3 ms·
It's the same old same old. Like you correctly identified it's a new place, it looks different. People don't think an attacker could approach them over IM, but
by SCHiM 5y ago
It's the same old same old. Like you correctly identified it's a new place, it looks different. People don't think an attacker could approach them over IM, but they can.
But the problem goes beyond that. Many organizations have disabled sharing executable file formats in attachments over e-mail. GMail flat-out prevents you from sharing executables, and macro enabled word documents as attachments, even when put into a zip file.
But on Microsoft teams? I sent a zip file with 8 unsigned executables to a colleague a few days ago. No warnings, no messages, no nothing :)
- recursive 5y agoI don't know if it's true, but a co-worker of mine said that, "in the wild" signed binaries are positively correlated with being malware. I don't think the signing itself does much.
- zeusk 5y agoFor general public I can see how that is helpful if they can't decide if a foreign executable is trust worthy or if they execute everything with admin/root privilege. As for me, I really hate this "feature". I work with IHVs and often have to share private binaries and it's a chore using xcopy/sfpcopy to their bespoke network path, from where I guess then someone manually copies over to their local subnet. We should have a more robust mechanism in place than to outright ban sharing of executable files. Windows Smartscreen and Mac's Gatekeeper method of online checksum/signature verification is sort of interesting.
- 650REDHAIR 5y ago1000 times no. You need to build security for the lowest common denominator.
- zeusk 5y agoWhich is what Defender smartscreen and Gatekeeper are. With their full on setting, they give you a big fat warning on running files from internet. This is like banning guns and cars because they can kill people. Also, you do 24 hours of lemons?