Scary .desktop behaviour

Sebastien Bacher seb128 at canonical.com
Tue Jan 4 07:58:06 CST 2005


Le mardi 04 janvier 2005 à 14:35 +0100, Julien Olivier a écrit :

> As I understand it, .desktop files are the only ones that can be sent
> attached in an email and executed right after being downloaded without
> any manipulation (apart from right-clicking it).

In which software ? In my evolution I can only save the file.


>  More over, as
> the .desktop file appears in Nautilus as "GoodDocument.doc" instead of
> "GoodDocument.doc.desktop", it is easy to make users believe that it is
> *not* executable while it is.

It appears according to the name set in the desktop file ...


> IMHO, this problem is a critical security issue, even if it can only
> affect the user's files (which are often the most important ones).

I got the point any suggestion to improve that ? I've no real idea of
what could be better than the actual system.


Cheers,

Sebastien Bacher





More information about the ubuntu-devel mailing list