Recent Posts

Community

Email Notifications

Personal Links

Archives

Harry Waldron - IT Security

Security Developments, Software Updates and Best Practices

Internet Explorer 8 Beta 2 - Will focus on security improvements

Idea Two recent ZDNet blog posts highlight forthcoming security improvements for the next beta release of IE 8.  The release to testers is planned for August.  These improvements will make IE8 a worthwhile upgrade when it is released in the future.

Internet Explorer 8 Beta 2 - Will focus on security improvements
http://blogs.zdnet.com/security/?p=1396
http://blogs.zdnet.com/Bott/?p=484

QUOTE: When Microsoft's Internet Explorer 8 hits the Beta 2 milestone in August, the browser makeover will feature a full-fledged anti-malware blocker and new protections against some forms of cross-site scripting attacks. The existing phishing filter IE 7 has been renamed SmartScreen Filter and will include blacklist-based blocking of known exploit sites.  Also new in IE 8 Beta 2 is an XSS Filter to detect Type-1 (reflection) attacks that can lead to cookie theft, keystroke logging, Web site defacement and credentials theft:

The new beta refresh will also include support for safer Web 2.0-type mashups, DEP (data execution protection) turned on by default in Windows Vista SP 1, domain highlighting to help flag phishing attacks and changes to the way ActiveX controls are handled.

Below are also an overview of security improvements found in the current beta version:

Internet Explorer 8 - Two New Security Improvements
http://www.itsecurity.com/features/ie8-security-features-032408/

QUOTE:  IE 8's security environment benefits from the addition of two major enhancements: the Safety Filter tool and the Domain Highlighting feature. Here's a closer look at both of these new enhancements.

1. Safety Filter -- IE 8 ups the ante with a new Safety Filter that analyzes the entire URL string to search for carefully hidden signs that a Web site may be something other than it claims to be. In Microsoft's words, the Safety Filter provides "a more granular detection" capability, allowing the browser to protect users from more targeted and sophisticated attacks.

2. Domain Highlighting -- IE 8's other major new security feature is a technology that highlights the top-level domain in the browser's address bar. This enhancement might not sound like much, but it is designed to provide a hard-to-miss visual clue that will function like a traffic light. The idea is to enable users to quickly confirm that the Web site they are visiting is the site that they intended to visit.