On BNET: How to do anything better
BNET Business Network:
BNET
TechRepublic
ZDNet

By Graeme Wearden
Posted on ZDNet News: Oct 27, 2005 11:58:00 AM

Microsoft is tightening up the way its Internet Explorer browser handles HTTPS for version 7, which is used to secure online transactions, in an attempt to give people more protection online.

In a posting on the Microsoft Internet Explorer blog, IE program manager Eric Lawrence said that IE 7 would support the Transport Layer Security (TLS) protocol by default.

Existing versions of IE automatically use the SSL 2.0 protocol, which is weaker than TLS, to encrypt user data, although it is possible to manually switch to TLS.

Microsoft's decision to ditch support for SSL 2.0 means that any site that still requires this protocol should upgrade, but Lawrence claimed there are "only a handful" of such sites.

Lawrence also explained how IE 7 will behave differently from earlier versions when it encounters potential security problems.

"Whenever IE6 encountered a problem with a HTTPS-delivered Web page, the user was informed via a modal dialog box and was asked to make a security decision. IE 7 follows the XPSP2 'secure by default' paradigm by defaulting to the secure behavior," said Lawrence.

IE 7 will not give users the option of seeing both secure and insecure items within an HTTPS page. With IE6, this option appears when the browser encounters an HTTPS page that includes some HTTP content. But in IE 7, only the secure content will be rendered by default, forcing the user to choose to access the rest via the information bar.

"This is an important change because very few users (or web developers) fully understand the security risks of rendering HTTP-delivered content within a HTTPS page," Lawrence claimed.

Graeme Wearden of ZDNet UK reported from London.

  • Talkback
  • Most Recent of 14 Talkback(s)
The lows these people can rich have no bottom...
I wont be surprised if one nice sunny day MS users wake up to the fact that MS's NT-NG is some Linux or BSD kernel and other accutraments from the OSS community...

As a matter of fact, they mu... (Read the rest)
Posted by: michael_t Posted on: 10/27/05 You are currently: Logged In as: a Guest  | Login | Terms of Use
For total Security  nucrash | 10/27/05
Microsoft outlines IE7 security plans  Loverock Davidson | 10/27/05
Uh Mike did you steal Lovey's id and password?  shallow_diver | 10/27/05
Does MS pay you by salary or per post?  K B | 10/27/05
Why would MS be paying me?  Loverock Davidson | 10/27/05
I'm happy about  Krazyken39 | 10/27/05
the roll out of this is too slow  MIS Master | 10/27/05
Microsoft Security  Doc Farmer | 10/27/05
Ther IE7 framework is very complex  michael_t | 10/27/05
you know....  Monkey_MCSE | 10/27/05
The lows these people can rich have no bottom...  michael_t | 10/27/05
Finally they are catching up?  B.O.F.H. | 10/27/05
The "NEW" MS Marketing model  toomuchgreeatea@... | 10/27/05
Copying from Firefox  ivanii | 10/27/05

What do you think?

Managed Hosting

  • If the cost of building and managing a robust technology infrastructure is prohibitive for your small or mid-sized business (SMB), managed hosting may be worth another look. For help determining whether a managed or dedicated hosting solution makes sense for your business, read this informative blog post by Josh Hoskins.
  • From our sponsors
    Smart IT Investment
    Click Here
  • Fully-managed hosted IT solutions Complete hosted solutions tailored to your needs with no capital expenditures — the smart approach to IT investment Discover no-capex IT
  • The Planet
advertisement
Click Here