Re: MS signed softwrare privileges

From: Steven M. Bellovin (smbat_private)
Date: Wed Feb 23 2000 - 17:15:09 PST

  • Next message: dies: "Open IP Directed Broadcast List..."

    In message <Pine.GSO.4.20.0002221939500.8993-100000at_private>, Dax
    Kelson writes:
    
    > However (playing devil's advocate), you've trusted Microsoft to silently
    > execute "any code" on your machine at least once before by installing
    > their closed-source operating system, and that is a massive amount of
    > unaudited code.
    
    Yes and no.  First, as Juan's original note pointed out, this creates risks
    from MS software you didn't install.  Second, and perhaps more important,
    anyone who has ever administered a production system knows that you *don't* do
    updates, even "harmless" ones, on production systems without testing *in your
    environment*, and you *never* do them at critical periods.  The ability for
    someone else to update my system is completely unacceptable, even without any
    security issues whatsoever.
    
    		--Steve Bellovin
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:36:58 PDT