Stupid ebay/amazon question

Ben Scott dragonhawk at gmail.com
Fri Jun 30 18:53:01 EDT 2006


On 6/30/06, puissante <puissante at lrc.puissante.com> wrote:
>> Firefox has suffered similar image processing issues to IE with JPG
>> processing around-a-bouts the time 1.0 came out.
>
> Yes, but those are due to bugs and flaws in the software, not the basic
> mechanism like Active-X is.

  Well, since you bring it up, Firefox's "Extensions" are very similar
to ActiveX in this regard.  Both will auto-download programs to your
computer.

  The key difference is in the defaults for the access control.  By
default, Firefox will only allow you to install extensions from a
select list of sites (two of them, as of this writing), and even then,
Firefox will prompt you before doing so.

  In contract, until recently, by default, MSIE would automatically
download, install, and run any ActiveX program which was "signed".
Yikes!  Getting the code signed was fairly easy, but at least
established a papertrail.  But unsigned programs weren't really all
that different, and had no papertrail at all.  Unsigned programs gave
you the same style of "Are you sure" Y/N dialog box Microsoft gives
for a bunch of other things (so many users just hit "Yes" without
looking).  Even for informed users, it was way too easy to
accidentally hit "Yes".  So you were basically giving up control of
your computer to the operators of random websites.  Great design,
there.

  You can change the defaults in either program: You can tell Firefox
to be stupid if you really want to.  You can also lock down MSIE to
something reasonable.  Of course, fixing the settings in MSIE is not
at all obvious, so the "typical user" will never even know to do so,
let alone how.

  Microsoft changed the MSIE defaults to sane values in Win XP SP 2.
Of course, that only helps those Microsoft lusers who run Win XP and
install all the Microsoft updates.  Anyone else is still wide open.
(But Microsoft cares about security...)

-- Ben



More information about the gnhlug-discuss mailing list