I mean... You have to explicitly hit "open", and it requires you to do so? This is like saying email has a vulnerability because it lets* me open files sent there?
Starts getting into demarcation land at that point, because the OS defines what files are opened in which program. Just saving makes sense as a compromise though!
Right, but they could define a special behaviour so it doesn't immediately run a script you click on. It is kinda your fault if you get got by this, but it would be a bit more secure with mitigations in place.
5 Comments
bravesilvernest@lemmy.ml · 15 pts · 2y
I mean... You have to explicitly hit "open", and it requires you to do so? This is like saying email has a vulnerability because it lets* me open files sent there?
I get what they are after, but this is a stretch.
ZarkleFarkle@sh.itjust.works · 3 pts · 2y
I guess preferably they'd just be saved and/or opened in a text editor, rather than ran on your computer
bravesilvernest@lemmy.ml · 3 pts · 2y
Starts getting into demarcation land at that point, because the OS defines what files are opened in which program. Just saving makes sense as a compromise though!
ZarkleFarkle@sh.itjust.works · 3 pts · 2y
Right, but they could define a special behaviour so it doesn't immediately run a script you click on. It is kinda your fault if you get got by this, but it would be a bit more secure with mitigations in place.
Sh0ckw4ve@lemmy.world · 6 pts · 2y
Haha jokes on them, it won't even let me install their apps on Windows