[<prev] [next>] [day] [month] [year] [list]
Message-ID: <9E97F0997FB84D42B221B9FB203EFA273F3470@dc1ms2.msad.brookshires.net>
From: toddtowles at brookshires.com (Todd Towles)
Subject: IE is just as safe as FireFox
Borja makes a good point. Just like asking...why do e-mails have
incorrect words in them, when they are all instantly spell checked? ;)
> -----Original Message-----
> From: full-disclosure-admin@...ts.netsys.com
> [mailto:full-disclosure-admin@...ts.netsys.com] On Behalf Of
> Borja Marcos
> Sent: Thursday, November 18, 2004 8:47 AM
> To: Poof
> Cc: full-disclosure@...ts.netsys.com
> Subject: Re: [Full-Disclosure] IE is just as safe as FireFox
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> > Why is it that Microsoft's code has less quality even
> though all code
> > that's written is instantly audited? (Each line of code is checked
> > before it's 'passed' in to the code tree.)
>
> Design, design and design. Also, design.
>
> Writing programs isn't a simple matter of writing code
> and auditing it for buffer overflows. What about the lousy
> MIME-type handling in IE, detecting intelligently (but after
> declaring it harmless in the "security check") that a program
> disguised as an audio file could actually be an executable,
> and happily running it?
>
> It is bad design. The same as ActiveX. Why are many IE
> security problems avoided by disabling "Active Scripting"?
>
> There seems to be an obsession with "code" these days.
> And people affected by such disease forget that the code
> should come after a good design, and a bad design can only be
> fixed scaping it and starting over.
>
>
>
>
>
> Borja.
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.2.4 (Darwin)
>
> iD8DBQFBnLX5ULpVo4XWgJ8RAlTJAJ92yXv8C5ArhrGzsHCNXBQHyECqhQCcDoL9
> LGLighoTQw5rSwV2/mMp72k=
> =TDnR
> -----END PGP SIGNATURE-----
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html
>
Powered by blists - more mailing lists