Annoyances.org
Home » Windows Vista Discussion Forum » Message 1244388406 Search | Help | Home
  
Tip: Run a free scan for common Windows errors ad

re: Is this really a vulnerability or just hype? Results of my tests, check the facts.
Sunday, June 7, 2009 at 8:26 am
Windows Vista Annoyances Discussion Forum
Posted by lbecque (8 messages posted)


I agree with you Daniel that this is still a threat to the clueless who click yes to everything. But no OS, security package, firewall or anti-virus is going to make things completely safe for people who ignore these warnings and don't know what they are doing. Ignorance aside, if the option to prompt you is turned on with this FF extension then it is no worse than the many other ways in Windows that you can click on something and it warns you that you are about to run an application or do something that affects the security of your PC.

The fault that I see is that MS installed this extension with the prompt option turned off, which is easily changed but many people won't know to do this. Also, IE has the same problem and I don't see a way to correct this.


On Sunday, June 7, 2009 at 6:13 am, Daniel Weinreb wrote:
>Even if it asks the user first (which, as you point out, is NOT the default), it's
>still a security vulnerability in practice. Consider how this works for an ordinary
>person (my Dad). He is offered a useful service, if he clicks on some link. So
>he clicks. A message comes up saying "blah, blah, incomprehensible techie stuff,
>blah, blah: do you want to get the nice service that you asked for, or do you want
>to not get it?" Of course, he answers yes.
>
>(Same for the messages that Firefox pops up when there is a PKI problem such as an
>expired certificate, or a totally bogus certificate, or no certificate, at a server.)


Written in response to:
re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (Daniel Weinreb: Sunday, June 7, 2009 at 6:13 am)

Responses to this message:
*re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (Daniel Weinreb: Sunday, June 7, 2009 at 11:40 am)

All messages in this thread [show all]
-Is this really a vulnerability or just hype? Results of my tests, check the facts. (lbecque: Thu, Jun 4, 2009, 4:04 pm)
-Important update and workaround (lbecque: Thu, Jun 4, 2009, 7:09 pm)
-re: Important update and workaround (Steve: Thu, Jun 4, 2009, 7:50 pm)
-re: Important update and workaround (Charlie Hadden: Fri, Jun 5, 2009, 5:33 am)
*re: Important update and workaround (Steve: Fri, Jun 5, 2009, 6:20 am)
-re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (Daniel Weinreb: Sun, Jun 7, 2009, 6:13 am)
-re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (lbecque: Sun, Jun 7, 2009, 8:26 am)
-re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (Daniel Weinreb: Sun, Jun 7, 2009, 11:40 am)
*re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (Hayes Whitt: Wed, Jun 10, 2009, 10:32 pm)
-re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (dmex: Mon, Jun 8, 2009, 8:49 pm)
-re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (lbecque: Tue, Jun 9, 2009, 10:28 am)
*re: Is this really a vulnerability or just hype? Results of my tests, check the facts. (Hayes Whitt: Thu, Jun 11, 2009, 2:14 pm)
Return to the Windows Vista Discussion Forum


All content at Annoyances.org is Copyright ©1995-2012 Creative Elementtm All rights reserved.
Please do not plagiarize; redistributing these pages without permission is strictly prohibited.