7 ms·
> Typically installed by booby-trapped Microsoft Office documents and distributed via email It bothers me that this is the tactic of the vast majority of malwa
by vmoore 4y ago
> Typically installed by booby-trapped Microsoft Office documents and distributed via email
It bothers me that this is the tactic of the vast majority of malware. Microsoft Word's 'enable content' button if clicked, can execute code and this is the first point of entry for most malware. Why allow for arbitrary code execution in Word in the first place? It's an anti-feature and the only use-case for it is getting infected with malware. It needs to be dropped by Microsoft as soon as possible, wiping out a whole class of attack.
- steponlego 4y agoIt’s necessary in case the “good guys” need a security vulnerability to do “good things.” Proprietary software will always have security holes planted by governments. Linux has had this issue too, being a huge mess of code written by a huge number of mega-corps across the globe. I often chuckle at the thought of all the Israeli, Chinese, Russian, and NSA spies constantly undoing each other’s work. It’s why I run OpenBSD now.
- nickpeterson 4y agoI feel ya, but even OpenBSD may not help if you end up running a bunch of things from ports.
- steponlego 4y agoGood old pledge and unveil help that a lot.
- red-iron-pine 4y agoDidn't it come out a few years ago that OpenBSD -- or anything *BSD -- was one of the keywords that the MONSTER email sniffer used by the FBI. Like if you're using OpenBSD they're already trying to track you...
- steponlego 4y agoSounds like an endorsement to me.
- yjftsjthsd-h 4y ago> It's an anti-feature and the only use-case for it is getting infected with malware. That's an interesting question; what is the intended use case for that feature? It has to have some actual business value or they would have removed it after all these decades of trying to make it less egregiously dangerous
- idiotsecant 4y agoIt has enormous value, based on technical debt. Tons of legacy business processes rely on crusty old VBA living in microsoft office documents.
- can16358p 4y agoI think they should stay but run within a very hard virtual sandboxed environment totally separate from user's system. That might be the sweet spot. Still not 100% secure and there might be some attack vectors but better than what we have now.
- voakbasda 4y agoCars once relied on fuel containing lead, which had indisputable value for those mechanical systems. Once external factors were understood and considered, it was banned through regulation, despite the value that it provided. Keeping this technology around has external costs to our entire computing ecosystem that outweigh the benefits.
- albatross13 4y agoIt is hilarious to me that: 1. I've never thought about this concept 2. I've never been exposed to it This world is absolutely wild. To be clear- I fully believe you, I've just never worked at a place where we relied on VBA in a word doc lol
- idiotsecant 4y agoThis is a momnkeypaw situation- you wish for VBA from office products to be removed, so the monkeypaw grants your wish, but you get to be the poor SOB who reimplements the billions of lines of code that is duct taping together business logic in these documents all around the world.
- rnk 4y agoThese execution possibilities on word docs and other microsoft office docs are inherently dangerous, everyone knows it. I guess we need real apps to do things. We all know it.
- Jtsummers 4y agoWhat's a "real app"? How much does it cost? How long until it's ready? How well does it integrate with other systems you're already using? Can the users extend it or do you have to purchase a support contract and still pay extra $$$$$$ to get even a basic feature added? Companies and individuals keep using Excel and other things because they work for them today. They integrate well enough with the other things they're using. It's a mess, don't get me wrong, and a security nightmare. But you need to come up with something that Alice in Accounting, Bob in Billing, Charlie in Contracting and all the other non-technical folks can use and extend themselves. Locking them into "real apps" is the reason they break out Excel. They need to get things done, and the apps they're provided are insufficient so they make (or inherit from their predecessors) their own.
- albatross13 4y ago[flagged]
- brewtide 4y ago[flagged]
- albatross13 4y agoA real app costs about tree fiddy one.
- wtallis 4y agoI don't see any compelling use case for executing code in a Word document, but it's pretty obvious that Excel spreadsheets can benefit from that capability.
- ajsnigrutin 4y agoWe have executable code in our browsers, and that code cannot do a lot of bad stuff, and when it can, it's a huge thing and a very shameful day for browser developers.
- rstuart4133 4y ago> and that code cannot do a lot of bad stuff, True now. But Microsoft made a contribution in this area too. Active-X plugin's were effectively DLL's you downloaded and then IE attached to itself. Since they ran as IE they could do anything IE was allowed to do - like modify most files on disk, including the OS. The customer got a plugin that could do literally anything the browser was allowed to do to the disk, display, network and OS, and it being native code Active-X plugins were quuuuuick. Microsoft got lock in. Security disaster understates it of course. They were rightfully treated like toxic waste by very browser except IE. My real point is Microsoft has form in this area. And it's form that continues to this day. They could have made VBA as safe as Javascript over time by perhaps introducing a safe version that was always allowed to run, and made the dangerous variant harder and harder to unlock. They've never showed the slightest interest in doing so. Instead they ship "Windows Defender", which is about as effective as a week old cotton mask in a COVID ward. Come to that they could have provided a Windows environment as safe as iOS and Android, and migrated everything in over the course of a decade or two. Again - not the slightest hint. Instead they apparently prefer to keep their systems insecure, and sell yearly licences to half arsed fixes like Intune to businesses who can afford it.
- andromeduck 4y agoWhat if I want a spreadsheet in my word doc?
- arprocter 4y agoSupposedly CVE-2022-30190 (Follina) works in the Preview pane of Explorer if it's an RTF document I'm not sure many folks have Preview enabled, but still...
- fulafel 4y agoWord documents have carried malware for decades, over email over microsoft supported email services. The most widespread untargeted ones eventually get added to antivirus signature databases so the % of population affected is limited. It's not like it surprises anyone. The corporate IT world has its own logic and incentives. The users certainly aren't going to rebel.