Re: MacDefender / Safari issue



In article <SalmonEgg-0E7752.08340229052011@xxxxxxxxxxxxxxxxxxx>,
Salmon Egg <SalmonEgg@xxxxxxxxxxxxx> wrote:

Michelle Steiner <michelle@xxxxxxxxxxxx> wrote:

Alan Browne <alan.browne@xxxxxxxxxxxxxxxxxxxxx> wrote:

It still needs the user to click on 'OK' first though.

FWIW, most of the scaremongering about this malware has been propagated
by our friendly Intego. Not a source I have much trust in myself.

FWIW, I think it's probably time for Apple to remove the 'Open Safe
Files' option altogether now. I always found it annoying anyway, as I'd
sometimes be downloading a few updates at once, and keep having to
dismiss the dialogues. It's been disabled on my system for a long time
now.
I extracted this partial quote and I apologize if I have it wrong.

What prevents the malicious source from making OK or cancel from doing
things other than CANCEL? Moreover, OK is usually ambiguous. There are
too many well meaning sites with dialog boxes for which you do not know
exactly what will happen. They can range from you acknowledging that
you read the message to installations or other big deals.

One big complaint of mine about this Trojan horse is that CANCEL merely
gets you back to where you were and sets up an endless loop.


You basically cannot trust any of it. Back in the 1990s there was joke
Windows program floating around the net which demonstrated this quite
well. All the standard buttons did something other than what they said,
and that included the minimize, maximize and close icons too.

--
Paul Sture
.



Relevant Pages

  • Re: MacDefender / Safari issue
    ... by our friendly Intego. ... FWIW, I think it's probably time for Apple to remove the 'Open Safe ... What prevents the malicious source from making OK or cancel from doing ...
    (comp.sys.mac.system)
  • Re: MacDefender / Safari issue
    ... most of the scaremongering about this malware has been propagated ... FWIW, I think it's probably time for Apple to remove the 'Open Safe ... What prevents the malicious source from making OK or cancel from doing ...
    (comp.sys.mac.system)
  • Re: Generic SendInput samples?
    ... I can try the sample code on my vista and XP no-SP vm's tonight. ... SP1 or SP2? ... Fwiw, I just tried it on the mvps server, and it's not working ... .NET: It's About Trust! ...
    (microsoft.public.vb.general.discussion)
  • Re: How to Cancel a "non cancellable" Event
    ... You read way too much into my post while obviously not reading it carefully. ... FWIW: This component is *free* and I'm just trying to work around a ... Trying to cancel an event to *prevent* the ... primary and fundamental functionality of the component - BY DEFINITION - is ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Liberalism is a Disease That Leads to Extinction
    ... > This part I'll have to trust you on. ... FWIW, a Southern Democrat running ... Prev by Date: ...
    (rec.org.mensa)