-
Website
http://www.scobleizer.com/ -
Original page
http://scobleizer.com/2006/01/13/more-on-wmf-did-microsoft-leave-a-backdoor/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
danja
44 comments · 4 points
-
polizeros
52 comments · 1 points
-
AndyBeard
69 comments · 4 points
-
Zachary Adam Cohen
35 comments · 8 points
-
dbarefoot
40 comments · 3 points
-
-
Popular Threads
-
World-brand-building mistakes France’s entrepreneurs make
2 weeks ago · 181 comments
-
The best and worst thing Twitter did in 2009: RT
3 days ago · 24 comments
-
2010: the year SEO isn’t important anymore
1 week ago · 67 comments
-
iPhone developers abandoning app model for HTML5?
1 week ago · 52 comments
-
A new addition here: the Meebo bar
2 days ago · 8 comments
-
World-brand-building mistakes France’s entrepreneurs make
Thanks for the link to Stephen's post btw, v. interesting.
I think it is possible, but not likely. Mr. Gibson can be a little paranoid. That's his job.
S.
All the WMF issues are due to plain old incompetence.
a) didn't require user interaction (opening webpage or image)
b) not part of a public API
c) make it targetable (pick an IP instead of indiscriminate)
Hmm, screw that, conspiracy theories are much more fun! UFOs power MacOSX! Steve Jobs is an android powered by pure evil! Walt Disney was the antichrist!
Pure nonsense ..
podcast, I think he was reaching a little .
Since the 13th, when Gibson's podcast aired, this has been the only response from MS. It would appear that a technically competent rebuttal is in order.
Has someone come along and documented that Gibson's findings (that the only way to trigger malicious code is by setting the file length to 1, and that the value of SetAbortProc doesn't matter since the code that will be executed is immediately following the header)? Has anyone rebutted them?
I'll be the first to admit that Gibson has an ego the size of Montana (or at least San Diego), but silence on this does not do MS any good, and this appears to be something difficult to "evangelize" away, given all the security reviews that this code should have received enroute to XP SP2, and Vista. (Unless by "code review" they mean checking the filenames.)
Tim