Slashdot Mirror


Brian Hook on the ActiveX Experience

Obiwan Kenobi writes "Brian Hook of id software fame got around to developing on ActiveX and found some minor grievances, particularly in the security department. To quote: "I've been doing some ActiveX coding on the side for a couple days, stuff I'm not familiar with, and I'm just flat out _appalled_ at how bad that entire API and design is. I can make an OCX that basically formats your hard drive, stick it on a Web page with a tag, and if your security settings are set low enough, you'll start formatting your hard drive the minute you visit my Web page.""

4 of 523 comments (clear)

  1. Re:Gee, that's news... by Assmasher · · Score: 0, Flamebait

    Exactly. :)

    You should visit his site (ensure you have high security if using IE, lol) and see some of the stupid things he says.

    I always assumed that he was really sharp.

    --
    Loading...
  2. Closed source = safe...I think. by astebbin · · Score: 0, Flamebait

    Well, don't worry everyone, I am sure that ActiveX isn't nearly as bad as Brian described it... after all, it's just another fine Microsoft product. Plus, since it's closed source, none of those mean nasty hackers will be able to open it up and use it to blow up your computer....right? What, you mean that isn't true?!? Closed source is insecure?!? And Bill Gates isn't a supporter of free net culture deep down inside?

    The truth can be a bitter pill to swallow... :)

  3. Nothing useful from old troll, GeckoX by twitter · · Score: 0, Flamebait
    First off, none of the issues he cites are in any way new, these problems are old hat. ... The guys just now digging into ActiveX and has decided flat out that MFC is the way to do it? Strike 1, and strike 2. Not immediately dropping it and moving on to something more suitable, you're out man.

    Great apology, GeckoX. Would you mind telling us how using ATL would help and why those mechanisms have not been put back into MFC? The problem is seven years old because Microsoft did a bad job seven years ago and has not fixed it yet.

    It's all too obvious that this article was posted because it fits the anti-MS slant quite well. ... this article brings absolutely NOTHING to the table except another excuse to bash MS and an OLD MS technology.

    Once again, enlighten us, GeckoX. What nasty piece of crap does Microsoft have to replace this old nasty? Tell us the wonders of .NET single sign on or something.

    The author has done a service to people contemplating this kind of work. The neophyte designer should know the general reputation of the players involved and that comes from looking at old stuff too, especially if it's currently used. People in the past have been suckered by M$'s huge PR budget, which includes astroturfing of discussion forums.

    Gecko, the name rings a bell. Let's look at what we find in your posting history. Oh yes, lots of M$ apologizing and insult for Slashdot readers:

    1. Here you are telling me I'm stupid for not wanting to pay MP3 fees. Must be why your name rings a bell.
    2. Here he acts as if you can audit DiBold's paperless and hoplessly insecure M$ based voting machines. This kind of undermines trust in GeckoX security advice if telling us that ActiveX could be used was not bad enough.
    3. The idea being that a happy geek is a productive geek, but the problem of course was that no geek could ever truly be happy as they can never hope to bag a spouse, let alone get laid and have kids.. Nice insult, your sense of humor on April first is different to say the least.
    4. Here he is telling us .NET and C# are the tools for the job. He must mean every job, but mono is impossible. He must have enjoyed the chance to beg for M$ compatibility, swipe at a free project and say M$ rocks all in one thread.
    5. Bash Java this seems to be a consistent thread. Praise M$ efforts, bash others at the same thing.
    6. Claiming Microsoft invented Virtual Desktops and Pagers, give me a break.
    7. Open Source is not secure, he tells us, as if OpenBSD did not exist.
    8. Of course IIS is wonderful. I suppose that's why banks using it upload trojans to IE users.

    It's easy to find junk like this from GeckoX using a Google search, geckox slashdot. Thanks for playing.

    --

    Friends don't help friends install M$ junk.

    1. Re:Nothing useful from old troll, GeckoX by hfis · · Score: 0, Flamebait

      You're a fucking faggot.