OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.


Help: OASIS Mailing Lists Help | MarkMail Help



   re: LISTADMIN: No attachments to list messages PLEASE

[ Lists Home | Date Index | Thread Index ]
  • From: David Megginson <david@megginson.com>
  • To: "XML Developers' List" <xml-dev@ic.ac.uk>
  • Date: Sat, 27 Mar 1999 11:09:14 -0500 (EST)

Rzepa, Henry writes:

 > Regarding the above message, I must say most strongly that
 > attaching enclosures to list postings is HIGHLY discouraged (not to
 > mention asking them not to show it to anyone else!).  Apart from
 > the risk of a virus, it also means everyone on the list has to
 > suffer the inconvenience of downloading a document they might not
 > want, and in many cases might not be able to read (Unix etc).

As became clear in the follow-ups, the posting was done by a worm that
hides in Word macros (the Internet's equivalent of animal dung,
apparently) exploits gaping security holes in Outlook to mail itself
out to everyone in a person's address list.

In other words, the original poster did *not* post the attachment to
xml-dev, the worm did.  His only mistakes were (a) using Microsoft
Windows, (b) opening a file in MS Word, and (c) not uninstalling
Outlook from his computer the first time he booted up.  If you had
summarily unsubscribed him, then you would simply have added an unjust
punishment to the embarrassment he was already suffering.

In fact, all three of the mistakes were probably mandated by company
policy; if so the true blame belongs in three places, in diminishing
order of culpability:

1. The poster's company, for ignoring the importance of technical
   diversity and mandating the same operating system and software for
   everyone (it's much easier to write a worm or virus when everyone's 
   using exactly the same software).

2. Redmond, for ignoring security whenever possible.

3. The creator of the worm.

If I'm right about corporate policy, then most of the blame goes to
the company -- Redmond just wants to sell software, and the worm
creator just wants attention, but the company failed to act in its own
self-interest.  Technical diversity is critical for good operation:
I'd no more want to see an all-Linux shop than I'd want to see an
all-Windows or an all-Mac shop.

All the best,


David Megginson                 david@megginson.com

xml-dev: A list for W3C XML Developers. To post, mailto:xml-dev@ic.ac.uk
Archived as: http://www.lists.ic.ac.uk/hypermail/xml-dev/ and on CD-ROM/ISBN 981-02-3594-1
To (un)subscribe, mailto:majordomo@ic.ac.uk the following message;
(un)subscribe xml-dev
To subscribe to the digests, mailto:majordomo@ic.ac.uk the following message;
subscribe xml-dev-digest
List coordinator, Henry Rzepa (mailto:rzepa@ic.ac.uk)


News | XML in Industry | Calendar | XML Registry
Marketplace | Resources | MyXML.org | Sponsors | Privacy Statement

Copyright 2001 XML.org. This site is hosted by OASIS