Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > ger.ct > #283874

Re: Linux-Sicherheit verrottet?

Path csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From Hanno Foest <hurga-news2@tigress.com>
Newsgroups ger.ct
Subject Re: Linux-Sicherheit verrottet?
Date Fri, 18 Nov 2016 10:10:39 +0100
Lines 27
Message-ID <e97usgFpbfbU1@mid.individual.net> (permalink)
References <e96q9mFhhpnU1@mid.individual.net> <e9725fFj8qdU1@mid.individual.net> <e97l8cFn6k9U1@mid.individual.net>
Mime-Version 1.0
Content-Type text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding 8bit
X-Trace individual.net bVb14ip9otZrIx9R0c1/mwpPRAuV07Ajs23XBwZDE52zaeDXer
Cancel-Lock sha1:3j0gv8DVaqz14CX7vOP5NLta0vI=
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.4.0
In-Reply-To <e97l8cFn6k9U1@mid.individual.net>
Xref csiph.com ger.ct:283874

Show key headers only | View raw


Am 18.11.2016 07:26 schrieb Michael Bode:

>> Es ist nicht das Problem von Linux, daß Chrome automatisch Scheiße baut.
>> Chrome ist eine Applikation wie jede andere, und natürlich können
>> scheiss Applikationen Scheiße bauen.
>
> Wo ist das Problem, wenn Chrome eine Datei runterlädt, wenn man auf
> deren Download-Link klickt?

"It is not necessary to click on the button corresponding to the download."

"However, the default download behavior is one where you can point to 
e.g. Firefox’s solution as demonstrably superior: the user has to accept 
any random attacker supplied bytes before they are dumped to disk in a 
well known and indexable location, with an attacker supplied filename 
and extension."

> Ok wir verzichten also komplett auf Downloads aus dem Internet?

Unsinn. Die halbe Miete ist aber erst mal, daß alles, was potentiell 
schädliche Dateien auf den Rechner bringen könnte, eine bewußte 
Entscheidung voraussetzt.

Aber zugegeben: Was dieser "Tracker" da macht, ist auch bekloppt. 
"Metadata Extractor"? Wat? mlocate und gut ist.

Hanno

Back to ger.ct | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Linux-Sicherheit verrottet? Michael Bode <m.g.bode@web.de> - 2016-11-18 07:26 +0100
  Re: Linux-Sicherheit verrottet? Gerrit Heitsch <gerrit@laosinh.s.bawue.de> - 2016-11-18 07:41 +0100
    Re: Linux-Sicherheit verrottet? g.kuehne <kuehne123@front.ru> - 2016-11-21 15:58 +0100
  Re: Linux-Sicherheit verrottet? Hanno Foest <hurga-news2@tigress.com> - 2016-11-18 10:10 +0100
    Re: Linux-Sicherheit verrottet? Michael Bode <m.g.bode@web.de> - 2016-11-20 14:11 +0100
      Re: Linux-Sicherheit verrottet? "Dr. Joachim Neudert" <neudert@5sl.org> - 2016-11-20 14:51 +0100
        Re: Linux-Sicherheit verrottet? Michael Bode <m.g.bode@web.de> - 2016-11-20 15:36 +0100
      Re: Linux-Sicherheit verrottet? Hanno Foest <hurga-news2@tigress.com> - 2016-11-21 02:26 +0100
  Re: Linux-Sicherheit verrottet? Volker Neurath  <volker.neurath@gmx.de> - 2016-11-19 11:15 +0100

csiph-web