<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: F-Secure is mistaken regarding Windows 7 RC security &#8220;fail&#8221;</title>
	<atom:link href="http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/</link>
	<description>Because technology isn&#039;t just for geeks</description>
	<lastBuildDate>Tue, 24 Jan 2012 20:02:45 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
	<item>
		<title>By: Sean</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-2358</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Thu, 27 Aug 2009 22:01:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-2358</guid>
		<description>The other thing that annoys me about hiding extensions is a setup program

setup.exe, setup.msi, setup.ins, setup.txt, setup.com

&quot;please click on setup&#039;

Which one???

With this, it&#039;s easy to release something that has a similar name to a genuine program (does anyone remember companion viruses) and for it to launch the geniune article, thereby hiding the realisation that something is amiss</description>
		<content:encoded><![CDATA[<p>The other thing that annoys me about hiding extensions is a setup program</p>
<p>setup.exe, setup.msi, setup.ins, setup.txt, setup.com</p>
<p>&#8220;please click on setup&#8217;</p>
<p>Which one???</p>
<p>With this, it&#8217;s easy to release something that has a similar name to a genuine program (does anyone remember companion viruses) and for it to launch the geniune article, thereby hiding the realisation that something is amiss</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-2343</link>
		<dc:creator>Jan</dc:creator>
		<pubDate>Tue, 25 Aug 2009 19:08:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-2343</guid>
		<description>&quot;But if you the user goes out of your way to change the default applications to something else that doesn’t automatically flag untrusted files, then you either should know better or you’re responsible for your own actions.&quot;

That is silly; there are many reasons to use Firefox instead of IE nowadays, and many people who are not extremely knowledgeable do. There is no warning anywhere in Windows 7 that installing non-Microsoft software will open you to this kind of danger.

Arguably, the addition of this &#039;flagging an executable as possibly dangerous&#039; means that this problem is now a security hole in any program that does not use it. Saying that there is no security hole because anyone who does not use Microsoft software should know what he is doing is silly, however.

(And, incidentally, I think that, since simply displaying the file types would fix the problem to some degree, MS is still partly to blame).</description>
		<content:encoded><![CDATA[<p>&#8220;But if you the user goes out of your way to change the default applications to something else that doesn’t automatically flag untrusted files, then you either should know better or you’re responsible for your own actions.&#8221;</p>
<p>That is silly; there are many reasons to use Firefox instead of IE nowadays, and many people who are not extremely knowledgeable do. There is no warning anywhere in Windows 7 that installing non-Microsoft software will open you to this kind of danger.</p>
<p>Arguably, the addition of this &#8216;flagging an executable as possibly dangerous&#8217; means that this problem is now a security hole in any program that does not use it. Saying that there is no security hole because anyone who does not use Microsoft software should know what he is doing is silly, however.</p>
<p>(And, incidentally, I think that, since simply displaying the file types would fix the problem to some degree, MS is still partly to blame).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jvans</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1488</link>
		<dc:creator>Jvans</dc:creator>
		<pubDate>Tue, 12 May 2009 11:17:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1488</guid>
		<description>If find this incredible because it&#039;s coming from a firm that is responsible for problably the worst anti-malware program in the world. Don&#039;t you believe me . Have a look a this :&lt;br&gt;&lt;br&gt;http://www.youtube.com/watch?v=ZlHgZBkwyEg&lt;br&gt;&lt;br&gt;http://www.youtube.com/watch?v=OUTWqHIFzM8&lt;br&gt;&lt;br&gt;F-Secure Fails</description>
		<content:encoded><![CDATA[<p>If find this incredible because it&#8217;s coming from a firm that is responsible for problably the worst anti-malware program in the world. Don&#8217;t you believe me . Have a look a this :</p>
<p><a href="http://www.youtube.com/watch?v=ZlHgZBkwyEg" rel="nofollow">http://www.youtube.com/watch?v=ZlHgZBkwyEg</a></p>
<p><a href="http://www.youtube.com/watch?v=OUTWqHIFzM8" rel="nofollow">http://www.youtube.com/watch?v=OUTWqHIFzM8</a></p>
<p>F-Secure Fails</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gubment.cheez</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1484</link>
		<dc:creator>gubment.cheez</dc:creator>
		<pubDate>Tue, 12 May 2009 11:17:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1484</guid>
		<description>this sounds like the exploit that requires administrative privleges to work</description>
		<content:encoded><![CDATA[<p>this sounds like the exploit that requires administrative privleges to work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George Ou</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1483</link>
		<dc:creator>George Ou</dc:creator>
		<pubDate>Sat, 09 May 2009 14:03:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1483</guid>
		<description>Kelbo, it already is done automatically.  But if you the user goes out of your way to change the default applications to something else that doesn&#039;t automatically flag untrusted files, then you either should know better or you&#039;re responsible for your own actions.</description>
		<content:encoded><![CDATA[<p>Kelbo, it already is done automatically.  But if you the user goes out of your way to change the default applications to something else that doesn&#8217;t automatically flag untrusted files, then you either should know better or you&#8217;re responsible for your own actions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kelbo</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1482</link>
		<dc:creator>Kelbo</dc:creator>
		<pubDate>Sat, 09 May 2009 14:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1482</guid>
		<description>&quot;advanced users who don&#039;t use IE probably know better and already undo the extension hiding&quot;&lt;br&gt;&lt;br&gt;The experts should be making the policies to protect the general public who do not possess the knowledge of either the potential vulnerabilities or the procedures to prevent impact .  If the &quot;people who know&quot; do something, it should be done automatically for the &quot;people who have no clue&quot;.&lt;br&gt;</description>
		<content:encoded><![CDATA[<p>&quot;advanced users who don&#8217;t use IE probably know better and already undo the extension hiding&quot;</p>
<p>The experts should be making the policies to protect the general public who do not possess the knowledge of either the potential vulnerabilities or the procedures to prevent impact .  If the &quot;people who know&quot; do something, it should be done automatically for the &quot;people who have no clue&quot;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ctelon</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1481</link>
		<dc:creator>ctelon</dc:creator>
		<pubDate>Fri, 08 May 2009 14:11:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1481</guid>
		<description>I don&#039;t like having extensions shown because I usually forget to add the extension when renaming a file, causing other problems. I have other habits that help me prevent opening unwanted executables. This is how it has been as far as I can remember. Why is showing extensions an issue now? The average user is not interested in knowing what the file extension is, and probably don&#039;t even know what an extension is. An advanced user would just set the computer to show the extensions if needed. Educating the users is definitively the way to go. And why blame Microsoft for the way third party apps work…what is that?!</description>
		<content:encoded><![CDATA[<p>I don&#8217;t like having extensions shown because I usually forget to add the extension when renaming a file, causing other problems. I have other habits that help me prevent opening unwanted executables. This is how it has been as far as I can remember. Why is showing extensions an issue now? The average user is not interested in knowing what the file extension is, and probably don&#8217;t even know what an extension is. An advanced user would just set the computer to show the extensions if needed. Educating the users is definitively the way to go. And why blame Microsoft for the way third party apps work…what is that?!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sneeze</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1480</link>
		<dc:creator>sneeze</dc:creator>
		<pubDate>Thu, 07 May 2009 21:02:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1480</guid>
		<description>dietrich: That&#039;s not true at all; any tar archive can store files with +x. For this problem, it would depend on whether the distro lets people run executables just by clicking on them, which it shouldn&#039;t.</description>
		<content:encoded><![CDATA[<p>dietrich: That&#8217;s not true at all; any tar archive can store files with +x. For this problem, it would depend on whether the distro lets people run executables just by clicking on them, which it shouldn&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nuCrash</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1479</link>
		<dc:creator>nuCrash</dc:creator>
		<pubDate>Thu, 07 May 2009 17:26:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1479</guid>
		<description>I don&#039;t really think this applies to Microsoft.  This has been around for years.  You have one of two choices and either one comes down to educating the end user.&lt;br&gt;&lt;br&gt;1.  Disable the file extensions by default and teach the users what changing the file extensions do  (Something I already implement at my work site.)&lt;br&gt;&lt;br&gt;2. Hide the file extensions and teach the users to scan any files that they save to their computer or open on a source that may not be trustworthy.  (Again, something I do already at my work site.)&lt;br&gt;&lt;br&gt;Should this be even considered an exploit?</description>
		<content:encoded><![CDATA[<p>I don&#8217;t really think this applies to Microsoft.  This has been around for years.  You have one of two choices and either one comes down to educating the end user.</p>
<p>1.  Disable the file extensions by default and teach the users what changing the file extensions do  (Something I already implement at my work site.)</p>
<p>2. Hide the file extensions and teach the users to scan any files that they save to their computer or open on a source that may not be trustworthy.  (Again, something I do already at my work site.)</p>
<p>Should this be even considered an exploit?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George Ou</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/comment-page-1/#comment-1478</link>
		<dc:creator>George Ou</dc:creator>
		<pubDate>Thu, 07 May 2009 12:22:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.formortals.com/?p=180#comment-1478</guid>
		<description>That&#039;s fine Mikko, but I think you should point out that MOST default vectors on the Windows platform are indeed covered and advanced users who don&#039;t use IE probably know better and already undo the extension hiding.  As for those applications you mention that fail to mark files untrusted, that&#039;s a security failure in those particular applications from third party vendors.  You should blame those third parties for these problems and not Microsoft.&lt;br&gt;&lt;br&gt;As for sneakernet techniques, autorun is a MUCH larger risk than this particular vector.  But again, I would prefer that Microsoft stop hiding file extensions but it isn&#039;t really accurate to portray this as a Windows 7 issue nor is it even a marginal security issue.</description>
		<content:encoded><![CDATA[<p>That&#8217;s fine Mikko, but I think you should point out that MOST default vectors on the Windows platform are indeed covered and advanced users who don&#8217;t use IE probably know better and already undo the extension hiding.  As for those applications you mention that fail to mark files untrusted, that&#8217;s a security failure in those particular applications from third party vendors.  You should blame those third parties for these problems and not Microsoft.</p>
<p>As for sneakernet techniques, autorun is a MUCH larger risk than this particular vector.  But again, I would prefer that Microsoft stop hiding file extensions but it isn&#8217;t really accurate to portray this as a Windows 7 issue nor is it even a marginal security issue.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

