Quantcast

Hackers Advise Microsoft on IE

Developers offer a peek at browser update, accept suggestions.

Dan Nystedt, IDG News Service

  • 0 Yes
  • 0 No

KUALA LUMPUR, MALAYSIA -- Microsoft showed off its preliminary work on the second beta version of Internet Explorer 7 at the Hack in the Box Security Conference here, and came away with some good feedback, company managers said Thursday.

"It's the first time we've ever come out ahead of a product release to present and get feedback," said Tony Chor, group program manager at Microsoft's Internet Explorer team, referring to the company's presentation to a hacker-specific group.

Security Advice

Chor and colleague Andrew Cushman, director of Microsoft's security engineering and communication group, spoke highly of the comments they heard at the presentation. They said they preferred the term "security research community" for attendees, instead of "hacker."

"Hacker has a negative connotation, like a criminal," said Cushman. People such as attendees of the Hack in the Box conference approach security from a very different, very valuable perspective, he added.

"This community is a good source of information and we haven't availed ourselves of that source," said Cushman.

Chor went a step further, saying Microsoft has maintained an "adversarial" relationship with the hacking community in the past, but "that wasn't working. It just made them mad and we didn't benefit from their passion and expertise."

But the software giant is putting that past behind it, and its goal is to engage the "security research community" more in the future, presenting at more hacker conventions and giving them a chance to critique some of Microsoft's work ahead of releases.

Chor and Cushman also handed out their business cards liberally, and hope to get more e-mail responses from people, as well as notes on their blog, they said.

"People had a lot of good suggestions, and asked a lot of good questions," said Chor.

IE7 Insights

Some conference attendees gave Microsoft high marks for showing off some new security features on the Web browser and seeking their views, adding they would have liked to hear more technical detail on new features in IE7 Beta 2. But their impression was the presenters appeared almost apologetic, and the hackers don't plan to switch to any Microsoft products near term, at the expense of, say, Mozilla's Firefox browser.

Chor said he plans to increase the amount of technical detail in future presentations.

The Beta 2 version of IE7, currently under construction at Microsoft, will likely be ready by the end of the year, said Chor.

One new feature on the Web browser is it runs in higher security "Protected Mode" by default, set at a lower user privilege. In protected mode, all downloads and other packages are automatically dropped in the "temporary Internet files" folder, so malware can't be deposited on the hard disk. In the temporary folder, IE and Windows treat the files as dangerous and they're given no privileges to move about.

With add-ons like a Google toolbar or ActiveX, IE7 Beta 2 will offer more permission prompts, since downloads such as ActiveX opt-ins can be an avenue for attack, Chor said.

Microsoft will license its "Protected Mode" innovation to other developers for free to help spread its use, and increase security, Chor said.

For businesses, Microsoft added a "Compatibility Mode" that works when a person is using the company's intranet and allows them to drop files wherever they want to on their PCs.

  • Recommend this story?
  • 0 Yes
    0 No

"Hackers Advise Microsoft on IE" Comments

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
  • Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.

PC World's Marketplace