It's the internet age, now. Local-only really isn't any more.
It's the internet age, now. Local-only really isn't any more.
Part of the reason it's so easy to infect technically illiterate crowd nowadays is that they didn't develop an immunity system - something us who grew up with computers take almost for granted. It doesn't really take that much to become almost completely immune to malware - 90% of it is simple to spot (don't download things from CNET or any other site that has lots of ads, and especially those that try to trick you into clicking them; don't open .exe's you didn't explicitly requested; know what's an .exe; don't open attachments you didn't expect; etc.) - but somehow the society at large doesn't bother. And yet they expect someone else to fix it for them. As the saying goes, "Any fool can use a computer. Many do.".
I understand how we got there. I don't like it, but well, Moloch does what he wants. The thing to remember is, the increased sterility of the ecosystem and all those things done "for Security!" come at the cost of the ability of general-purpose computation. Future systems will tend to be dumbed down to the point they're not general-purpose computers anymore.
I wish, I hope, they'll let us keep PCs as specialized machines, like lathes and mills.
You're spot on that most people don't bother learning these things anymore, and particularly in the tablet ecosystem where apps are expected to be doctored for them as they come from a trusted source.
Security is fundamentally broken - there is a lot of innovation that needs to happen to make our computers more secure. There are a lot of non mainstream systems that have better security, we need to move their practices/architecture into the mainstream.
Hell, when you see things like quantum insert - how can any user be expected to keep their machine secure.
For all these years, I never clearly understood just what was meant by open an attachment. I don't have a clear description, definition, or explanation. Help! [No joke]
Background.
In about 1995, I was using some OS/2 e-mail program that wanted to put an icon somewhere for each e-mail message, screamed bloody murder at all those absurd icons until my throat was sore, got out the e-mail RFCs, and in about an hour used the TCP/IP interface of the scripting language Rexx to write my own POP3 e-mail software. Did all the e-mail reading and writing in just my favorite text editor, KEdit. The pair worked great -- used them for years.
Then, sure, just as in the e-mail RFCs, especially about multi-media internet mail extensions (MIME) or some such, there were attachments. So, again in Rexx, I wrote the basic base 64 en/decode software to handle attachments.
So, of course, I could receive a virus via e-mail totally safely -- to me, an attachment was just some simple ASCII characters to be interpreted as the base 64 encoding of something, maybe a JPG file. No harm in receiving the ASCII characters -- they look like just gibberish of simple typing by a very busy kitty cat walking on a keyboard, no harm in that -- or the base 64 code or translating that base 64 code to bytes and storing the bytes in a disk file. A file is just a sequence of bytes, any bytes at all -- harmless. Simple. Save.
So, if an attachment claimed that it was a JPG, then I might give the corresponding file from translation from base 64 to some graphic software to display the JPG. If in fact the attachment was an EXE to do harm to my computer data, etc., then I would trust the graphics program to notice that the attachment was not a JPG -- should be easy enough for the graphics program to tell.
Then I moved to Windows XP and then SP3 and Outlook 2003, and I'm still there and see little or no reason to change but just want to get on with my real work where XP SP3 is fine.
So, Outlook has attachments. Still, I never knew just what the heck was meant by open an attachment. So, if an attachment, say, in some MIME e-mail header line or some such, claims that it is a JPG file, then maybe give the attachment, translated from base 64, to some graphics program and trust that the graphics program will (1) display a real JPG without harm or (2) give an error message at anything else. Similarly for PNG, GIF, BMP, HTML, CSS, JS, etc.
For an EXE, of course, certainly, no way would Windows let the thing try to execute as software, right? I mean, not a chance, true? Or, the old, rock solid, first rule of computer security was to never, but never permit data from an untrusted source to execute as software, right? Handle such data just as bytes, sure, okay, safe, etc., but just no way ever let it execute as software, and that should be okay, right?
So, what does open do that is not safe?
No joke: In all these years, I've heard about e-mail and open an attachment and still have no clear description, definition, or explanation that would say just what open does or why it's dangerous.
As far as I can tell, the people, maybe who wrote Outlook 2003, who talked about doing an open on an e-mail attachment never really made at all clear just what the heck they were talking about.
Since many people still are afraid of open, where I see little chance of harm, maybe others would like some clarity, too.
Help! [no joke].
Attachments, be it EXEs or DOCs or whatever, exist as bytes in memory but don't (at least, they shouldn't) get processed - that is, opened - until you explicitly ask to.
So, JPEGs get handled by the JPEG shell handler. DOCs get handled by the DOC shell handler.
And unfortunately EXEs get handled by the EXE shell handler. This breaks the rule that you stated, that you should never ever permit data from an untrusted source to execute. This is where the problem lies!
As far as "open" means, it is a piece of terminology to explain the concept of saving data to a temporary store and then passing that file reference to the shell, which typically for most programs gets passed as a parameter to that file-type-handling program. Explorer > Tools > Folder Options will list file types in there and you can see how different types are handled, and the parameters passed to programs.
Of course, the base64 encoding, temporary file saving, shell passing is a bit more complex to explain to someone than using the expression "open", hence why people just say "open the attachment".
It's a terminology thing.
https://news.ycombinator.com/item?id=9050436
about
http://www.nytimes.com/2015/02/15/world/bank-hackers-steal-m...
in that NYT piece on hacking banks in Russia there is:
"In many ways, this hack began like any other. The cybercriminals sent their victims infected emails — a news clip or message that appeared to come from a colleague — as bait. When the bank employees clicked on the email, they inadvertently downloaded malicious code. That allowed the hackers to crawl across a bank’s network until they found employees who administered the cash transfer systems or remotely connected A.T.M.s."
So, to get infected all they had to do was just click "on the email"? Not even click on an attachment! That must be some strange, dangerous e-mail software!