Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > ger.ct > #284142

Re: Linux-Sicherheit verrottet?

From Michael Bode <m.g.bode@web.de>
Newsgroups ger.ct
Subject Re: Linux-Sicherheit verrottet?
Date 2016-11-20 14:11 +0100
Message-ID <e9dlo6F6c4mU1@mid.individual.net> (permalink)
References <e96q9mFhhpnU1@mid.individual.net> <e9725fFj8qdU1@mid.individual.net> <e97l8cFn6k9U1@mid.individual.net> <e97usgFpbfbU1@mid.individual.net>

Show all headers | View raw


Am 18.11.2016 um 10:10 schrieb Hanno Foest:
> Am 18.11.2016 07:26 schrieb Michael Bode:
> 
>>> Es ist nicht das Problem von Linux, daß Chrome automatisch
>>> Scheiße baut. Chrome ist eine Applikation wie jede andere, und
>>> natürlich können scheiss Applikationen Scheiße bauen.
>> 
>> Wo ist das Problem, wenn Chrome eine Datei runterlädt, wenn man
>> auf deren Download-Link klickt?
> 
> "It is not necessary to click on the button corresponding to the
> download."
> 
> "However, the default download behavior is one where you can point
> to e.g. Firefox’s solution as demonstrably superior: the user has to
> accept any random attacker supplied bytes before they are dumped to
> disk in a well known and indexable location, with an attacker
> supplied filename and extension."


Ok, die "Website" war dann wohl folgende:

https://security.appspot.com/security/vmnc/vmnc_width_height_int_oflow.avi


Zum Thema

> Bei Chrome marodiert ein besoffener Haufen Schönwetterprogrammierer,
> die nichts als Windows kennen und daher ihr Gerümpel auch unter Linux
> wie bei Windows benehmen lassen müssen - ich sag nur
> Usability-Verbrechen wie schnappende Scrollbalken. Daß die auch ihre
> Sicherheitskatastrophen und automatischen in-den-Fuß-Schießer
> mitbringen ist naheliegend.

wäre vielleicht noch anzumerken, das das nicht jeder genauso formulieren
würde:

" Google Chrome’s culpability
Let’s be clear: Google Chrome is the most secure of the common general
purpose browsers out there. It has had more effort and money put into
sandboxing, code quality, mitigations, fuzzing and community security
involvement than the other browsers. This is all backed by a large,
strong security team -- the largest monetary investment of the major
browser vendors, which speaks volumes."

Back to ger.ct | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Linux-Sicherheit verrottet? Michael Bode <m.g.bode@web.de> - 2016-11-18 07:26 +0100
  Re: Linux-Sicherheit verrottet? Gerrit Heitsch <gerrit@laosinh.s.bawue.de> - 2016-11-18 07:41 +0100
    Re: Linux-Sicherheit verrottet? g.kuehne <kuehne123@front.ru> - 2016-11-21 15:58 +0100
  Re: Linux-Sicherheit verrottet? Hanno Foest <hurga-news2@tigress.com> - 2016-11-18 10:10 +0100
    Re: Linux-Sicherheit verrottet? Michael Bode <m.g.bode@web.de> - 2016-11-20 14:11 +0100
      Re: Linux-Sicherheit verrottet? "Dr. Joachim Neudert" <neudert@5sl.org> - 2016-11-20 14:51 +0100
        Re: Linux-Sicherheit verrottet? Michael Bode <m.g.bode@web.de> - 2016-11-20 15:36 +0100
      Re: Linux-Sicherheit verrottet? Hanno Foest <hurga-news2@tigress.com> - 2016-11-21 02:26 +0100
  Re: Linux-Sicherheit verrottet? Volker Neurath  <volker.neurath@gmx.de> - 2016-11-19 11:15 +0100

csiph-web