2 ms·
> It is a program that reads unstrusted binary blobs When opening any office files from unknown or untrusted sources is something you feel you have to do, you'
by redprince 3y ago
> It is a program that reads unstrusted binary blobs
When opening any office files from unknown or untrusted sources is something you feel you have to do, you're probably well off isolating that operation and thus limit the blast area.
For people working exclusively on their own files or with trusted colleagues, that is pretty much a non issue.
- tredre3 3y agoWhy do you keep moving the goalposts? First you say that people should just audit the code if they don't trust it. Then you say if someone wants to read untrusted files they should just spin up a virtual machine? So I need to spend thousand of hours reading libreoffice's and its dependencies' code, and then I still need to run it in a virtual machine when I read untrusted files (in case there are bugs that could be exploited)? It makes zero sense to keep pushing that nonsense when the alternative is to sandbox apps to begin with. It makes EVERYBODY safe from backdoors and bugs, for FREE. Why do you fight it?
- redprince 3y ago> First you say that people should just audit the code if they don't trust it. Then you say if someone wants to read untrusted files they should just spin up a virtual machine? Because of an intended functionality of many of those file formats, which makes them quite dangerous when coming from untrusted sources: Macros.