[2861] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

RE: ActiveX - Arrogance rules (fwd)

daemon@ATHENA.MIT.EDU (Paul Phillips)
Fri Aug 30 20:20:33 1996

Date: Fri, 30 Aug 1996 15:24:04 -0700 (PDT)
From: Paul Phillips <psp@well.com>
To: Chris Newton <chris@sandpiper.com>
cc: www-security@ns2.rutgers.edu
In-Reply-To: <9608292032.AA23736@sandy.sandpiper.com>
Errors-To: owner-www-security@ns2.rutgers.edu



On Thu, 29 Aug 1996, Chris Newton wrote:

> This begs another twist on the old denial-of-service attack. Someone blows the
> whistle on an obscure ActiveX control from a competitor, and lo and behold,
> people start blocking everything from that site

This is no more or less likely to happen because of ActiveX controls 
than it is now for any number of existing pieces of software.  On the
net, when someone accuses another, the first thing that happens is
thousands of people rush out to verify the claim.  False accusations
of trojan horses will not lead to site blocking, they'll lead to public
ridicule.

I think some of you underestimate how difficult it is to keep millions
of people in the dark when they have direct communication channels to
one another.  

--
Paul Phillips <psp@well.com>


home help back first fref pref prev next nref lref last post