Neil Hopcroft

A digital misfit

“And yes, the trojan will most likely also work under Linux, but it won’t do really anything there as it tries to download and execute Win32 EXE trojan.”

Presumably it wouldn’t take much to run this under WINE, should the initial attempt to launch it failed. I wonder how much of a problem that could cause? …indeed, maybe it could obtain a different executable, which would presumably run within the security limitations of the user running the JVM.


4 comments

  1. ewx

    I don’t entirely see what the fuss is about. The trojan under discussion requires user confirmation to install (in the face of messages saying “not trusted” I’m sure underinformed people still hit “yes” on such things but they’re hardly new.

    There is a valid point to consider that the dialog boxes you get for these specific things are often hopelessly overcrowded. The one in the site you link to isn’t too bad, ISTR the one Firefox gives you in the same case is exceptionally verbose. Really it should be cut down to a line or two at most, with NOT TRUSTED in 72 point flashing text; the basic requirement is that anyone not equipped to understand what’s going on should feel very nervous and look for NO or CANCEL buttons.

    • Thats the problem – its all too complicated, and everyone is so used to saying “Always trust microsoft”, or whoever their favorite vendor is, that they don’t actually *read* the dialogs any more, especially as they’re full of complicated technical words.

      Indeed, over on S60 there are trojans spreading that require the user to get the answer to that question wrong three times in a row in order to get infected. They still spread, but, for some reason, mostly amongst people who have something to sell…

Leave a Reply

Your email address will not be published.