(Excerpts from a message dated 08-27-99, John Thompson to Murray Lesser)
Hi John--
JT>Looking at the new virus listing with each signature update, it
>appears almost all new viruses these days are not just
>Windows-specific, but MS-Word/Office macro viruses. That's good
>for those of us who don't use Windows or other MS products but I
>can't help but wonder how long it will be before somebody manages to
>exploit Java as a virus distribution/execution environment. Then
>OS/2 and even linux users would have something to worry about...
"Malicious Applets" in Java are not new. The book "Java Security"
(ISBN 0-471-17842-X) was written by McGraw and Felten in 1997 (Felten
was the Princeton programming expert who testified for the Feds in the
Microsoft trial). Most of the malicious applets reported in that book
have been blocked by later versions of Java and by later browsers, but
new ones keep cropping up. One of the inherent problems with Java
Applet security is that the browser is responsible for implementing much
of the available security rules, and a browser bug can be exploited to
let the wrong things come through. (This is not a problem with Java
application programs that are not run from Web sites: if you ignore the
usual dangers associated with running any application written in any
language when you don't know where it came from!) I am still leery
enough of Java Applets to not visit any Web site unless I know the
perpetrator, and I use WebEx rather than Netscape if the site allows it
(and I avoid "freeware" from unknown sources).
I tend to avoid Web sites, in general, because I find dealing with
them is a frustrating experience, mostly due to poor design. Given the
choice between ordering catalog merchandise on the Web, or calling with
an 800 number and talking to a person, I'll take the telephone every
time! I imagine that I am not the only one who has reached this
conclusion. According to a recent survey, the use of on-line banking is
mow decreasing, rather than continuing to increase as expected.
Apparently, the Average Idiot Home User is also finding it harder to do
business on the Web than some merchants expected it to be :-(.
Regards,
--Murray
___
* MR/2 2.25 #120 * If it can happen, it will (Murphy)
--- Maximus/2 2.02
* Origin: OS/2 Shareware BBS, telnet://bbs.os2bbs.com (1:109/347)
|