IE7 to Beef Up Secure Web Surfing

By Ed Oswald | Published October 25, 2005, 11:50 AM

Internet Explorer 7 will come with several security enhancements to HTTPS connections, a Microsoft program manager said on the IE Blog over the weekend. Chief among the changes is the disabling of the SSLv2 protocol by default in favor of the stronger-encryption available through TSLv1.

"Generally, IE users will not notice any difference in the user-experience due to this change; it's a silent improvement in security," program manager Eric Lawrence wrote. He said that few sites still require SSLv2, and upgrading to SSLv3 or TSLv1 is generally a simple migration on most sites.

Also, when dealing with secure sites whose certificates are not valid, IE7 by default will err on the side of caution and block access much like Windows XP Service Pack 2 already does. A certificate that was either issued to a different hostname than the one visited, issued by an untrusted root, or was revoked or expired would trigger such an event.

Lawrence added that Windows Vista will take the enhancements in IE7 even further, with stronger encryption and tighter security certificate policies.

The Internet Explorer development team has also issued a call for action to ensure secure sites are offering users the highest encryption available and that their security certificates are valid.

"If your site supports TLS, please ensure that it has a standards-compliant implementation of TLS that does not fail when extensions are present. Testing for a non-compliant TLS server is as simple as navigating to any HTTPS page on the server using IE7 on Vista Beta 2," Lawrence wrote.

"Thanks for your help in securing the Web."

Comments

View comments by with a score of at least

Here we go again with IE and security. Give me a break. This will be just another rushed product by MS to compete with FF and Opera. Enough with the crap MS

http://www.illmethinks.com

Score: 0

|

That's why I'm hoping to push MS in the true direction and physically destroy the opposition. Then it can make a small side company under a new name to avoid charges against monopoly.

Score: 0

|

It's not the monopoly. Windows. Internet Explorer. Media Player. All full of bugs. Full of wholes. Full of rubish that we don't want or need. (If I want a media player, I will download one... one shouldn't be included. I think a browser should be included. But not one of that is a "feature packed" as IE)

Score: 0

|

Just the old pattern-merchants in the open again.

"Windows is even better now than ever before."

Isn't this sentence - in one or the other shape - the one that you can watch onscreen installing EVERY Windows OS since 3.0 ? ? ?

Now they shout:

"Vista will take the enhancements in IE7 even further, with stronger encryption and tighter security certificate policies".

! W O W !

Then they "beg" people:

"If your site supports TLS, please ensure that it has a standards-compliant implementation of TLS that does not fail when extensions are present. Testing for a non-compliant TLS server is as simple as navigating to any HTTPS page on the server using IE7 on Vista Beta 2"

They even thank those who comply with their requests! What a courtesy!

In reality this will be the next standard in this whole world of computing.

That's how they do it - everywhere. Not only MS.

And:

- NO - I DO NOT HATE ANYBODY.

Just the old pattern-merchants in the open again...

Score: 0

|

dlowell,

Please stop spamming and making people to convert to Firefox.

Back on topic, this sounds like good news... if MS follow through. Also, keep in mind they've already seat this many times... not like it is new or anything.

Score: 0

|

www.getfirefox.com www.opera.com www.stopie.com

Score: 0

|

IMPORTANT NEWS!!!!!!!!!!
!!!READ THIS IMPORTANT ANNOUNCEMENT!!!

MICROSOFT TODAY RELEASED AN OFFICAL PATCH TO FIX ALL OF INTERNET EXPLORER'S PROBLEMS

HERE IS THE DOWNLOAD LINK:
http://download.mozilla....p;os=win&lang=en-US
-BETANEWS ADMIN

Score: 0

|

I don't think the BN admins will appreciate you impersonating them.

Score: 0

|

I agree, and you do a horrible job. Capitals? The hell with you, witch, get off my internet.

Score: 0

|

Come on guys ff isnt all that great, it's a good one but so is ie and opera and maxthon, give ie 7 a chance then we will see.

Score: 0

|

Hope you wear flame retardant clothes, because somebody's fixin to get scorched. Agree that some people need to wait until they use the finished product before cutting it. Hey, maybe it will stink, but maybe it'll surprise some of you FF guys too. I'll definately give it a try, as I did FF and Opera...

Score: 0

|

I doubt there are many here who will refuse to try it. It is unfortunate that many who do will try it with their minds already made up, though.

It could be good, it could suck. Won't know until I see the final. I grabbed Beta 1 and was patently unimpressed.

We'll see...

Score: 0

|

It's IE. it's full of security holes. I'll wait till security sites report it as safe before using it.

Maxthon = IE. It's the engine, not the shell, that matters.

Score: 0

|

You should see the version in the new Vista beta. It's slightly different from IE7 beta 1 for XP. I think a lot of people will like it.

Score: 0

|

I have already made up my mind. I recently switched to Linux. No IE or any other Microsoft garbage. Yes I know i'm setting myself up to be flamed. All I have to say is BRING IT ON!! I'll stick to what I said come hell, highwater or Microsucks sheep.

Score: 0

|

Since it'll be bolted into Windows, I don't see how anyone that uses Windows won't use it at least once.

Instant marketshare, bleh.

Score: 0

|

Well if....IF...I decide to get Vista, I'm sure I can find a way around using IE. I may have to download a Vista compatible version of Firefox on my Linux computer and transfer it over but I'll go out of my way to keep from using IE if I have to. I hate IE.

Score: 0

|

Firefox also has security holes.

BTW, IE7 beta has been out for a while but I still didn't see any security warning or whatsoever. Microsoft must have done something right.

Score: 0

|

It wasn't a public beta.

Score: 0

|

Security holes are usualy fixed within a day or something with FF. and it doesn't have as many

It's that damn ActiveX that's the main problem. Sure, AX has it's uses (Yahoo Toolbar, Windows update,etc)... but it's also a weakness (spyware)

Score: 0

|

Microsoft, come back. You beat the fruit originally; let's get it right this time around. If you fail, you fail me. Then I will s***, all over, your g**d*** porches.

Score: 0

|

roflmao...

*sniff*

*wipes eyes*

GOD, THAT WAS GOOD.

Thanks, man.

Score: 0

|

First point, its TLS 1.0, not TSL 1.0 as the report at BetaNews indicate.

Second, this news is simply a defensive measure, since Mozilla Firefox is already making plans to drop SSL v.2 support and instead support the built-in SSL 3.0 and TLS 1.0 protocols:
http://www.mozillazine.o...kback.html?article=7252

Score: 0

|

Firefox 1.5 Beta 2, already has TLS 1.0 and SSl 3.0 support, but still supports SSL 2.0 as of right now. They may drop it by the final release. Micro$oft's IE will always be many steps behind firefox, sorry Micro$oft.

Score: 0

|

Am I too late for the FF/IE flamewar?

Score: 0

|

I think it's just getting started. I do love these friendly discussions though.

Score: 0

|

I'm suiprised no-one flamed me for not mentioning Opera.

Score: 0

|

Don't forget ad muncher.

Score: 0

|

Now you've gone and done it. There'll be much screaming and yelling now, all because you had to bring up the whole greasemonkey, Adblock, admuncher debate again.

I hope you realize what you've done. I hope it haunts you for the rest of your days. I hope you endure even only half as much pain and anguish as such topics have brought to others you..you...

...insensitive clod!

:P

I'm bored. Just warning ya. ;)

Score: 0

|

What are you on about? :P

And it's going to be a FF/O/IE war :P

Score: 0

|

hmmm... don't know what to say.

...I try? =/

While I'm at it:

Mac stinks.

(I'm joking people)

Score: 0

|

Guess i'm gonna try to get em started flaming....OPERA SUCKS!!!! Oh and while i'm at it Microsucks will be the death of us all!!!!!

Score: 0

|

DOH, I was gonna say that.

Score: 0

|

i dont think any ms browser will ever be more effective or secure than firefox, i compares FF beta 1 to IE7 beta 1. now i dont even have anything even closely related to ie on my windows xp (appart from both xp and ie being made by the same company). So for the last time, USE FF!!!!!!

and The RecklessWonder:

"Everybody who can write a better browser put their hand up.

Everybody else clam up."

no one person can be bothered to make something better than ie when theres Firefox out there, Part from that, most browsers are the efforts of large groups of people.

Score: 0

|

Everybody who can write a better browser put their hand up.

Everybody else clam up.

Score: 0

|

Did Microsoft only use one developer to write IE?

Then clam up. :-P

Score: 0

|

People who use IE are dummies, you should use Phoenix, oops i mean firebird, oops i mean firefox i think?

Score: 0

|

Your right. THat names changed too much :P

Score: 0

|

Now look man, it's called Maxthon. I mean MYIE2. I mean... something besides IE, yeah, that works. I recommend Maxthon anyway.

Score: 0

|

Idot, maxthon is IE based, its just as crappy and just as covered in holes.

Score: 0

|

Actually, more corectly stated, it's a shel that runs on top of the IE rendeing engine. Basically, it's a crutch for IE.

Score: 0

|

Well, I suppose it's a start. But I'll stick to Firefox or Opera. *forever*

Score: 0

|

yay, IE7 is gonna save the world. (sarcasm)

Score: 0

|

Anything is better than IE6, I guess. No news here.

Score: 0

|

Comcast deal for NBC Universal is about content, not broadband

Although Comcast is certainly America's largest broadband provider, at least for PCs, in most regards, today's deal with GE may not impact the Internet at all.

Mark Russinovich on MinWin, the new core of Windows

The next version of Windows three years hence will likely build onto a significant architectural change implemented in Windows 7 and Server 2008 R2.

Fee or free? Murdoch, Huffington square off over the cost of Internet news

Participants in an FTC workshop yesterday witnessed the two extremes of the Web news publishing debate, still centered on the issue of long-term profitability.

Security firm: Windows patches not responsible for 'Black Screen of Death'

On second thought, maybe that access control list thingie with the lockdown something-or-rather didn't trigger an alleged, perhaps non-existent, pandemic.

Online advertising evolves away from display, toward interactive software

Marketing departments and agencies are increasingly establishing positions for "creative technologists" who can steer designers and developers toward platforms that enable direct connections with consumers.

Google begrudgingly adjusts news crawling for paid publishers

If publishers want to make readers pay for news content, and thereby drive down its popularity and Google ranking, the company says, they can just go right on ahead.

Apple settles with Psystar except for 'circumvention devices'

The fracas with the Florida clone computer maker might have ended today had Apple not have muddled the issue over a cheap piece of Psystar software.

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.