Understood - but I'm not sure how many exist. Our solution is to make it very hard for the non-privileged user to install anything that can be used for privilege escalation. For us, the network aspect isn't often a factor there.
OK, remember, I'm not using windoze. But the "popular" Linux distributions are somewhat similar. The last version of Red Hat Linux offered the user the following install options (straight out of the RELEASE-NOTES for fc3):
- Custom Installation (Minimal): 620MB * Server: 1.1GB * Personal Desktop: 2.3GB * Workstation: 3.0GB * Custom Installation (Everything): 6.9GB
You wanna guess what the average newbie installs? You got it!
One very simple solution is to not install that applications as network enabled, and then offer a switch function to allow the application to be usable over the local network only. This could be handled by a crude firewall, or even by setting TTL to 1, as is already a requirement of the Link-Local (zero-conf) network setup.
Despite the posturing by microsoft, security doesn't sell very well, whether in computers, cars, or food items. The average computer user doesn't know what he wants. The average user wants fries with that, if prompted. But then, in the overwhelming majority of cases, the average computer user doesn't know what a computer is doing, and doesn't want to know.
Old guy