Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Microsoft OS X Security Software Windows IT

Adobe Hopes Pop-up Warnings Will Stop Office-Borne Flash Attacks 125

tsamsoniw writes "In the wake of the most recent zero-day attacks exploiting Flash Player, Adobe claims that it's worked hard to make Player secure — and that most SWF exploits stem from users opening infected Office docs attached to emails. The company has a solution, though: A forthcoming version of Flash Player will detect when it's being launched from Office and will present users with a dialog box with vague warnings of a potential threat."
This discussion has been archived. No new comments can be posted.

Adobe Hopes Pop-up Warnings Will Stop Office-Borne Flash Attacks

Comments Filter:
  • by Gothmolly ( 148874 ) on Friday February 08, 2013 @11:59PM (#42840799)

    This is why your data should not be executable.

  • Clever move (Score:4, Insightful)

    by physlord ( 1790264 ) on Saturday February 09, 2013 @12:03AM (#42840811) Homepage

    Yeah!. Since the average user totally understands the situation, that "vague warnings of a potential threat" will, obviously, solve the problem. Pure genius.

  • by v1 ( 525388 ) on Saturday February 09, 2013 @12:09AM (#42840843) Homepage Journal

    "So what's wrong with it?"

    "You have the latest flash virus. Have you opened any Word documents lately?"

    "Of course! I use Word all day."

    (scans hdd, finds the one in email that started it)

    "Did you open this?"

    "Of course I did. It's the weekly report."

    "Didn't it WARN you there may be a virus?"

    "Yes it opened up a box I hadn't seen before. But I needed to see the report, so I clicked the Open Anyway button."

    "Didn't you get the memo last week about not clicking Open Anyway?"

    "Of course I read the memo. But I need to read that report. I had to open it."

    aaaand this is why this doesn't work anywhere near as well as Adobe says it will. No matter how many times you tell them to call you and NOT open it anyway, they still will. And you'll be at her desk again. Maybe later today even. Because she opened it anyway, because she "had to". (speaking from experience here)

    The only reasonably effective way to implement this is with a policy that is system-wide, that allows administrators to disable the Open Anyway button for the users that can't be trusted with it. (which will be most of them)

  • by hawguy ( 1600213 ) on Saturday February 09, 2013 @12:11AM (#42840853)

    There's absolutely no reason to have Flash installed on machines in an office. Remove it and give the users regular accounts so it can't be re-installed, and you'll be fine.

    Except of course, for the web-based trainings that employees have to take that rely on Flash.

  • by Darinbob ( 1142669 ) on Saturday February 09, 2013 @12:12AM (#42840857)

    People want convenience. And convenience is the mortal enemy of security.

  • by Darinbob ( 1142669 ) on Saturday February 09, 2013 @12:22AM (#42840927)

    People sometimes don't realize that people they know may be sending malware (not on purpose), or that someone may be pretending to be people they know. Just because the email is from the head of your church committee doesn't mean it's safe to open the "look at these kitties!" file.

    Some people also just click yes to everything. I was helping my mother figure out some new problem on Firefox, which involves telling her the names of a particular menu to choose and the like. And I couldn't figure out why she wasn't find the menus or buttons I was talking about. Then I realized she had updated her Firefox whenever it popped up and said "hey, please update me!", and now she had a UI she was unfamiliar with. This also means she occasionally ends up with google bars or yahoo bars or something else stupid that I have to uninstall every time I visit.

    It's not just mothers that do this, I see professionals in the office doing the same thing.

  • by decora ( 1710862 ) on Saturday February 09, 2013 @01:15AM (#42841197) Journal

    welcome to corporate america, you are responsible for shit you have no way to control or to fix.

    just like everyone else.

    those people who have to open those reports are in the same boat as you. if they dont open the report, then xyz doesnt get done, then a shit storm rolls down the hill and destroys the entire department.

  • by rudy_wayne ( 414635 ) on Saturday February 09, 2013 @01:28AM (#42841249)

    WTF is so convenient about having Word being able to display Flash content?

    Do a significant/noticeable number of people embed Flash content in their Word documents?

    The number of people actually doing this for legitimate reasons is probably very small. The problem is, companies like Microsoft and Adobe must constantly release new versions of their software in order to keep a constant revenue stream. And that means constantly adding new "features" of questionable value.

  • by hawguy ( 1600213 ) on Saturday February 09, 2013 @01:35AM (#42841289)

    Except of course, for the web-based trainings that employees have to take that rely on Flash.

    Web-based training is a virus. It both decreases productivity and makes users unhappy.

    No arguments here, but tell that to the state of California that requires 2 hours of sexual harassment training for all workers that supervise other employees. The training itself decreases productivity and makes users unhappy, making it web based doesn't make it moreso. A least I can browse the web while clicking through the tedious training with "quizes" with answers that anyone with a modicum of common sense can answer.

  • by chopthechops ( 979273 ) on Saturday February 09, 2013 @01:56AM (#42841373)
    After 18 years or so of increasingly frequent popup messages appearing in popular software you would think everyone realises by now how useless they are. Normal users don't read popups, and those who do read them don't know or care what they mean, and/or they just choose to ignore them. Actually I think software vendors know exactly how useless they are, and in the case of security-related popups it's just the vendor saying "security is the end user's problem, not ours". Kinda like the warnings you get on cigarette packets.
  • by symbolset ( 646467 ) * on Saturday February 09, 2013 @02:50AM (#42841585) Journal
    Why fix on flash? Word can be Pwned by an image, an embedded spreadsheet, a document template, one of a hundred forgotten media formats - or even a font. It's a beautiful gateway to being pwned that requires no user interaction. You don't even have to open a document: it installs pwnable services to facilitate remote management by random strangers.
  • by Chas ( 5144 ) on Saturday February 09, 2013 @02:56AM (#42841611) Homepage Journal

    Sorry.

    It doesn't happen that way.

    It just doesn't.

    They tried this with browsers. It was egregiously cumbersome and conditioned people to auto-click YES to everything.

    They tried this with Windows. It's still egregiously cumbersome and is still just conditioning people to blindly auto-click YES to everything.

    So...NOW...they're adding MORE crap to click YES automatically to?

    Third time's the charm?

    FUCK NO!

    Three strikes and you're out fuckers!

    Warning popups prevent a small amount of infestations up front.
    HOWEVER, down the road, as people get conditioned to the popups, they just click past without looking. Because the popups ARE IN THEIR WAY.

    Adding a stupid popup is basically an admission that they're too goddamn stupid or lazy (or both) to secure their software properly. Or that their software is, inherently not secure or not able to BE secured.

    At which point, it's crap that needs to be replaced with a better solution. Even if it means giving up the convenience of "Well this works right now".

  • by Titus Groan ( 2834723 ) on Saturday February 09, 2013 @08:07AM (#42842459)
    just because the software is flexible enough to do the job doesn't make it the right tool for that job. this system can indeed be built in house by those who don't have a full understanding of programming but do have a better insight in to the data that's being manipulated. it's going to be poorly documented and when it breaks or goes wrong very few people are going to be able to fix it for you. Do the job properly from the outset - hire a programmer and have custom software written to your spec. The false economy of using off the shelf products has led to many companies downfall.

I've noticed several design suggestions in your code.

Working...