[Coco] Big Security Issue

coco at jechar.ca coco at jechar.ca
Fri May 26 21:37:31 EDT 2023


All Coco list users.

Google has made an extremely STUPID mistake that effects everyone's
security. The following youtube video describes the problem.

  https://www.youtube.com/watch?v=V82lHNsSPww

As a result I would suggest that anyone who has a site with a zip file 
on it rename the zip file for example any file named

f i l e . z i p  ( I have added extra spaces here for safety )

should rename there file to file.zipfile the coco archive should requite 
all
zip files to be uploaded with a .zipfile extension instead and all 
existing zip files in the archive should be renamed from zip to zipfile 
the user can then
download the file with zipfile extension and rename it's extension to 
zip locally for unpacking maybe someone will want to create a version of 
unzip that can directly unpack a file with a name like x.zipfile

Hate to be barer of bad news but looks like we all have a headache to 
deal with thanks to Google's stupidly or greed and ICAN's dereliction of 
duty. I hope someone gets together a Class action suit against them.

Charlie

In particular


More information about the Coco mailing list