The Economist's Screen Saver creates a huge security hole
4 Jun. 1999
Summary
The Economist newspaper provides its readers with a free screen saver that can download cover story news from The Economist's web site and show it while the user's screen saver is active. Since this screen saver is not integrated with Windows NT's security, it opens a big security hole that allows anyone with physical access to the machine unlimited access without knowing the screensaver password.
When the Economist screen saver is active, it is possible to launch Internet Explorer (Running under SYSTEM security context). From this point it is trivial to browse the network and open files, excel spreadsheets, word documents, or anything else on the local computer and network neighborhood.
After all this, the status of the screen saver remains unchanged - making it almost impossible to know whether someone accessed your computer while you weren't at you desk.
This has been verified on NT Workstation 4.0 SP5 with IE5, but probably affects all Windows versions.