You can lead a horse to water, but you can't make him think. Part 1.

Years ago, the Open Source and Linux/Unix crowd (most of whose members are in both camps) jumped up and down on how stupid MS Office's developers were for including a macro language (at all, in many people's minds) in Word, among other applications in that suite.

Wind forward to today, and F-Secure comes out with the following announcement:

"One of our researchers, Sami Rautiainen, produced a paper for the Virus Bulletin Conference in September of 2003 on the topic of OpenOffice Security. The conclusions that he reached: The macro language and the API of OpenOffice are very powerful, but unfortunately the power can be abused for malicious purposes. The security settings in the default installation of OpenOffice much resembles older versions of Microsoft Office."

Okay, so that's from 2003 - old news.

Then they go on:

"That was then, and now… we have a sample of a proof-of-concept macro-virus for OpenOffice.org named Stardust.A. This thing is very proof-of-concept and is not something in the wild, but it's interesting to note that the waters are indeed being tested."

Unless I'm missing something here, that's yet another demonstration that, as far as developer security goes, there's no lesson like the one you learned first-hand.  Apparently, OpenOffice didn't learn from Microsoft's Word macro virus woes, and then didn't learn sufficiently from F-Secure's paper.

Update: As if that wasn't enough, I read this story from an Australian IT news web site. I don't know that I can even comment on the stunningly dangerous naivete shown by the Linux / Open Source advocate there. Read it for yourself - what do you think?

Published Fri, Jun 2 2006 11:37 by Alun Jones

Comments

# You can lead a horse to water, but you can't make him think. Part 2.

In the interests of balance to my last post, maybe I should tell a story about a Microsoft developer...

Friday, June 02, 2006 1:58 PM by Tales from the Crypto

# re: You can lead a horse to water, but you can't make him think. Part 1.

"There just isn't a way to really attack Linux or OS X or any of the Unix variants - once you compile it, it's like iron"  Tom Adelstein (From the IT News article)

That's not naive, that's stupid.

Monday, July 10, 2006 2:18 PM by Tom

# re: You can lead a horse to water, but you can't make him think. Part 1.

Tom's right - Tom's statement was stupid.  [I hope the two Toms aren't the same person!]  I don't know of Tom Adelstein, so I can't say whether he's prone to making stupid statements, but that one sticks out as reason to ignore him in future.

Tuesday, July 11, 2006 3:14 PM by Alun Jones

Leave a Comment

(required) 
(required) 
(optional)
(required) 
If you can't read this number refresh your screen
Enter the numbers above: