




Hard to believe it, but in the Mac version of MS Office 2008, Microsoft have managed to make TWO pretty bit errors with the installation - both of which are security flaws.
Go Microsoft!
First one. Every Mac file has an owner (pretty much like all other OSes, really, including Windows). Each owner has a number called a User ID (UID) which the computer uses to track who is who.
On the Mac, UID 501 is the first account you create. UID 502 is the second, and so on.
When software is installed, it should either be owned by the UID of the person installing it, or by the system. That way, either the person installing it can control it, or the system administrator can, depending on how you want to do it.
Secure and simple. Easy to do, hard to get wrong, right?
Well, if you are MS, WRONG.
In their infinite wisdom, MS decided to make ALL files in your MS Office 2008 Mac installation owned by UID 502!
This means if you have more than one account on your Mac, the second account has full control over the Office installation, regardless of who installed it. BAD idea.
If you have only one account, then even you have no control over the files as you don't own them.
WTF were MS thinking about?
Do they not bother with things like sanity checks or security audits before releasing things?!
Second flaw.
EVERY single file in the Office 2008 installation is made executable (has the executable flag set)!
BOG no-no.
Yet in their infinite wisdom, MS decided that was a good idea.
WTF? On what planet is it a good idea to make your product less secure?!
There is a way to fix bug 1 (http://www.macworld.com/article/131822/ ... ssues.html has the details) so if you are unfortunate enough to have MS Office 2008 on your Mac, you might want to fix it via that link.
There is no current fix for bug 2 - MS claim to be working on it.
Alternatively you could just get rid of Office and go for iWork08 or OpenOffice, neither of which have the security bugs MS and implemented.
But come on. What the fuck were MS thinking?
TWO security flaws in the installation?
Makes you wonder about the quality of the rest of their stuff, it really does














Return to Life, the Universe and Everything
Users browsing this forum: No registered users and 0 guests