Security 101

by matt 9. January 2007 08:55

This just beggars belief. Acer appears to have sold computers with a pre-installed ActiveX control that allows any web site to run any executable on your machine with any command line arguments.

Now, I'm no security expert. But working for an internet bank you do pick a few things up. Probably by osmosis. So, I'm going to take a gamble here and state that I think this is a Really Bad Thing.

If this had been Joe Random Programmer posting some example code on his blog, then I could forgive them. A sternly worded comment could point out the error of their ways.

But a corporation has no excuse. Someone must have requested this feature, someone must have specced it, someone built it and someone tested it. And none of them noticed the glaringly large security hole?

And Slashdot ran this story on the same day they ran a story entitled "What Makes Software Development So Hard?". With news like this Acer thing, I reckon we need to make Software Development harder, and get a bit of old Darwinian magic in to fix this...

Tags:

Comments

Add comment


(Will show your Gravatar icon)

biuquote
  • Comment
  • Preview
Loading



About the author

Something about the author

Calendar

<<July 2010>>
MoTuWeThFrSaSu
2829301234
567891011
12131415161718
19202122232425
2627282930311
2345678

View posts in large calendar

RecentComments

Comment RSS

License

Creative Commons License
Except where otherwise noted, content on this site is by Matt Ellis and is licensed under a Creative Commons Attribution-Share Alike 3.0 Unported License.

©2010 Matt Ellis