<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Excel security flaws out in the open</title>
	<atom:link href="http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/</link>
	<description>Daily posts of Excel tips…and other stuff</description>
	<lastBuildDate>Wed, 08 Feb 2012 23:58:05 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Dick Kusleika</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30307</link>
		<dc:creator>Dick Kusleika</dc:creator>
		<pubDate>Sat, 02 Feb 2008 02:54:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30307</guid>
		<description>&lt;p&gt;You may discuss boobs on this forum only if from a medical perspective, and then only if you refer to them as bazangas.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You may discuss boobs on this forum only if from a medical perspective, and then only if you refer to them as bazangas.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Thomlinson</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30304</link>
		<dc:creator>Jim Thomlinson</dc:creator>
		<pubDate>Sat, 02 Feb 2008 00:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30304</guid>
		<description>&lt;p&gt;If you want secure there is only one sure method. Locate the button labeled 1/0 and (firmly but gently)... press. In ten seconds or less you will be secure. Other than that it seems to me that common sense is one of the best defences.&lt;/p&gt;
&lt;p&gt;Keep your anit-virus up to date. Don&#039;t open anything to do with Viagra or big boob (can you say boobs on this forum). Is someone who never sends you  jokes suddenly send you a joke... the joke&#039;s not funny... its a virus. If someone needs you to look at something urgently, but nothing they ever do is urgent... it&#039;s not urgent... it&#039;s a virus. Finally most of the people who want your e-mail address have no interest in talking to you about anything you care about. Give them your hotmail account and then never check that account.&lt;/p&gt;
&lt;p&gt;My final caution. If you buy something from a store and they want to know your address, find out if they make housecalls to fix whatever it is you just bought. If the answer is no, then they don&#039;t need your address.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>If you want secure there is only one sure method. Locate the button labeled 1/0 and (firmly but gently)&#8230; press. In ten seconds or less you will be secure. Other than that it seems to me that common sense is one of the best defences.</p>
<p>Keep your anit-virus up to date. Don&#8217;t open anything to do with Viagra or big boob (can you say boobs on this forum). Is someone who never sends you  jokes suddenly send you a joke&#8230; the joke&#8217;s not funny&#8230; its a virus. If someone needs you to look at something urgently, but nothing they ever do is urgent&#8230; it&#8217;s not urgent&#8230; it&#8217;s a virus. Finally most of the people who want your e-mail address have no interest in talking to you about anything you care about. Give them your hotmail account and then never check that account.</p>
<p>My final caution. If you buy something from a store and they want to know your address, find out if they make housecalls to fix whatever it is you just bought. If the answer is no, then they don&#8217;t need your address.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Murphy</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30264</link>
		<dc:creator>Simon Murphy</dc:creator>
		<pubDate>Fri, 01 Feb 2008 02:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30264</guid>
		<description>&lt;p&gt;I&#039;m with Jon, so much of this &#039;security&#039; fluff is a pure powerplay, by people who think their job it is to stop everyone else working.&lt;/p&gt;
&lt;p&gt;Bear in mind that many of these security issues are not macro driven, they are carefully corrupted .xls (and other) files that will upset Excel when it tries to open them. They may not contain any macros at all.&lt;/p&gt;
&lt;p&gt;&#039;treat like porn...&#039;, If they were treated like porn the sys admins would have already removed them from your email, quarantined them, sent you (and the sender) a threatening email, burned them onto cd and taken them home for personal use.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I&#8217;m with Jon, so much of this &#8216;security&#8217; fluff is a pure powerplay, by people who think their job it is to stop everyone else working.</p>
<p>Bear in mind that many of these security issues are not macro driven, they are carefully corrupted .xls (and other) files that will upset Excel when it tries to open them. They may not contain any macros at all.</p>
<p>&#8216;treat like porn&#8230;&#8217;, If they were treated like porn the sys admins would have already removed them from your email, quarantined them, sent you (and the sender) a threatening email, burned them onto cd and taken them home for personal use.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Peltier</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30263</link>
		<dc:creator>Jon Peltier</dc:creator>
		<pubDate>Fri, 01 Feb 2008 02:06:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30263</guid>
		<description>&lt;p&gt;Mike said: &quot;If I treated every spreadsheet like porn, I WOULD open it up and take a gander.&quot;&lt;/p&gt;
&lt;p&gt;I&#039;m sure Mike wasn&#039;t the only one thinking this.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Mike said: &#8220;If I treated every spreadsheet like porn, I WOULD open it up and take a gander.&#8221;</p>
<p>I&#8217;m sure Mike wasn&#8217;t the only one thinking this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alderaic</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30254</link>
		<dc:creator>Alderaic</dc:creator>
		<pubDate>Thu, 31 Jan 2008 20:13:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30254</guid>
		<description>&lt;p&gt;hey you know what, if only they wanted to install a certificacte server on the network so that users could sign their documents, they would also be able to let the security settings on HIGH...&lt;/p&gt;
&lt;p&gt;guess what, it is easier to set it to low rather than installing the server and teaching the users how to register a certificate&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>hey you know what, if only they wanted to install a certificacte server on the network so that users could sign their documents, they would also be able to let the security settings on HIGH&#8230;</p>
<p>guess what, it is easier to set it to low rather than installing the server and teaching the users how to register a certificate</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Alexander</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30252</link>
		<dc:creator>Mike Alexander</dc:creator>
		<pubDate>Thu, 31 Jan 2008 19:30:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30252</guid>
		<description>&lt;p&gt;&quot;IT guys should tell end users right off the bat that if they see an unrecognizable Excel document in their inbox, they should treat it like porn -- it&#039;s not something you should be opening up at work.&quot;&lt;/p&gt;
&lt;p&gt;Most of the Excel files we work with are unrecognizable.  Besides, If I treated every spreadsheet like porn, I&#039;d WOULD open it up and take a gander.  Look at that table structure...Wowza!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>&#8220;IT guys should tell end users right off the bat that if they see an unrecognizable Excel document in their inbox, they should treat it like porn &#8212; it&#8217;s not something you should be opening up at work.&#8221;</p>
<p>Most of the Excel files we work with are unrecognizable.  Besides, If I treated every spreadsheet like porn, I&#8217;d WOULD open it up and take a gander.  Look at that table structure&#8230;Wowza!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Peltier</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30247</link>
		<dc:creator>Jon Peltier</dc:creator>
		<pubDate>Thu, 31 Jan 2008 17:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30247</guid>
		<description>&lt;p&gt;Dick -&lt;/p&gt;
&lt;p&gt;Notice that many of the quotes came from &quot;security experts&quot; that owned companies that provided security to other companies? If they can convince their clients that problems exist, they can increase their revenues. I&#039;ve been using a VM for internet access, without any AV, and the only &quot;infection&quot; I&#039;ve gotten have been so called tracking cookies. No real threats.&lt;/p&gt;
&lt;p&gt;What the IT guys fear from letting users use Excel and VBA is the loss of control over those users.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Dick -</p>
<p>Notice that many of the quotes came from &#8220;security experts&#8221; that owned companies that provided security to other companies? If they can convince their clients that problems exist, they can increase their revenues. I&#8217;ve been using a VM for internet access, without any AV, and the only &#8220;infection&#8221; I&#8217;ve gotten have been so called tracking cookies. No real threats.</p>
<p>What the IT guys fear from letting users use Excel and VBA is the loss of control over those users.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zach</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30244</link>
		<dc:creator>Zach</dc:creator>
		<pubDate>Thu, 31 Jan 2008 16:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30244</guid>
		<description>&lt;p&gt;Doco,&lt;/p&gt;
&lt;p&gt;I believe the phrase is rearranging the deck chairs on the Titanic.&lt;/p&gt;
&lt;p&gt;But I agree and disagree with you.  I think .Net is a little less susceptible to the script kiddie, but not to someone who is determined.  But, lately, those who are determined to hack are those looking to make money out of it.  I don&#039;t know if that&#039;s something they&#039;re going to get out of an Excel attack.&lt;/p&gt;
&lt;p&gt;I don&#039;t know how easily OO can be targeted with Python code so I can&#039;t comment, except for that the limited userbase inherently makes it more secure by being a smaller target.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Doco,</p>
<p>I believe the phrase is rearranging the deck chairs on the Titanic.</p>
<p>But I agree and disagree with you.  I think .Net is a little less susceptible to the script kiddie, but not to someone who is determined.  But, lately, those who are determined to hack are those looking to make money out of it.  I don&#8217;t know if that&#8217;s something they&#8217;re going to get out of an Excel attack.</p>
<p>I don&#8217;t know how easily OO can be targeted with Python code so I can&#8217;t comment, except for that the limited userbase inherently makes it more secure by being a smaller target.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: doco</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30240</link>
		<dc:creator>doco</dc:creator>
		<pubDate>Thu, 31 Jan 2008 15:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30240</guid>
		<description>&lt;p&gt;What would VBA be replaced with and what would make that replacement any more effective than changing seats on the Titanic? Is .NET any less suseptable to black, gray or white hat hackers? I doubt it.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>What would VBA be replaced with and what would make that replacement any more effective than changing seats on the Titanic? Is .NET any less suseptable to black, gray or white hat hackers? I doubt it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dick Kusleika</title>
		<link>http://www.dailydoseofexcel.com/archives/2008/01/30/excel-security-flaws-out-in-the-open/#comment-30235</link>
		<dc:creator>Dick Kusleika</dc:creator>
		<pubDate>Thu, 31 Jan 2008 15:03:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.dailydoseofexcel.com/?p=1802#comment-30235</guid>
		<description>&lt;blockquote&gt;&lt;p&gt;&quot;The increase in attacks in Excel are numerous and the application seems to be at the forefront of ushering in frequent application-level attacks that we&#039;re seeing more of now than ever,&quot;&lt;/p&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;The forefront?  How many people did award-winning journalist Jabulani Leffall have to interview before he founds someone with just the right amount of hyperbole?&lt;/p&gt;&lt;/blockquote&gt;
</description>
		<content:encoded><![CDATA[<blockquote><p>&#8220;The increase in attacks in Excel are numerous and the application seems to be at the forefront of ushering in frequent application-level attacks that we&#8217;re seeing more of now than ever,&#8221;</p>
</blockquote>
<blockquote>
<p>The forefront?  How many people did award-winning journalist Jabulani Leffall have to interview before he founds someone with just the right amount of hyperbole?</p>
</blockquote>
]]></content:encoded>
	</item>
</channel>
</rss>

