I'm not surprised they say

I'm not surprised they say they've found security holes in Windows Media Player skins. I did one of the first skins Microsoft commissioned for Player 7, and the potential for those things is remarkable. Basically, anything you can do with a local, scripted, web page is open to the developer.

That being said, the default settings on most people's browsers prevent these kinds of exploits. And I'm really tired of this George Guninski guy making a name for himself by "discovering" these "vulnerabilities". Being able to run signed code was a design decision Microsoft made. I understand why people object to that decision, those opinions are legitimate and there are platforms that make other decisions in those regards.

But there are problems with the constant teeth-gnashing and hand-wringing over the handling of unsigned code on Windows/IE machines. First, people blindly click "OK" and "Run" on every goddamn thing they see. If they get a program from a stranger, set their security settings to let any random program run, (and they do have to set them, it's not the default) and then decide to run a program that screws up their machine, what should be the result? I say they should be fucked. A little judgemental and perhaps overly Darwinistic, but those are fundamental flaws of my character, and I'm happy with them.

I know, I know, I'm blaming the victim and what about people who don't know any better and blah, blah, blah. But believe me, there are so many warnings you have to click through, a user has to have made at least three separate decisions to exceed their level of knowledge and keep pushing towards their own destruction before anything bad will happen. I see it as a decision akin to smoking; If they want to kill themselves, go ahead as long as they don't affect me.

Which brings me to the second, bigger point. The George Guninskis of the world, with their sky-is-falling alarmist security announcements punish advanced users by pretending that these are big dangers for home users, and then I lose things like the ability to get to a goddamn program that someone emails me.

So the hell with you, George. I mean that in the nicest possible way.

I'm Anil Dash, and I've been blogging here since 1999, writing about how culture is made. Contact me at anil@dashes.com, at +1 646 833 8659, or at anildash on Twitter or IM. Find out more »

If you're new to the site, check out my Best Of and Most Popular things I've written in the past 10 years, or explore the full archives. Browse by month or year using the calendar below.

Powered by Hunch.com

1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009
  Jan Jan Jan Jan Jan Jan Jan Jan Jan Jan
  Feb Feb Feb Feb Feb Feb Feb Feb Feb Feb
  Mar Mar Mar Mar Mar Mar Mar Mar Mar Mar
  Apr Apr Apr Apr Apr Apr Apr Apr Apr Apr
  May May May May May May May May May May
  Jun Jun Jun Jun Jun Jun Jun Jun Jun Jun
Jul Jul Jul Jul Jul Jul Jul Jul Jul Jul Jul
Aug Aug Aug Aug Aug Aug Aug Aug Aug Aug Aug
Sep Sep Sep Sep Sep Sep Sep Sep Sep Sep Sep
Oct Oct Oct Oct Oct Oct Oct Oct Oct Oct Oct
Nov Nov Nov Nov Nov Nov Nov Nov Nov Nov Nov
Dec Dec Dec Dec Dec Dec Dec Dec Dec Dec