On TechRepublic: Who lies the most on resumes?
BNET Business Network:
BNET
TechRepublic
ZDNet

May 8th, 2008

Microsoft shares more IE8 security details

Posted by Mary Jo Foley @ 5:12 pm

Categories: Corporate strategy, Security, Internet Explorer

Tags: Security, ActiveX Control, Microsoft Internet Explorer, Microsoft Corp., Beta 2, Web Browsers, ActiveX/COM/COM+/DCOM, Internet, Software Development, Software/Web Development

When Microsoft officials released a first test build of Internet Explorer (IE) 8 back in March, they said they were intentionally refraining from talking specifics about new security features and functionality that would be part of the next browser release.

In the past few weeks, however, Microsoft has started providing more IE 8 security information via postings to the IE Blog.

This week, Internet Explorer Program Manager Matthew David Crowley blogged about the changes Microsoft is making around ActiveX controls with the next release of its browser. Specifically, IE 8 users running on Vista will allow “standard” users to install ActiveX controls in their own user profile without requiring administrative privileges. Crowley explained:

“This improvement makes it easier for an organization to realize the full benefit of User Account Control by enabling standard users to install ActiveX controls used in their day-to-day browsing.

“If a user happens to install a malicious ActiveX control, the overall system will be unaffected, as the control was installed only under the user’s account. Since installations can be restricted to a user profile, the risk and cost of compromise (and, in turn, the total cost of administering users on a machine) will be lowered significantly.”

In April, IE team members blogged about another security change Microsoft is instituting with IE 8. Microsoft will enable DEP/NX (Data Execution Prevention/No Execute) by default in IE 8 on Vista and Windows Server 2008. In IE7, DEP/NX is off by default — in order to avoid compatibility issues. But by turning on DEP/NX, Microsoft is expecting it will lessen the number of browser-based security hacks.

Microsoft released a public Beta 1 of IE 8 on March 5. Beta 2 is due out this summer. Microsoft still has yet to say when the final IE 8 release will be out.

Mary Jo has covered the tech industry for more than 20 years. Don't miss a single post. Subscribe via Email or RSS. Got a tip? Send Mary Jo your rants, rumors, tips and tattles. For disclosure on Mary Jo's industry affiliations, click here.
  • Talkback
  • Most Recent of 2 Talkback(s)
Agreed
Kind of far enough along in the OS evolution that to have products which are DEP-unaware amounts to purposely sloppy code.... (Read the rest)
Posted by: croberts Posted on: 05/09/08 You are currently: Logged In | Log out
DEP is a great idea CobraA1   | 05/08/08
Agreed croberts   | 05/09/08

What do you think?

No Trackbacks Yet

The URI to TrackBack this entry is:
http://blogs.zdnet.com/microsoft/wp-trackback.php?p=1386

advertisement

Order Microsoft 2.0

Pre-order Microsoft 2.0

Order 'Microsoft 2.0' by Mary Jo Foley at Amazon.com.

Recent Entries

advertisement

Archives

ZDNet Blogs

All-in-One Printers

advertisement
Click Here