4 ms·
Social engineering will ALWAYS be the most effective means of compromising a system. If you can get the user to run a thing, you have got them to run anything
by TodPunk 11y ago
Social engineering will ALWAYS be the most effective means of compromising a system. If you can get the user to run a thing, you have got them to run anything you want forever. This is not a problem with VBA, VBA is merely providing functionality (and useful functionality in many respects). There is no way to prevent this in VBA or any other technology. The only vector of mitigation is educating the user.
- makmanalp 11y agoSocial engineering will be always effective, but that's not the point. This /is/ a problem with VBA - as a person viewing a document, it doesn't seem like you're running anything, but really you're running arbitrary unsigned code that has full r/w access to everything on your system. To make it worse, this has been a major attack vector for over a decade yet it's still completely unsandboxed.
- gnaritas 11y agoThat's not really true, it doesn't run by default, the user is prompted and warned about possible malicious scripts AND they run them anyway. All you have to do is put instructions/picture in the doc telling the user to click that button to see the content, and they usually will. Users are simply ignorant of the dangers, that's the problem and it's always been the problem and that's unlikely to change.
- makmanalp 11y agoI know it doesn't run by default - a warning about malicious scripts is a cop out and everyone knows it. Yes, if we trained everyone to be programmers, then maybe no one would click it. However, the point is, how do I know what will happen when I click this button? Will it run a helpful macro to format my data or will it delete all my files? Why is a macro language allowed to do that? Why do those two things have the same security level assigned to them? You should run executables only from trusted sources - that's what we're told, right? Now - do you trust an email appearing to genuinely be from a very prestigious honor society from the world's largest CS authority? Why not? Why was the person not able to cryptographically verify that, yes, that is indeed where this file came from? What is that - you say that since they didn't know the sender personally, they shouldn't have trusted the file anyway? A different example: What if, say, someone used windowsupdate or apt-get as an attack vector? I bet you're trusting those strangers already, as we speak, and you have pretty much no say in the matter. "Oh, we'll put in a warning dialog" is the most crappy duct-tape there-I-fixed-it style solution to this extremely nuanced problem, and blaming the user does nothing to secure real world systems.
- gnaritas 11y ago> You should run executables only from trusted sources - that's what we're told, right? No, that's what computer savvy people know, normal users don't think twice about running an executable from any source, that's the whole point. Nothing you suggested will stop what people simply do continually, open anything from anyone without caring who the sender is. Sandboxes don't just protect things, they forbid necessary and useful things so you can't simply sandbox everything because users will simply refuse to use your crippled software and opt for the less secure but more functional version. Users don't care about security, that's the problem; it's a social problem, not a technical one.
- xorcist 11y agoThere has historically been countless of ways to circumvent that prompt, even after they put it in there. If you opened a txt file in your editor, which then installed spyware on your computer, wouldn't you put the blame squarely on your editor?
- gnaritas 11y agoYes, but docs are text files, they're binary.
- billyhoffman 11y agoI get what you are saying, and fundamentally it is a social/education vector. However there are easy, obvious things that Microsoft can do to make this better. Off the top of my head, macro execution shouldn't be a boolean choice. Don't let Macros modify the file system or connect the network, without additional prompts/warnings. Default to not allowing these at all, and the user can't just click a "OK" dialog to start allow it. Bury that setting deep in Control Panel. OS X/HFS+ has an interesting feature of using meta data to tell where files came from. You get security prompts even days later when doing certain actions with files downloaded from the Internet. Word/Office could act differently with Macros based on whether this file was an email attachment or downloaded vs. a local file the user created. When enabling VBA scripts, they could be run in a sandbox for a few seconds to see what it modifies on the system. Yes, there are ways around this, but lets raise the bar some.