<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Attachment Security, Part Deux</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx</link><description>Here's Part One . 
 OK
this isn't really a continuation of the history, but rather some more
rambling on some of what I discussed in part one. I just wanted an
excuse to say "Part Deux". 

 

 After the news reports about 
the first big email</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>hi-tech blog  &amp;raquo; Blog Archive   &amp;raquo; Human nature and email attachment security</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#3166642</link><pubDate>Thu, 11 Dec 2008 06:41:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3166642</guid><dc:creator>hi-tech blog  &amp;raquo; Blog Archive   &amp;raquo; Human nature and email attachment security</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://blog.hi-tech-sw.net/2008/12/11/human-nature-and-email-attachment-security/"&gt;http://blog.hi-tech-sw.net/2008/12/11/human-nature-and-email-attachment-security/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3166642" width="1" height="1"&gt;</description></item><item><title>Human nature and email attachment security | MS Tech News</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#3142797</link><pubDate>Tue, 28 Oct 2008 01:22:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3142797</guid><dc:creator>Human nature and email attachment security | MS Tech News</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://mstechnews.info/2008/10/human-nature-and-email-attachment-security/"&gt;http://mstechnews.info/2008/10/human-nature-and-email-attachment-security/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3142797" width="1" height="1"&gt;</description></item><item><title>Human nature and email attachment security</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#3135909</link><pubDate>Mon, 13 Oct 2008 20:07:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3135909</guid><dc:creator>KC on Exchange and Outlook</dc:creator><description>&lt;p&gt;Dare's post about human nature touches on UAC in Vista: How do you design a dialog prompt to warn users&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3135909" width="1" height="1"&gt;</description></item><item><title>re: Attachment Security, Part Deux</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#406601</link><pubDate>Tue, 21 Jun 2005 05:15:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:406601</guid><dc:creator>Dean Harding</dc:creator><description>Might be a bit late to chime here, but...&lt;br&gt;&lt;br&gt;The problem (that I see) with blocking attachments by extension is that it means that ligitimate attachments which are .exe or whatever (it happens, I'll often find some cool tool on the net and forward it 'round to my team mates) means that we need to create &amp;quot;workarounds&amp;quot; like zipping the .exe first.&lt;br&gt;&lt;br&gt;But of course, that just conditions users to open a virus in Winzip and run it from there... so then you block .exe-in-.zip files, and ligitimate people have to work around /that/ and that just conditions people to..., and so on.&lt;br&gt;&lt;br&gt;It's kind of like that feature in OSX where if you run something that needs admin privileges, it pops up a dialog asking for the password.  All that does is condition people to type in their admin password all time and all it takes is someone to create a copy of that dialog in their phishing app, and away it goes!&lt;br&gt;&lt;br&gt;(By the way, I don't use OSX so maybe that dialog is just an urban legend, I don't know...)&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=406601" width="1" height="1"&gt;</description></item><item><title>Weekend reading</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#406345</link><pubDate>Tue, 14 Jun 2005 19:26:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:406345</guid><dc:creator>subject: exchange</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=406345" width="1" height="1"&gt;</description></item><item><title>re: Attachment Security, Part Deux</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#406168</link><pubDate>Fri, 10 Jun 2005 03:26:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:406168</guid><dc:creator>KC Lemson [MSFT]</dc:creator><description>Chaz: I saw on that blog that you found the new URL, sorry - I changed 'kc' to 'cynical' as I didn't want people who googled my name to find that one *first*, since they were probably looking for this one instead :-)&lt;br&gt;&lt;br&gt;Peter: In general I agree, but it's difficult to ignore ignorance in such cases :-) I totally agree in the effectiveness of simple file-extension-blocking filters, both on the client and server. When we first did the Outlook block for attachments, it seemed like such a major step, to completely block access... now it's a given.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=406168" width="1" height="1"&gt;</description></item><item><title>re: Attachment Security, Part Deux</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#406007</link><pubDate>Tue, 07 Jun 2005 12:23:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:406007</guid><dc:creator>Peter</dc:creator><description>I know you didn't write this post to rebut them, but Slashdot posters should generally be ignored.&lt;br&gt;&lt;br&gt;Nothing cures user apathy about attachments like a good virus infection.  After the owner of our company opened an unknown attachment and spread a virus throughout the network, the incidence of people doing that dropped to zero.  &lt;br&gt;&lt;br&gt;Also, a good Exchange-based attachment blocking by extension filter does wonders.  We have been protected from several new viruses before the signatures were updated just by blocking executable attachments at the gateway.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=406007" width="1" height="1"&gt;</description></item><item><title>re: Attachment Security, Part Deux</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#406002</link><pubDate>Tue, 07 Jun 2005 09:27:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:406002</guid><dc:creator>chaz</dc:creator><description>&lt;a rel="nofollow" target="_new" href="http://lemson.typepad.com/kc/"&gt;http://lemson.typepad.com/kc/&lt;/a&gt;&lt;br&gt; has been sitting in my bookmarks for a while. Also googled you and got the same url. Perhaps I'm just being a bit dim...&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=406002" width="1" height="1"&gt;</description></item><item><title>re: Attachment Security, Part Deux</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#405908</link><pubDate>Mon, 06 Jun 2005 00:00:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:405908</guid><dc:creator>KC Lemson [MSFT]</dc:creator><description>What URL are you using for typepad? I'm not having a problem.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=405908" width="1" height="1"&gt;</description></item><item><title>re: Attachment Security, Part Deux</title><link>http://blogs.technet.com/b/kclemson/archive/2005/06/04/405887.aspx#405907</link><pubDate>Sun, 05 Jun 2005 23:10:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:405907</guid><dc:creator>chaz</dc:creator><description>Good article.&lt;br&gt;&lt;br&gt;Did you know your typepad blog is down?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=405907" width="1" height="1"&gt;</description></item></channel></rss>