<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Edge : internet explorer</title><link>http://msmvps.com/blogs/tonybradley/archive/tags/internet+explorer/default.aspx</link><description>Tags: internet explorer</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>AutoComplete May Equal AutoCompromise</title><link>http://msmvps.com/blogs/tonybradley/archive/2007/09/18/autocomplete-may-equal-autocompromise.aspx</link><pubDate>Tue, 18 Sep 2007 15:07:28 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1204321</guid><dc:creator>Essential Computer Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/tonybradley/rsscomments.aspx?PostID=1204321</wfw:commentRss><comments>http://msmvps.com/blogs/tonybradley/archive/2007/09/18/autocomplete-may-equal-autocompromise.aspx#comments</comments><description>It is very convenient to have your various usernames and passwords stored in your computer system. When you are logging into a web site or application, the information is automatically filled in for you so you don&amp;#8217;t have to try to remember what...(&lt;a href="http://msmvps.com/blogs/tonybradley/archive/2007/09/18/autocomplete-may-equal-autocompromise.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1204321" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/microsoft/default.aspx">microsoft</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet+explorer/default.aspx">internet explorer</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/ie7/default.aspx">ie7</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/identity+theft/default.aspx">identity theft</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/breach/default.aspx">breach</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/compromise/default.aspx">compromise</category></item><item><title>Guest on IMI TechTalk Radio Show</title><link>http://msmvps.com/blogs/tonybradley/archive/2007/02/10/guest-on-imi-techtalk-radio-show.aspx</link><pubDate>Sun, 11 Feb 2007 04:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:564271</guid><dc:creator>tonybradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/tonybradley/rsscomments.aspx?PostID=564271</wfw:commentRss><comments>http://msmvps.com/blogs/tonybradley/archive/2007/02/10/guest-on-imi-techtalk-radio-show.aspx#comments</comments><description>&lt;P&gt;Tom D'Auria invited me back to talk more computer security on his IMI TechTalk radio show. I appeared on the show in &lt;A class="" title="November of 2006" href="http://techtalk.imi-us.com/Archives/2006/20061126/"&gt;November of 2006&lt;/A&gt; to promote my book, &lt;A class="" title="Essential Computer Security" href="http://www.amazon.com/gp/product/1597491144/ref=cm_arms_pdp_dp/105-2933294-6506053"&gt;Essential Computer Security&lt;/A&gt;. We did not get to cover all of our questions in the time allotted, so I will be back on the show on Sunday, February 18th. This show will focus on wireless network security, avoiding becoming a victim of a phishing attack, botnets, and the importance of backing up data. Of course, I will also promote my book again. &lt;img src="http://msmvps.com/emoticons/emotion-2.gif" alt="Big Smile" /&gt;&lt;/P&gt;
&lt;P&gt;To listen to the show, you can tune in to KFNX AM 1100, broadcast out of Phoenix, AZ, at 5pm EST on Sunday, February 18. If you aren't in the Phoenix area, you can also listen to the live simulcast of the show on the &lt;A class="" title="KFNX web site" href="http://www.1100kfnx.com/"&gt;KFNX web site&lt;/A&gt;. Or, as an alternative, you can download an MP3 recording of the entire show after the fact from the &lt;A class="" title="IMI TechTalk web site" href="http://techtalk.imi-us.com/"&gt;IMI TechTalk web site&lt;/A&gt;.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=564271" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet/default.aspx">internet</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/home+computer/default.aspx">home computer</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/microsoft/default.aspx">microsoft</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/backup/default.aspx">backup</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/restore/default.aspx">restore</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet+explorer/default.aspx">internet explorer</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/ie7/default.aspx">ie7</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/zero-day/default.aspx">zero-day</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/essential+computer+security/default.aspx">essential computer security</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/imi-techtalk/default.aspx">imi-techtalk</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/radio/default.aspx">radio</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/Tom+D_2700_Auria/default.aspx">Tom D'Auria</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/interview/default.aspx">interview</category></item><item><title>Internet Explorer Protected Mode</title><link>http://msmvps.com/blogs/tonybradley/archive/2007/02/06/internet-explorer-protected-mode.aspx</link><pubDate>Tue, 06 Feb 2007 13:33:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:548938</guid><dc:creator>tonybradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/tonybradley/rsscomments.aspx?PostID=548938</wfw:commentRss><comments>http://msmvps.com/blogs/tonybradley/archive/2007/02/06/internet-explorer-protected-mode.aspx#comments</comments><description>In Vista, Internet Explorer gets the benefit of some added security. Using WIC (Windows Integrity Control), Vista treats files and processes associated with Internet Explorer as Low integrity as long as it is running in Protected Mode. Internet Explorer Protected Mode is enabled by default and ensures that the Low integrity objects associated with Internet Explorer are unable to write to, act on, or otherwise interact with any objects higher than Low integrity- which is most of the system. For more information, you can read this article I posted on my About.com Internet / Network Security site: &lt;A class="" title="Internet Explorer Protected Mode" href="http://netsecurity.about.com/od/secureyourwindowspc/a/ieprotected.htm"&gt;Internet Explorer Protected Mode&lt;/A&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=548938" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet/default.aspx">internet</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/windows+vista/default.aspx">windows vista</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet+explorer/default.aspx">internet explorer</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/ie7/default.aspx">ie7</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/protected+mode/default.aspx">protected mode</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/object/default.aspx">object</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/mandatory+integrity+control/default.aspx">mandatory integrity control</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/trust/default.aspx">trust</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/windows+integrity+control/default.aspx">windows integrity control</category></item><item><title>Windows Integrity Control</title><link>http://msmvps.com/blogs/tonybradley/archive/2007/02/05/windows-integrity-control.aspx</link><pubDate>Mon, 05 Feb 2007 14:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:546057</guid><dc:creator>tonybradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/tonybradley/rsscomments.aspx?PostID=546057</wfw:commentRss><comments>http://msmvps.com/blogs/tonybradley/archive/2007/02/05/windows-integrity-control.aspx#comments</comments><description>With Vista, Microsoft introduced a new security concept to help protect your computer. Rather than relying on discretionary controls, like NTFS file and folder permissions which users can assign and change, Vista also has new mandatory controls. WIC, or Windows Integrity Control (also referred to as MIC, or Mandatory Integrity Control in some circles), assigns an integrity, or trustworthiness, level to each object and uses the integrity levels to control interactions between the objects. The integrity levels are assigned by the operating system and supercede, or override, the dicretionary permissions to protect the computer system. WIC is used throughout the system, but is arguably most noticeable in the Internet Explorer Protected Mode which protects the Vista operating system from malicious web content in Internet Explorer. For more details about WIC, check out this article I submitted to SecurityFocus: &lt;A class="" title="Introduction to Windows Integrity Control" href="http://www.securityfocus.com/infocus/1887"&gt;Introduction to Windows Integrity Control&lt;/A&gt;.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=546057" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet/default.aspx">internet</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/windows+vista/default.aspx">windows vista</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/microsoft/default.aspx">microsoft</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/user/default.aspx">user</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet+explorer/default.aspx">internet explorer</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/ie7/default.aspx">ie7</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/web/default.aspx">web</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/protected+mode/default.aspx">protected mode</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/wic/default.aspx">wic</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/object/default.aspx">object</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/mandatory+integrity+control/default.aspx">mandatory integrity control</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/trust/default.aspx">trust</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/windows+integrity+control/default.aspx">windows integrity control</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/mic/default.aspx">mic</category></item><item><title>IE6 Vulnerable More Than 3/4 Of 2006</title><link>http://msmvps.com/blogs/tonybradley/archive/2007/01/07/ie6-vulnerable-more-than-3-4-of-2006.aspx</link><pubDate>Sun, 07 Jan 2007 15:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:476060</guid><dc:creator>tonybradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/tonybradley/rsscomments.aspx?PostID=476060</wfw:commentRss><comments>http://msmvps.com/blogs/tonybradley/archive/2007/01/07/ie6-vulnerable-more-than-3-4-of-2006.aspx#comments</comments><description>&lt;P&gt;According to a &lt;A class="" title=study href="http://blog.washingtonpost.com/securityfix/2007/01/internet_explorer_unsafe_for_2.html"&gt;study&lt;/A&gt; compiled by the Washington Post's &lt;A class="" title="Brian Krebs" href="http://blog.washingtonpost.com/securityfix/" target=_blank&gt;Brian Krebs&lt;/A&gt;, Internet Explorer 6 was vulnerable for 284 out of 365 days in 2006. That amounts to over 77% of the year. What does that mean? It means the for 3/4 of the year there were known vulnerabilities affecting Internet Explorer 6 for which no patch existed. &lt;/P&gt;
&lt;P&gt;Some were fairly serious zero-day exploits that were being actively exploited in the wild while users waited for an update from Microsoft. Others were less serious, but were still left vulnerable, mostly due to the nature of the monthly Security Bulletin and patch release schedule that Microsoft uses. A flaw that is discovered the day after "Patch Tuesday" will most likely remain unpatched for an entire month until the next "Patch Tuesday". By contrast, Krebs found that the Firefox browser was only vulnerable for 9 days, and IE7 was too new to have any substantial data for this year's survey. &lt;/P&gt;
&lt;P&gt;The pro-Firefox, Microsoft-bashing crowd will jump all over this. You can see it in the comments on Krebs' article. I fall into the camp that believes that IE is targeted because of its market share as much as the quality of the code. Firefox or Opera may, in fact, be superior from a security standpoint, but neither is impervious and if they had 85% of the web browser market share we wouldn't be so hyper-focused on the weaknesses of Internet Explorer (and neither would the malware authors). Still, it doesn't paint a pretty picture and Microsoft should take notice and seek to rectify the issue for IE7 and for 2007. You can read Krebs' complete article here: &lt;A class="" title="Internet Explorer Unsafe for 284 Days in 2006" href="http://blog.washingtonpost.com/securityfix/2007/01/internet_explorer_unsafe_for_2.html"&gt;Internet Explorer Unsafe for 284 Days in 2006&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=476060" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet/default.aspx">internet</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/home+computer/default.aspx">home computer</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/windows+xp/default.aspx">windows xp</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/microsoft/default.aspx">microsoft</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/vulnerability/default.aspx">vulnerability</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/patch/default.aspx">patch</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/internet+explorer/default.aspx">internet explorer</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/ie7/default.aspx">ie7</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/web/default.aspx">web</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/worm/default.aspx">worm</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/hack/default.aspx">hack</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/firefox/default.aspx">firefox</category><category domain="http://msmvps.com/blogs/tonybradley/archive/tags/zero-day/default.aspx">zero-day</category></item></channel></rss>