Microsoft.com Home
|
Site Map
MSDN Home
|
Developer Centers
|
MSDN Flash
|
Subscribers
Blogs Home
Sign in
|
Join
Search
RSS
OPML
Code/Tea/Etc...
Duncan Mackenzie has too much time on his hands
My ClickOnce chapter is up on the web
View in on the
vbasic
Developer Center...
Published Monday, October 27, 2003 9:49 PM by
Duncanma
Filed under:
.NET General
Comments
James Knowles
said:
Very Cool chapter ;-) Had some really interesting deployment options. We had to write our component to do the same stuff but ClickOnce will hopefully get rid of us supporting and developing that.
James
October 28, 2003 10:16 AM
Josh Hulbert
said:
Very cool. I am looking forward to playing with this!
October 28, 2003 11:58 AM
Kevin Hsu
said:
Duncan,
I went to the PDC and attended the ClickOnce team's presentations on this, and found your information just as informative. However, my question to you is the same as the question I presented them:
How much worse does ClickOnce make social engineering attacks and popup ads?
Because ClickOnce applications are full-fledged OS windows with the full range of .NET WinForm controls, it is really easy to spoof a pixel-perfect Windows dialog that asks the unsuspecting user for valuable information. For example, I was able to code a ClickOnce form that looks exactly like a .NET Passport wizard dialog.
Also, the ability for popup ads to appear and stay on your desktop is magnified dramatically. A WinForm can easily be coded to not ever close until the process is killed (which is hard for Mom and Dad to manage). Furthermore, WinForms can spawn as many other WinForms at any time interval it wants.
I feel the ClickOnce team's response of "well, we're not making the Web any less secure" simply unacceptable. It is significantly worse now because users now have no power to differentiate between local, trusted UI and remote, untrusted UI.
What are your thoughts on this?
kevhsu@msn.com
November 1, 2003 12:56 AM
Anonymous comments are disabled
This Blog
Home
Email
Links
Syndication
RSS 2.0
Atom 1.0
Recent Posts
This blog has moved... notice #2...
This blog has moved...
Has anyone tried migrating posts from weblogs.asp.net to another .Text installation?
Wes Haggard discusses the new iterators in C# 2.0
The email I get...
Tags
.NET General
CSharp Featured Team Posts
Digital Music and Media
Personal Musings
TechEd
Visual Basic
Visual C#
News
This blog has moved to
my own VB site
Archives
September 2004 (1)
August 2004 (15)
July 2004 (26)
June 2004 (38)
May 2004 (34)
April 2004 (35)
March 2004 (33)
February 2004 (29)
January 2004 (23)
December 2003 (9)
November 2003 (46)
October 2003 (34)
September 2003 (13)
August 2003 (5)
July 2003 (13)
June 2003 (14)
May 2003 (22)
April 2003 (15)
March 2003 (23)
February 2003 (9)
Manage Your Profile
|
Legal
|
Contact Us
|
MSDN Flash Newsletter
© 2009 Microsoft Corporation. All rights reserved.
Terms of Use
|
Trademarks
|
Privacy Statement