ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit

Microsoft outlines IE7 security plans

Graeme Wearden ZDNet.co.uk

Published: 27 Oct 2005 14:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is tightening up the way its Internet Explorer browser (IE) handles HTTPS for version 7, which is used to secure online transactions, in an attempt to give users more protection online.

In a posting on The Microsoft Internet Explorer blog, IE programme manager Eric Lawrence said that IE7 would support the Transport Layer Security protocol (TLS) by default.

Existing versions of IE automatically use the SSL 2.0 protocol, which is weaker than TLS, to encrypt user data, although it is possible to manually switch to TLS.

Microsoft's decision to ditch support for SSL 2.0 means that any site that still requires this protocol should upgrade, but Lawrence claimed there are "only a handful" of such sites.

Lawrence also explained how IE7 will behave differently from earlier versions when it encounters potential security problems.

"Whenever IE6 encountered a problem with a HTTPS-delivered webpage, the user was informed via a modal dialog box and was asked to make a security decision. IE7 follows the XPSP2 "secure by default" paradigm by defaulting to the secure behaviour," said Lawrence.

IE7 will not give users the option of seeing both secure and insecure items within an https page. With IE6, this option appears when the browser encounters an https page that includes some http content. But in IE7, only the secure content will be rendered by default, forcing the user to choose to access the rest via the information bar.

"This is an important change because very few users (or web developers) fully understand the security risks of rendering HTTP-delivered content within a HTTPS page," Lawrence claimed.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
59 out of 160 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Jnr Fix Protocol Contractor - London - Finance

Jnr Fix Protocol Contractor - London - Finance A financial institution in the centre of London is seeking a fix protocol engineer to join thier team. ...

Development Manager C/Embedded/Protocol Stacks Leeds

Superb Leeds based permanent opportunity for a Development Manager with an Embedded Engineering background to join a European market-leader in its ...

Fix Protocol Analyst - Contract - London City & NY

Fix Protocol Analyst - Contract - London City & NY A contract role with a consultancy within a financial institution. The successful candidate will ...

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.

Featured Talkback

if the OLPC winds up as a vehicle to create a dependence on Windows for millions of poor people, the net effect for humanity will be negative. What makes it good is if it leads the users to freedom through free, freedom-respecting software.

By: mattlee

Read full story:
Negroponte: Windows key to OLPC philosophy