I'm writing this message. It
> didn't load the ActiveX control without my knowledge, and it certianly didn't
> reboot my machine, as you claimed it would. Please refrain from spreading such
> misinformation in the future. By praying apon the fear, ignorance and doubt of
> the uninformed masses, you make yourself no better than the worst Microsoft
> advocate.

He is basically not spreading misinformation. The reason for the
message above is that fact that the control no longer has a
signature, which you could read from the above sentence...


--
____________________________________________________________________
--- Terje : t.ber...@shell.no - I speak only for ME.
---
--- <!--#include virtual="/docs/std/disclaimer.txt" -->

David LeBlanc

unread,
Nov 28, 1996, 3:00:00 AM11/28/96
to

eug...@cs.umb.edu (Eugene O'Neil) wrote:

>In article <57g1i6$g...@camel4.mindspring.com>, dleb...@mindspring.com (David LeBlanc) wrote:

>>Would you care to explain why it is that my browser a) didn't run the
>>control, and b) asked me what I wanted to do with it?

>The http server sent it with the wrong MIME type. You actually need to load
>it from http://simson.vineyard.net/activex/Exploder.html, which refers to the
>control in a way that Explorer understands.

Tried that. It didn't load or run the control. It just took me to
Netscape's page. Interesting in that it appears to just completely
ignore unsigned controls. I wonder how I'm supposed to develop them?

>Once you go to that URL, Explorer will load the control (or not load it)
>according to the security setup you have chosen. The default behaviour is to ask
>if the control should be loaded: you may also choose to never load controls,
>or always load them without asking. It is that last security option (which I
>stress you have to set by hand) that these people would like you to think is an
>unavoidable pitfall of ActiveX.

Right. I'm glad someone else sees this. It isn't even the default
setting on install. I do have ActiveX downloading enabled, but there
are no certificates I implicitly trust.

David LeBlanc

unread,
Nov 28, 1996, 3:00:00 AM11/28/96
to

>In article <57g1i6$g...@camel4.mindspring.com>, dleb...@mindspring.com
>(David LeBlanc) wrote:

to...@bitstream.net (tomp) wrote:

>> Would you care to explain why it is that my browser a) didn't run the
>> control, and b) asked me what I wanted to do with it?

>sure,

>Verisign demanded the key be removed and it was.
>Point is, while the key was there it worked.

Yeah, and you guys keep telling me my browser will download stuff
without asking me. It doesn't. $20 or a Domino's gift certificate to
the first person to show me a site where _my_ browser downloads and
runs an ActiveX control without asking me. Signed or not.

James C. McPherson

unread,
Nov 29, 1996, 3:00:00 AM11/29/96
to

On Wed, 27 Nov 1996 19:17:40 GMT, eug...@cs.umb.edu (Eugene O'Neil)
wrote:

[snip]


>I tried downloading that URL, and this is the message Explorer gave me:
>
> This page contains active content that is not verifiably safe to

> display. To protect your computer, this content will not be
> displayed.
>
> Choose Help to find out how you can change your safety settings
> so that you can view potentially unsafe content.
>
> [OK] [Help]
>

>I clicked OK, the dialog dissapeared, and now I'm writing this message. It
>didn't load the ActiveX control without my knowledge, and it certianly didn't
>reboot my machine, as you claimed it would. Please refrain from spreading such
>misinformation in the future. By praying apon the fear, ignorance and doubt of
>the uninformed masses, you make yourself no better than the worst Microsoft
>advocate.


You must have missed the earlier postings saying that Verisign
demanded that the signature be removed. Once it was removed, MSIE
would obviously not be able to disregard the security factors __unless
you instructed it to in your preferences settings__.

You just came in a little late to the discussion, so please don't put
your foot in your mouth by accusing regulars with good reputations of
spreading fear and ignorance when you haven't got the whole story.

cheers,
jcm

Historian/InterLibraryLoans/ITLO/Branch Sysmangler
mljm...@dingo.cc.uq.edu.au
j.mcp...@central1.library.uq.edu.au

David LeBlanc

unread,
Dec 1, 1996, 3:00:00 AM12/1/96
to

j.mcp...@central1.library.uq.oz.au (James C. McPherson) wrote:

>On Wed, 27 Nov 1996 19:17:40 GMT, eug...@cs.umb.edu (Eugene O'Neil)
>wrote:

>>I clicked OK, the dialog dissapeared, and now I'm writing this message. It

>>didn't load the ActiveX control without my knowledge, and it certianly didn't
>>reboot my machine, as you claimed it would. Please refrain from spreading such
>>misinformation in the future. By praying apon the fear, ignorance and doubt of
>>the uninformed masses, you make yourself no better than the worst Microsoft
>>advocate.

>You must have missed the earlier postings saying that Verisign
>demanded that the signature be removed. Once it was removed, MSIE
>would obviously not be able to disregard the security factors __unless
>you instructed it to in your preferences settings__.

>You just came in a little late to the discussion, so please don't put
>your foot in your mouth by accusing regulars with good reputations of
>spreading fear and ignorance when you haven't got the whole story.

That's all very nice, but you guys are trying to tell us our browsers
will download controls without asking. Mine does not. I know that
they can be configured as insecure as you like, but that still does
not change the fact that there are "regulars with good reputations"
who really are spreading fear and ignorance.

The potential risks associated with running a trojan are quite severe,
and downloading and running ActiveX controls is not something to be
taken lightly. Despite that, it does no one a service to go shouting
that the sky is falling.

When people spread false warnings, what it means is that people will
tend to disregard the real warnings. People should be warned to set
their browsers up securely (I believe the default isn't too shabby).
People should also be warned that downloading programs is something to
be taken seriously. They should also be warned if (when) there are
any known maliceous controls.

Ideally, we should put aside our petty "my OS is better" or "vendor so
and so is evil" sort of rubbish when it comes to trying to make the
net a more secure place for people to work and play.

Mike Jagdis

unread,
Dec 2, 1996, 3:00:00 AM12/2/96
to

David LeBlanc said

>When people spread false warnings, what it means is that people will
>tend to disregard the real warnings. People should be warned to set
>their browsers up securely (I believe the default isn't too shabby).
>People should also be warned that downloading programs is something to
>be taken seriously. They should also be warned if (when) there are
>any known maliceous controls.

Anyone who thinks they can deploy browsers throughout their Internet
connected organisation and rely on the users to make on the spot
risk assessments of whether to click ok or not is living in cloud
cuckoo land. Companies already spend serious money trying to prevent
virus attacks - and cleaning up after them. There are real, and
very significant, risks here.

Mike

--
.----------------------------------------------------------------------.
| Mike Jagdis | Internet: mailto:mi...@roan.co.uk |
| Roan Technology Ltd. | |
| 54A Peach Street, Wokingham | Telephone: +44 118 989 0403 |


David LeBlanc

unread,
Dec 2, 1996, 3:00:00 AM12/2/96
to

Mike Jagdis <mi...@roan.co.uk> wrote:

>David LeBlanc said

>>When people spread false warnings, what it means is that people will
>>tend to disregard the real warnings. People should be warned to set
>>their browsers up securely (I believe the default isn't too shabby).
>>People should also be warned that downloading programs is something to
>>be taken seriously. They should also be warned if (when) there are
>>any known maliceous controls.

>Anyone who thinks they can deploy browsers throughout their Internet
>connected organisation and rely on the users to make on the spot
>risk assessments of whether to click ok or not is living in cloud
>cuckoo land. Companies already spend serious money trying to prevent
>virus attacks - and cleaning up after them. There are real, and
>very significant, risks here.

If that's appropriate, then I'd configure them all not to download any
active content, or only allow active content from internal sites. If
you're running NT, you can keep them from changing that as well.

david parsons

unread,
Dec 2, 1996, 3:00:00 AM12/2/96
to

In article <57qq00$j...@camel2.mindspring.com>,
David LeBlanc <dleb...@mindspring.com> wrote:

>When people spread false warnings, what it means is that people will
>tend to disregard the real warnings. People should be warned to set
>their browsers up securely (I believe the default isn't too shabby).
>People should also be warned that downloading programs is something to
>be taken seriously. They should also be warned if (when) there are
>any known maliceous controls.

People won't pay attention. It's a lot simpler to just lock down the
gateway to the outside world so those things won't get in. If you've
got a nontrivial organization, betting against some minion(*) forgetting
to turn off all the KICK ME buttons is a sure way to lose money fast.


(* or some executive, but that doesn't matter quite so much for the
company.)

____
david parsons \bi/ o...@pell.chi.il.us
\/

Vikas Agnihotri

unread,
Dec 2, 1996, 3:00:00 AM12/2/96
to

On Mon, 02 Dec 1996 12:34:42 GMT, David LeBlanc <dleb...@mindspring.com> wrote:
[<-->] Mike Jagdis <mi...@roan.co.uk> wrote:
[<-->]
[<-->] >David LeBlanc said
[<-->]
[<-->] If that's appropriate, then I'd configure them all not to download any
[<-->] active content, or only allow active content from internal sites. If
[<-->] you're running NT, you can keep them from changing that as well.

IMHO, these kind of tactics will defeat the whole purpose of the WWW/Internet/
Intranet, etc. What is the point of having a advanced technology if you want
to throttle it down and not let it perform to its full potential?
The solution is for MS to work on evolving Active-X and Sun on Java to
make them more secure languages/environments so that no-matter what
your browser/settings, no HTML, however cleverly written can wreak havoc
on the local computer. Hmmmm... too idealistic, huh? Oh well..

--Vikas


Andrew Harrison

unread,
Dec 3, 1996, 3:00:00 AM12/3/96
to

Intentional.

It's a con and trolls work underground doing unspeakable
things.

Though my subconscious may well be fooling me.

Regards

Andrew Harrison

Tony Langdon

unread,
Dec 3, 1996, 3:00:00 AM12/3/96
to

It's 03 Dec 96 06:26:47,
We'll return to mi...@roan.co.uk and All's
discussion of Is ActiveX Microsoft's undoing?

>People should also be warned that downloading programs is something to
>be taken seriously. They should also be warned if (when) there are
>any known maliceous controls.

mi> Anyone who thinks they can deploy browsers throughout their Internet
mi> connected organisation and rely on the users to make on the spot
mi> risk assessments of whether to click ok or not is living in cloud
mi> cuckoo land. Companies already spend serious money trying to prevent
mi> virus attacks - and cleaning up after them. There are real, and
mi> very significant, risks here.

Indeed, and I have heard (so far) 2 reports of suspicious damage caused
to peoples' systems while accessing the Web. From the description I've
read, it appears to be some form of Trojan on (a) specific site(s). At
this stage, the reports are what I would call unconfirmed, though one of
the people affected is someone I correspond regularly with, and I don't
think they'd start up another urban legend a la "Good Times". I am
trying to find out the suspicious URL's so I can examine them more
closely.

... I doubled my hard disk by a factor of two
--
|Fidonet: Tony Langdon 3:632/367.2
|Internet: tl...@freeway.apana.org.au
|
| Standard disclaimer: The views of this user are strictly his own.


Andrew Harrison

unread,
Dec 5, 1996, 3:00:00 AM12/5/96
to

Despite your protestations users typically ignore warnings or override
them.

Most corporations have stringent regulations about using shareware
or applications that have not been virus checked. Despite this
they get infected either because users ignore these regulations
and do not follow the proper procedure. In many cases users have
trusted the source of the software and therefore have not performed
adequate checks.

Sounds spookily like ActiveX.

> When people spread false warnings, what it means is that people will
> tend to disregard the real warnings. People should be warned to set
> their browsers up securely (I believe the default isn't too shabby).

> People should also be warned that downloading programs is something to
> be taken seriously. They should also be warned if (when) there are
> any known maliceous controls.
>

> Ideally, we should put aside our petty "my OS is better" or "vendor so
> and so is evil" sort of rubbish when it comes to trying to make the
> net a more secure place for people to work and play.
>

It is not that I have any particular dislike of MS or their products.
What I do dislike is people advocating using technologies for
things that they were never designed to do. For example ActiveX as a
secure method for distributing components or Java as a language for
delivering high performance numerical computing.

The problem with ActiveX is that it opens up the possibility for
componenent based solutions, this in turn opens up new methods for
distributing these components for example by selling and distributing
components over the Internet using micro charging.

If this happens then the small number of ActiveX components in use
will increase to a flood, with ActiveX's underlying lack of security
what is currently an academic discussion on an advocacy group will
become something much more serious.

Anyone who understands the dynamics and setup of the Internet will
also realise that the ActiveX protagonists defense that anyone
missusing Verising signatures will be caught and made to experience
the full weight of the Law is in parctice very naive.

It stems from a quaint faith in the remedy of going
to Law and neatly ducks any responsibility you may have for
your own actions.

P.S This is not my view about the difficulty of traceing and
punishing people who missbehave on the Internet. The LAW Society
in the UK are one of the sponsors of a seminar in London this
week which addresses exactly this problem.

Regards

Andrew Harrison
Senior Constultant SunUK

Eugene O'Neil

unread,
Dec 6, 1996, 3:00:00 AM12/6/96
to

In article <329e7bc0...@news.uq.edu.au>, j.mcp...@central1.library.uq.oz.au (James C. McPherson) wrote:
>On Wed, 27 Nov 1996 19:17:40 GMT, eug...@cs.umb.edu (Eugene O'Neil)
>wrote:
>
>[snip]
>>I tried downloading that URL, and this is the message Explorer gave me:
>>
>> This page contains active content that is not verifiably safe to
>> display. To protect your computer, this content will not be
>> displayed.
>>
>> Choose Help to find out how you can change your safety settings
>> so that you can view potentially unsafe content.
>>
>> [OK] [Help]
>>
>>I clicked OK, the dialog dissapeared, and now I'm writing this message. It
>>didn't load the ActiveX control without my knowledge, and it certianly didn't
>>reboot my machine, as you claimed it would. Please refrain from spreading such
>
>>misinformation in the future. By praying apon the fear, ignorance and doubt of
>
>>the uninformed masses, you make yourself no better than the worst Microsoft
>>advocate.
>
>
>You must have missed the earlier postings saying that Verisign
>demanded that the signature be removed. Once it was removed, MSIE
>would obviously not be able to disregard the security factors __unless
>you instructed it to in your preferences settings__.
>
>You just came in a little late to the discussion, so please don't put
>your foot in your mouth by accusing regulars with good reputations of
>spreading fear and ignorance when you haven't got the whole story.

The post I responded to claimed that the signiture was still valid, despite
the protests of verisign. They also claimed that Explorer would load it
without asking my permission.

I tested the second statement empirically, found it to be false, and reported
this to the net. Now you tell me that it was common knowledge that the first
statement was also wrong... and I'm the one who has a foot in my mouth? I don't
follow you.

The simple fact is, Explorer won't load a control without your permission unless
you TELL it to load controls without your permission: and if you do that, you
obviously deserve whatever you get. Anyone who leads people to believe otherwise
is praying apon people's fear, ignorance, and doubt, no matter how "good" their
reputation is.

-Eugene

Nathan Hand

unread,
Dec 7, 1996, 3:00:00 AM12/7/96
to

Eugene O'Neil (eug...@cs.umb.edu) wrote:

: In article <329AF8...@canada.sun.com>, David Collier-Brown <dav...@canada.sun.com> wrote:
: > However, I hacen't seen the real problem discussed
: >thus far: the active-x application with be run **WITHOUT QUESTIONING THE
: >USER** if it has a verisign certificate.
: > The example exploder at
: >http://simson.vineyard.net/activex/Exploder.ocx was distributed
: >with a valid verisign certificate, on the grounds that it was a
: >non-malicious demonstration of a security problem...

: I tried downloading that URL, and this is the message Explorer gave me:

: This page contains active content that is not verifiably safe to
: display. To protect your computer, this content will not be
: displayed.

: Choose Help to find out how you can change your safety settings
: so that you can view potentially unsafe content.

: [OK] [Help]

: I clicked OK, the dialog dissapeared, and now I'm writing this message. It
: didn't load the ActiveX control without my knowledge, and it certianly didn't
: reboot my machine, as you claimed it would. Please refrain from spreading such
: misinformation in the future. By praying apon the fear, ignorance and doubt of
: the uninformed masses, you make yourself no better than the worst Microsoft
: advocate.

Verisign spat the dummy and made the exploder author remove the
authentication. However several Windows 95 machines were rebooted
before Verisign caught on. Fortunately the point was proven that
the signing security scheme is ineffective and shortsighted.

Hmmm... much like ActiveX. Oh I'm sorry, my opinion doesn't count
because I'm inflicted with "Microsoft hatred". Hehehe.

--
This newsgroups are forums of intellectual debate and counter arguements
[seen on a microsoft advocacy group... proof of garbage in, garbage out]

Andrew J. Templin

unread,
Dec 8, 1996, 3:00:00 AM12/8/96
to

Eugene O'Neil (eug...@cs.umb.edu) wrote:

> The simple fact is, Explorer won't load a control without your permission
> unless you TELL it to load controls without your permission: and if you do
> that, you obviously deserve whatever you get. Anyone who leads people to
> believe otherwise is praying apon people's fear, ignorance, and doubt, no
> matter how "good" their reputation is.


So, Eugene:

Explorer asks you about ALL ActiveX controls? Even if signed by Verisign?

And this is the default for Explorer? [1]

Is this what you are saying?

Anxiously awaiting your reply...

Andrew

[1] Yeah, I know all about Netscape's defaults. Don't get me started.

--
Andrew J. Templin
Confused Programmer (TM) / Recovering Sysadmin
nos...@wwa.com

David Hopwood

unread,
Dec 9, 1996, 3:00:00 AM12/9/96
to

In message <E20Ip...@world.std.com>

eug...@cs.umb.edu (Eugene O'Neil) writes:

> The simple fact is, Explorer won't load a control without your
permission unless
> you TELL it to load controls without your permission: and if you do
that, you
> obviously deserve whatever you get.

It's not anything like that simple. Users will treat the security dialog as
asking 'Do you trust this vendor to have good intentions?'. What it should be
asking is 'Do you trust this vendor never to make exploitable mistakes?'

The _never_ is an important point. If a control has an exploitable bug, there
is no easy way to revoke its signature. The vendor can't even ask Verisign to
do that, since the browser never connects to Verisign. So an attacker
can choose
exactly which version of a control to attack, even if it is no longer on the
vendor's web pages.

Keeping track of bugs in the current versions of a limited amount of code
(browsers, interpreters, and operating systems) is hard enough - now try doing
that for every version of every ActiveX control signed by a
"Commercial Software
Publisher". Most of that code will be written in C or C++ - languages
which never
had the ability to write trustworthy code as a design criterion.

IMHO, if ActiveX becomes a widely used standard, it will throw away any chance
the Internet has of becoming adequately secure.

David Hopwood
david....@lmh.ox.ac.uk, hop...@zetnet.co.uk

Larry Kilgallen

unread,
Dec 10, 1996, 3:00:00 AM12/10/96
to

In article <199612092...@zetnet.co.uk>, David Hopwood <hop...@zetnet.co.uk> writes:

> IMHO, if ActiveX becomes a widely used standard, it will throw away any chance
> the Internet has of becoming adequately secure.

In my opinion, the Internet lost that chance when it was based on the
TCP/IP protocol stack which by default allows connections to be set
up without either authentication or intervention of the system manager.

Larry Kilgallen

Dr.Dimitri Vulis KOTM

unread,
Dec 10, 1996, 3:00:00 AM12/10/96
to

kilg...@eisner.decus.org (Larry Kilgallen) writes:

> In article <199612092...@zetnet.co.uk>, David Hopwood <hopwood@zetnet.


>
> > IMHO, if ActiveX becomes a widely used standard, it will throw away any cha

> > the Internet has of becoming adequately secure.
>
> In my opinion, the Internet lost that chance when it was based on the
> TCP/IP protocol stack which by default allows connections to be set
> up without either authentication or intervention of the system manager.

Hopefully IPv6 will rectify this.

---

<a href="mailto:d...@bwalk.dm.com">Dr.Dimitri Vulis KOTM</a>
Brighton Beach Boardwalk BBS, Forest Hills, N.Y.: +1-718-261-2013, 14.4Kbps

Eugene O'Neil

unread,
Dec 10, 1996, 3:00:00 AM12/10/96
to

In article <32A6CA...@uk.sun.com>, Andrew Harrison <andrew....@uk.sun.com> wrote:

>> The potential risks associated with running a trojan are quite severe,
>> and downloading and running ActiveX controls is not something to be
>> taken lightly. Despite that, it does no one a service to go shouting
>> that the sky is falling.
>>
>Despite your protestations users typically ignore warnings or override
>them.
>
>Most corporations have stringent regulations about using shareware
>or applications that have not been virus checked. Despite this
>they get infected either because users ignore these regulations
>and do not follow the proper procedure. In many cases users have
>trusted the source of the software and therefore have not performed
>adequate checks.

Using your own logic... what can you do about it? Tell them not to use
Internet Explorer? What is to stop them from ignoring THAT warning as well?
They can download and install Explorer in about an hour, then download
ActiveX controls to their hearts content. Or they can just download normal
binary executables from god knows where, and execute them.

If you can't trust your users to use ActiveX responsibly, you just can't trust
them with a computer.

>Anyone who understands the dynamics and setup of the Internet will
>also realise that the ActiveX protagonists defense that anyone
>missusing Verising signatures will be caught and made to experience
>the full weight of the Law is in parctice very naive.

Is it nieve to think that anyone caught selling malicious shrink-wrapped
software will be punished? That is also a distribution model based on fear and
trust, and it has worked pretty well so far.

-Eugene

Larry Kilgallen

unread,
Dec 10, 1996, 3:00:00 AM12/10/96
to

In article <6ykqyD1...@bwalk.dm.com>, d...@bwalk.dm.com (Dr.Dimitri Vulis KOTM) writes:
> kilg...@eisner.decus.org (Larry Kilgallen) writes:
>
>> In article <199612092...@zetnet.co.uk>, David Hopwood <hopwood@zetnet.
>>
>> > IMHO, if ActiveX becomes a widely used standard, it will throw away any cha
>> > the Internet has of becoming adequately secure.
>>
>> In my opinion, the Internet lost that chance when it was based on the
>> TCP/IP protocol stack which by default allows connections to be set
>> up without either authentication or intervention of the system manager.
>
> Hopefully IPv6 will rectify this.

I do not know the details, but with the emphasis on compatibility I
would estimate secure defaulting would not be included. Either that
or everyone accustomed to the old way of doing business would just
turn off the security in order to have existing applications work.

Larry Kilgallen

William Hugh Murray

unread,
Dec 11, 1996, 3:00:00 AM12/11/96
to

Dr.Dimitri Vulis KOTM wrote:
>
> kilg...@eisner.decus.org (Larry Kilgallen) writes:
>
> > In article <199612092...@zetnet.co.uk>, David Hopwood <hopwood@zetnet.
> >
> > > IMHO, if ActiveX becomes a widely used standard, it will throw away any cha
> > > the Internet has of becoming adequately secure.
> >
> > In my opinion, the Internet lost that chance when it was based on the
> > TCP/IP protocol stack which by default allows connections to be set
> > up without either authentication or intervention of the system manager.
>
> Hopefully IPv6 will rectify this.
>
> ---
>
> <a href="mailto:d...@bwalk.dm.com">Dr.Dimitri Vulis KOTM</a>
> Brighton Beach Boardwalk BBS, Forest Hills, N.Y.: +1-718-261-2013, 14.4Kbps

It is comforting to know that are only two fundamental vulnerabilities
in the internet. They are nodes (e.g., Microsoft systems, Unix, MS
Word, BASIC, Jave, ActiveX, applications) and links (IP). Fixing one
without fixing the other will not improve the results.

Insecure examples of both these will persist for a decade or more.
Currently we are losing the battle. That is, we are introducing
insecure nodes and links faster than we are introducing secure ones.

The implication is that we may never be able to rely upon the transport
layer for any useful degree of security. Therefore, at least in the
meantime, we must secure applications end-to-end. Even then we will
probably need compensating or complementary controls.

Do not let this worry you too much. We have gotten along very well with
paper for several hundred years. Surely we can better than that.

D. J. Bernstein

unread,
Dec 12, 1996, 3:00:00 AM12/12/96
to

Larry Kilgallen <kilg...@eisner.decus.org> wrote:
> TCP/IP protocol stack which by default allows connections to be set
> up without either authentication or intervention of the system manager.

Nonsense. A machine won't make a TCP/IP connection if the system manager
doesn't turn it on. That's intervention.

Perhaps you meant to say that TCP/IP doesn't communicate tags from your
favorite intra-machine identification system. So what? TCP is a
host-to-host transport protocol. If you want something more, put it on
top of TCP.

---Dan
Put an end to unauthorized mail relaying. http://pobox.com/~djb/qmail.html

Stefek Zaba

unread,
Dec 12, 1996, 3:00:00 AM12/12/96
to

In comp.security.misc, Larry Kilgallen (kilg...@eisner.decus.org) wrote:

> I do not know the details, but with the emphasis on compatibility I
> would estimate secure defaulting would not be included. Either that
> or everyone accustomed to the old way of doing business would just
> turn off the security in order to have existing applications work.

Bzzt. Next contestant please. IPSEC (IP-level security) is *mandatory*
for IPv6 implementations, optional for IPv4. Whether individual (ab)users
turn it on or off on their machines is up to them, though they run the
risk of not having their packets forwarded if they don't run at least
AH (authentication). That would be a simple policy for ISPs to enforce,
which would kick IP-spoofing and TCP session-hijacking attacks into touch.
Roll on the brave new world.

IPSEC details at (among others)
ftp://ftp.isi.edu/internet-drafts/draft-ietf-ipsec*; for an overview see
this month's Byte.

Cheers, Stefek
> Larry Kilgallen

Larry Kilgallen

unread,
Dec 12, 1996, 3:00:00 AM12/12/96
to

In article <E29yL...@hplb.hpl.hp.com>, sj...@hplb.hpl.hp.com (Stefek Zaba) writes:
> In comp.security.misc, Larry Kilgallen (kilg...@eisner.decus.org) wrote:
>
>> I do not know the details, but with the emphasis on compatibility I
>> would estimate secure defaulting would not be included. Either that
>> or everyone accustomed to the old way of doing business would just
>> turn off the security in order to have existing applications work.
>
> Bzzt. Next contestant please. IPSEC (IP-level security) is *mandatory*
> for IPv6 implementations, optional for IPv4. Whether individual (ab)users
> turn it on or off on their machines is up to them, though they run the
> risk of not having their packets forwarded if they don't run at least
> AH (authentication). That would be a simple policy for ISPs to enforce,
> which would kick IP-spoofing and TCP session-hijacking attacks into touch.
> Roll on the brave new world.

Given your statement that secure defaulting is included, they I think
my alternative will hold sway for many years -- those offering ports
for connection will continue to do so without demanding the identity
of the originating user for many years in order to be compatible with
the largest number of other sites (and frankly, to avoid the effort
of handling trouble calls).

Larry Kilgallen

Larry Kilgallen

unread,
Dec 12, 1996, 3:00:00 AM12/12/96
to

In article <1996Dec1200...@koobera.math.uic.edu>, d...@koobera.math.uic.edu (D. J. Bernstein) writes:
> Larry Kilgallen <kilg...@eisner.decus.org> wrote:
>> TCP/IP protocol stack which by default allows connections to be set
>> up without either authentication or intervention of the system manager.
>
> Nonsense. A machine won't make a TCP/IP connection if the system manager
> doesn't turn it on. That's intervention.
>
> Perhaps you meant to say that TCP/IP doesn't communicate tags from your
> favorite intra-machine identification system. So what? TCP is a
> host-to-host transport protocol. If you want something more, put it on
> top of TCP.

TCP/IP implementations I have seen do not provide an option for the
system administrator to restrict operation to those client protocols
which have adequate authentication. Of course they can make such
restrictions for a range of low port numbers, but generally higher
port numbers are available to any user.

This fundamental insecurity is the reason for the development of
"firewalls", a whole sub-industry devoted to feeding the belief
of every company that none of the bad guys work for _them_.

Larry Kilgallen

Larry Kilgallen

unread,
Dec 12, 1996, 3:00:00 AM12/12/96
to

In article <1996Dec1200...@koobera.math.uic.edu>, d...@koobera.math.uic.edu (D. J. Bernstein) writes:

> Perhaps you meant to say that TCP/IP doesn't communicate tags from your
> favorite intra-machine identification system.

No, I mean that it does not _require_ authentication of the
originating _user_ before allowing a connection.

Yes, for anything designed in current times, one-way transmission
of a reusable password is totally inadequate. A cryptographic
handshake is a requirement, allowing for mutual authentication
if that is an application requirement.

Yes, delegation of authority to machines operating unattended is a
requirement, but those machines are still operating on behalf of a
human user (who in turn may be acting on behalf of an institution).
Several cryptographic delegation protocols have been designed by
various parties.

Larry Kilgallen

Frithiof Jensen

unread,
Dec 13, 1996, 3:00:00 AM12/13/96
to

In article <E27tA...@world.std.com>, eug...@cs.umb.edu (Eugene O'Neil) says:
>
>If you can't trust your users to use ActiveX responsibly, you just can't trust
>them with a computer.
>

So - I will just write a memo to my secretary that she must check the binary
of any ActiveX control for malicious intent!?

Most computer users have not got a clue how *anything* works internally -
that is the way it should be BTW. I think it is a bit rich to force people to
download perhaps hundreds of unknown executables per day and even
expect them to check each one before running it.

>Is it nieve to think that anyone caught selling malicious shrink-wrapped
>software will be punished?

Yep - countless programs have lost & corrupted data because they were
broken straight out of the box. Nothing Happens.

Besides - exactly how are you going to enforce wich countrys law on the
Internet? I Denmark f.ex. I can upload any kind of pornography - except
child pornography - with impunity because it is legal there. That really
pisses off the UK, not to mention Malaysia, Singapore etc. but...
What can they do about it?

If someone cracked a verified ActiveX control and stuck it on their Web page
in f.ex. Libya will the USA launch the F15's again?

The Internet is very much like the middle ages when it comes to Law & Order:
You build you fortress high and strong enough to keep the robbers out and
don't let in any strangers.

The real problem with ActiveX is that Microsoft will abandon it as soon as enough
competitors have started to ship it in their products - but that is not new at all.


===============================================================================
The above article is the personal view of the poster and should not be
considered as an official comment from the JET Joint Undertaking
===============================================================================

da...@xs4all.nl

unread,
Dec 13, 1996, 3:00:00 AM12/13/96
to

In <1996Dec12.075026.1@eisner> kilg...@eisner.decus.org (Larry Kilgallen) writes:

>TCP/IP implementations I have seen do not provide an option for the
>system administrator to restrict operation to those client protocols
>which have adequate authentication. Of course they can make such
>restrictions for a range of low port numbers, but generally higher
>port numbers are available to any user.

These restrictions can be extended to all port numbers, without
violating any part of the current IP.

>This fundamental insecurity is the reason for the development of
>"firewalls", a whole sub-industry devoted to feeding the belief
>of every company that none of the bad guys work for _them_.

Similarly, your proposal requires that none of the bad guys are
system administrators.
--
Richard Braakman

Larry Kilgallen

unread,
Dec 13, 1996, 3:00:00 AM12/13/96
to

In article <58s51k$f...@news.xs4all.nl>, da...@xs4all.nl () writes:
> In <1996Dec12.075026.1@eisner> kilg...@eisner.decus.org (Larry Kilgallen) writes:
>
>>TCP/IP implementations I have seen do not provide an option for the
>>system administrator to restrict operation to those client protocols
>>which have adequate authentication. Of course they can make such
>>restrictions for a range of low port numbers, but generally higher
>>port numbers are available to any user.
>
> These restrictions can be extended to all port numbers, without
> violating any part of the current IP.

Are there significant segments of the population who have chosen
to secure their systems in this fashion ? I am under the impression
that typical applications for TCP/IP are not designed to work in an
environment thus secured.

>>This fundamental insecurity is the reason for the development of
>>"firewalls", a whole sub-industry devoted to feeding the belief
>>of every company that none of the bad guys work for _them_.
>
> Similarly, your proposal requires that none of the bad guys are
> system administrators.

I don't recall making a proposal, but by definition a system administrator
has control of a machine and thus (given adequate skills) can read input
buffers on the fly, etc. Some set of people in the world will be trusted,
and obviously trusting all system administrators is safer than trusting
all people, since the former is a proper subset of the latter...

...unless, of course, someone can prove that everyone who is _not_
a system administrator can always be trusted, in which case the risks
are equal :-)

Larry Kilgallen

Lee E. Brotzman

unread,
Dec 13, 1996, 3:00:00 AM12/13/96
to

On Tue, 10 Dec 96 14:50:40 EST, Dr.Dimitri Vulis KOTM <d...@bwalk.dm.com> wrote:
>kilg...@eisner.decus.org (Larry Kilgallen) writes:
>
>> In article <199612092...@zetnet.co.uk>, David Hopwood <hopwood@zetnet.
>>
>> > IMHO, if ActiveX becomes a widely used standard, it will throw away any cha
>> > the Internet has of becoming adequately secure.
>>
>> In my opinion, the Internet lost that chance when it was based on the
>> TCP/IP protocol stack which by default allows connections to be set
>> up without either authentication or intervention of the system manager.
>
>Hopefully IPv6 will rectify this.

But I don't see how IPv6 will rectify the fact that ActiveX controls can
exploit security "holes" (they aren't really holes, since ActiveX has no real
security controls in the first place).

The widely publicized "reboot" control was at least open about what it was
going to do. A more covert approach would be to sign a "cool" control that at
the same time quietly scans the disk for pertinent information and sends this
back to the attacker. Will Verisign personally check every signed control for
every network message? I don't think so. By the time the damage is done, I
would expect that the attacker has his/her information and is long gone.

It is a poor substitute to just say "well they got what they deserved". No
one deserves to be hacked, and one would hope that their software will help
them out in that regard at least to some extent.

--
-- Lee E. Brotzman E-mail: l...@vicon.net
-- Advanced Data Solutions Phone : 814-861-5028


da...@xs4all.nl

unread,
Dec 14, 1996, 3:00:00 AM12/14/96
to

[Followups set to comp.security.misc only]

In <1996Dec13.154749.1@eisner> kilg...@eisner.decus.org (Larry Kilgallen) writes:
>In article <58s51k$f...@news.xs4all.nl>, da...@xs4all.nl () writes:
>> In <1996Dec12.075026.1@eisner> kilg...@eisner.decus.org (Larry Kilgallen) writes:
>>
>> These restrictions can be extended to all port numbers, without
>> violating any part of the current IP.

>Are there significant segments of the population who have chosen
>to secure their systems in this fashion ? I am under the impression
>that typical applications for TCP/IP are not designed to work in an
>environment thus secured.

Still, the protocol is not at fault. More importantly, the protocol
does not stand in the way of more secure implementations and/or
applications for it.

I also think that there _are_ such "significant segments", namely
all users who are connected through a firewall. Many implementations
of TCP-based protocols seem to need adjustment in order to function
well in such an environment, but the adjustments are typically minor
and do not involve fundamental problems except in the case of FTP.

While there are differences between a firewall and what you described
(what should I call it, if it's not a proposal?), the effects on
applications seem similar.

[Point about system adminstrators and trust conceded.]

--
Richard Braakman

William Hugh Murray

unread,
Dec 14, 1996, 3:00:00 AM12/14/96
to

Larry Kilgallen wrote:
>
> This fundamental insecurity is the reason for the development of
> "firewalls", a whole sub-industry devoted to feeding the belief
> of every company that none of the bad guys work for _them_.
>
> Larry Kilgallen


I assume that you overstate for a purpose. Nonetheless it is
appropriate for network operators to understand that they should use
firewalls head-to-head and head-to-tail. They should maintain sub-net
identity. They should use secure-IP behind the firewall.

Of course, this is counter to the tradition and intent of the internet.
The internet has traditionally been a flat mesh topology in which single
points of connection are seen as antisocial. They limit both
connectivity and band-width.

On the other hand, security was not a concern or even a consideration in
the early internet. Making it more secure is essential to its continued
utility. That will not be free.

William Hugh Murray

unread,
Dec 14, 1996, 3:00:00 AM12/14/96
to

Larry Kilgallen wrote:
>
> In article <58s51k$f...@news.xs4all.nl>, da...@xs4all.nl () writes:
> > In <1996Dec12.075026.1@eisner> kilg...@eisner.decus.org (Larry Kilgallen) writes:
> >
> >>TCP/IP implementations I have seen do not provide an option for the
> >>system administrator to restrict operation to those client protocols
> >>which have adequate authentication. Of course they can make such
> >>restrictions for a range of low port numbers, but generally higher
> >>port numbers are available to any user.
> >
> > These restrictions can be extended to all port numbers, without
> > violating any part of the current IP.
>
> Are there significant segments of the population who have chosen
> to secure their systems in this fashion ? I am under the impression
> that typical applications for TCP/IP are not designed to work in an
> environment thus secured.

Most certainly not. What are you, some kind of Fascist? What do you
want, security? The internet is about connectivity, band-width, and,
most importantly, freedom.

David LeBlanc

unread,
Dec 14, 1996, 3:00:00 AM12/14/96
to

vi...@insight.att.com (Vikas Agnihotri) wrote:

>On Mon, 02 Dec 1996 12:34:42 GMT, David LeBlanc <dleb...@mindspring.com> wrote:

>[<-->] If that's appropriate, then I'd configure them all not to download any
>[<-->] active content, or only allow active content from internal sites. If
>[<-->] you're running NT, you can keep them from changing that as well.

>IMHO, these kind of tactics will defeat the whole purpose of the WWW/Internet/
>Intranet, etc. What is the point of having a advanced technology if you want
>to throttle it down and not let it perform to its full potential?

I don't see anything wrong with it - you don't neccesarily need to
allow outside executables to come in to take full advantage of the
same technology internally. If I really wanted to ride herd on the
users, I'd set them all up not to be able to download any controls,
but provide the ones I'd put my blessing on. Same way I would with
executables coming in from floppies.

> The solution is for MS to work on evolving Active-X and Sun on Java to
>make them more secure languages/environments so that no-matter what
>your browser/settings, no HTML, however cleverly written can wreak havoc
>on the local computer. Hmmmm... too idealistic, huh? Oh well..

It would be nice, but yes, very idealistic. Not a bad vision to
strive for, however.

David LeBlanc |Why would you want to have your desktop user,
dleb...@mindspring.com |your mere mortals, messing around with a 32-bit
|minicomputer-class computing environment?
|Scott McNealy


D. J. Bernstein

unread,
Dec 14, 1996, 3:00:00 AM12/14/96
to

Larry Kilgallen <kilg...@eisner.decus.org> wrote:
> No, I mean that it does not _require_ authentication of the
> originating _user_ before allowing a connection.

What do you mean by ``authentication of the user''? You're referring to
a tag from your favorite intra-machine identification system, right?

What do you mean by ``does not require''? You mean that the client
doesn't have to transmit tags as part of the protocol, right?

In other words, as I said, TCP/IP doesn't communicate tags from your
favorite intra-machine identification system.

But you're denying that this is what you mean. So what _did_ you mean?

If you're going to claim that the structure of a low-level protocol
prevents the Internet from ever being ``adequately secure,'' you'll have
to do a better job of explaining yourself.

Larry Kilgallen

unread,
Dec 14, 1996, 3:00:00 AM12/14/96
to

In article <1996Dec1417...@koobera.math.uic.edu>, d...@koobera.math.uic.edu (D. J. Bernstein) writes:
> Larry Kilgallen <kilg...@eisner.decus.org> wrote:
>> No, I mean that it does not _require_ authentication of the
>> originating _user_ before allowing a connection.
>
> What do you mean by ``authentication of the user''? You're referring to
> a tag from your favorite intra-machine identification system, right?

My bias is toward a public key signature from the user seeking access,
authenticated through a hierarchy common to that user and the machine
to which access is being granted (or denied). Replay defense can be
via challenge-response or timestamp (or other robust methods which
might exist).

Others may prefer a different mechanism, and so long as it has as
much security for the authentication I have no complaint.

I would characterize inherent trust in some other node, as supported
by the Unix "r" protocols, as grossly inadequate for authentication,
even if authentication of that node was perfect.

> What do you mean by ``does not require''? You mean that the client
> doesn't have to transmit tags as part of the protocol, right?
>
> In other words, as I said, TCP/IP doesn't communicate tags from your
> favorite intra-machine identification system.

The buzz-phrase "tags from your favorite intra-machine identification
system" does not get any clearer with repetition.

> But you're denying that this is what you mean. So what _did_ you mean?

What I mean is _by_default_ the system administrator can be assured
that application-level data will not enter or leave the machine over
any connection until that connection has been authenticated as
discussed above. Although mutual authentication is a goal,
it does not add significant complexity to this problem space.

Obviously after the completion of authentication, there must be a
mechanism to defend against spurious packet insertion or modification,
but I am under the impression that IPV6 provides for this.

Larry Kilgallen

D. J. Bernstein

unread,
Dec 15, 1996, 3:00:00 AM12/15/96
to

Larry Kilgallen <kilg...@eisner.decus.org> wrote:
> My bias is toward a public key signature from the user seeking access,

Fine. Use your favorite encryption protocol on top of TCP/IP.

Of course, this would be tremendously wasteful for public information,
which (in case you haven't noticed) is the bulk of Internet traffic.

> What I mean is _by_default_ the system administrator can be assured
> that application-level data will not enter or leave the machine over
> any connection until that connection has been authenticated as
> discussed above.

With today's UNIX systems, you can set IPPORT_RESERVED to 65536, and
then impose whatever sort of religious fanaticism you want through
setuid programs.

What does this have to do with TCP/IP?

John Stevens

unread,
Dec 20, 1996, 3:00:00 AM12/20/96
to

In article <1996Dec14.160835.1@eisner>,

Larry Kilgallen <kilg...@eisner.decus.org> wrote:
>In article <1996Dec1417...@koobera.math.uic.edu>, d...@koobera.math.uic.edu (D. J. Bernstein) writes:
>> Larry Kilgallen <kilg...@eisner.decus.org> wrote:
>> But you're denying that this is what you mean. So what _did_ you mean?
>
>What I mean is _by_default_ the system administrator can be assured
>that application-level data will not enter or leave the machine over
>any connection until that connection has been authenticated as
>discussed above. Although mutual authentication is a goal,
>it does not add significant complexity to this problem space.

But this isn't (and *SHOULDN'T* be) a requirement for TCP/IP. This
is a function that should be added to a higher level of the protocol
stack.

>Obviously after the completion of authentication, there must be a
>mechanism to defend against spurious packet insertion or modification,
>but I am under the impression that IPV6 provides for this.

The kind of security you are talking about should *NOT* be forced
down into the lower levels of the protocol stack. The overhead
is high enough that it would be totally unacceptable to those
people who do not need/want it.

Don't forget, security is not an absolute requirement for every
user of TCP/IP.

John S.

John Stevens

unread,
Dec 20, 1996, 3:00:00 AM12/20/96
to

In article <1996Dec1500...@koobera.math.uic.edu>,

D. J. Bernstein <d...@koobera.math.uic.edu> wrote:
>Larry Kilgallen <kilg...@eisner.decus.org> wrote:
>> My bias is toward a public key signature from the user seeking access,
>
>Fine. Use your favorite encryption protocol on top of TCP/IP.
>
>Of course, this would be tremendously wasteful for public information,
>which (in case you haven't noticed) is the bulk of Internet traffic.

My point exactly. Thank you for stating it so (much more!) clearly
than I did.

It seems that Larry is one of those types of business user who sees
his own needs and desires quite clearly. . . but does not seem to
even acknowledge the needs of other users. Not an uncommon
attitude among business types, really. And quite understandable.

>> What I mean is _by_default_ the system administrator can be assured
>> that application-level data will not enter or leave the machine over
>> any connection until that connection has been authenticated as
>> discussed above.
>

>With today's UNIX systems, you can set IPPORT_RESERVED to 65536, and
>then impose whatever sort of religious fanaticism you want through
>setuid programs.
>
>What does this have to do with TCP/IP?

Nada. Again, my point exactly. Perhaps a clear discussion on what
the protocol stack is all about would help, here. . .

However, in my opinion, the kind of stuff that Larry is talking about
belongs at a higher level in the stack, say (just spitballing here,
mind you) at the application level. . .

John S.

Larry Kilgallen

unread,
Dec 20, 1996, 3:00:00 AM12/20/96
to

In article <59eprg$q...@bamboo.verinet.com>, jste...@bamboo.verinet.com (John Stevens) writes:

> However, in my opinion, the kind of stuff that Larry is talking about
> belongs at a higher level in the stack, say (just spitballing here,
> mind you) at the application level. . .

So how would a system administrator prevent the average programmer
from making calls to a lower level bypassing the authentication
mechanism ?

Larry Kilgallen

William Hugh Murray

unread,
Dec 21, 1996, 3:00:00 AM12/21/96
to

Of course he cannot. Therefore, good practice says that multiple people
must be involved in the controls over a program that will be used by
multiple people and programmers should not be permitted to execute
programs of their own against other peoples data.

I realize that in many communities the discussion of such controls is
justification for Draconian punishment.

John Stevens

unread,
Dec 23, 1996, 3:00:00 AM12/23/96
to

In article <1996Dec20.164525.1@eisner>,

Larry Kilgallen <kilg...@eisner.decus.org> wrote:
>In article <59eprg$q...@bamboo.verinet.com>, jste...@bamboo.verinet.com (John Stevens) writes:
>
>> However, in my opinion, the kind of stuff that Larry is talking about
>> belongs at a higher level in the stack, say (just spitballing here,
>> mind you) at the application level. . .
>
>So how would a system administrator prevent the average programmer
>from making calls to a lower level bypassing the authentication
>mechanism ?

Why should he? The point is to provide security that can be by-
passed in those cases where it is not needed.

Hence the reason that the first 1K TCP/IP ports are usually protected,
while those above that range are not.

If you need authentication for a service, use it. If not, don't.

A service that exports public information does not need authentication.

John S.

Larry Kilgallen

unread,
Dec 24, 1996, 3:00:00 AM12/24/96
to

In article <59mrg5$2...@bamboo.verinet.com>, jste...@bamboo.verinet.com (John Stevens) writes:
> In article <1996Dec20.164525.1@eisner>,
> Larry Kilgallen <kilg...@eisner.decus.org> wrote:
>>In article <59eprg$q...@bamboo.verinet.com>, jste...@bamboo.verinet.com (John Stevens) writes:
>>
>>> However, in my opinion, the kind of stuff that Larry is talking about
>>> belongs at a higher level in the stack, say (just spitballing here,
>>> mind you) at the application level. . .
>>
>>So how would a system administrator prevent the average programmer
>>from making calls to a lower level bypassing the authentication
>>mechanism ?
>
> Why should he? The point is to provide security that can be by-
> passed in those cases where it is not needed.

But that decision must be made by someone with proper authority --
_not_ just any individual user.

> A service that exports public information does not need authentication.

But random users of a system are not necessarily empowered to determine
that something is "public".

Obviously none of these concerns can be addressed for unsecured systems
such as where end users are allowed physical access to the machine.

Larry Kilgallen

0 new messages