MS Will Sandbox, Not Patch, Office 2010 Vulnerabilities
Microsoft has a reputation for rarely admitting or accepting defeat in any market. But the company is now waving the white flag of surrender after admitting that they can no longer keep up with hackers when discovering file format bugs in time to stop them from exploitation.
That doesn't mean that Microsoft is prepared to let online deviants have their way with software vulnerabilities. Instead, the company has decided to take a "sandbox" approach to Office documents in the next version of the application suite.
The Sandbox Technique
The sandbox technique will be a new addition to Office 2010 and will feature a "Protected View" setting that isolates Word, Excel and PowerPoint files in a read-only environment. Sandboxing gives minimal access to the rest of the computer and offers zero access to other documents and personal information.
The logic behind this system is that even if a document is suspicious (and later rendered malicious) it is essentially "trapped" inside of a virtual sandbox so that it can do no harm to any other files outside of that particular document.
Hackers Fuzz, Microsoft Chases
A number of security analysts believe that hackers have been using "fuzzing" measures to retrieve personal information and infect computers worldwide. Fuzzing is a tactic that relies on automated tools that drop random data into applications to see if, and where, vulnerabilities exist. (Source: computerworld.com)
The whole practice of fuzzing has led Microsoft on an 18-month wild goose chase that has reportedly created more frustration than success.
The sandbox technique is just one of a few new security measures embedded into Office 2010. Other safety features include a more flexible file blocker and "Office File Validation," a practice that was rolled out in Publisher 2007 Service Pack 2 (SP2).
Two More Security Features
The file blocker restricts access to specified document types. Microsoft announced that Office 2010 will let users customize this feature to better manage which formats Word, Excel and PowerPoint open.
Office File Validation, on the other hand, is a system that validates older, pre-XML file formats for Word, Excel and PowerPoint, then blocks those files that do not conform to the documented format. The idea here is that malicious documents would trigger a block from the onset, while the new sandbox feature would then activate and take over from there. (Source: cio.com)
Microsoft promised that the new security features offered in Office 2010 will have very little impact on the document load time. However, there is always the chance that the system requirements may impact the computer's memory and processor resources during future startups.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.