[2848] in WWW Security List Archive
RE: ActiveX - Arrogance rules (fwd)
daemon@ATHENA.MIT.EDU (Chris Newton)
Thu Aug 29 17:58:12 1996
Date: Thu, 29 Aug 96 13:32:40 PDT
From: chris@sandpiper.com (Chris Newton)
To: www-security@ns2.rutgers.edu
Errors-To: owner-www-security@ns2.rutgers.edu
>
> Only one person has to recognize that the ActiveX control is performing
> nefarious background activities to blow the whistle -- and that is one
> gigantic whistle. I do not have to provide an appeal to ethics to show
> that this simply will not happen with large companies. Self interest is
> enough. Do you have any idea what kind of publicity machine would come
> down on a company that did this?
>
>
This begs another twist on the old denial-of-service attack. Someone blows the
whistle on an obscure ActiveX control from a competitor, and lo and behold,
people start blocking everything from that site