Security Issues with Open Safe Files

Call it a feature or a convenience, I call it dangerous. Safari will automatically open any downloaded file such as a zip file or disk image. Theoretically, it checks if it is a signed file and thus “safe.” 1) I'm not comfortable with this because it can be used in exploits, usually a social engineered exploit.

Instead of opening automatically, I want the download to be saved and I will determine if I want to open it or not. Thus I turn this feature off in Safari>Preferences>General and uncheck the “Open safe files after downloading.”

security_issue_with_open_safe_files.txt · Last modified: 2010/02/19 17:01 (external edit)