Low-Rights IE Only for Longhorn Users - Techist - Tech Forum

Go Back   Techist - Tech Forum > Computer Software > Microsoft Windows and Software
Click Here to Login
Closed Thread
Thread Tools Display Modes
Old 06-14-2005, 04:17 AM   #1 (permalink)
Techie Beyond Description
Osiris's Avatar
Join Date: Jan 2005
Location: Kentucky
Posts: 36,817
Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris
Default Low-Rights IE Only for Longhorn Users

Low-Rights IE Only for Longhorn Users

Rob Franco, Lead Program Manager for Internet Explorer Security at Microsoft posted a missive to the IEBlog hoping to dissolve the confusion surrounding a planned security future that will be found in IE7. IE7 will run in a reduced privilege mode called "Low-Rights IE" that will limit the actions of malware.

But the safeguard will not be available to everyone - only users that upgrade to Longhorn will be protected. And even Longhorn users may be vulnerable at another well known exposure point: Microsoft will not modify the default security settings for ActiveX and scripting, which account for a large number of known vulnerabilities.

Microsoft has programmed Longhorn to make it possible for users to have normal Windows sessions while having reduced user account privileges - making the browser safer to use than when it ran with full administrative privileges.

Longhorn's predecessor, Windows XP, does not have this capability and cannot offer users the protection of Low-Rights IE. Users that do not upgrade to Longhorn will remain vulnerable to malware that can hijack default settings, modify system files and install malicious software.

"It's great to see Microsoft reducing the security footprint of future versions of IE. Reducing the privileges required to run IE should seriously reduce the amount of damage that occurs when browsing, and should reduce the amount of spyware and other nastiness that can infect users' machines via the browser," Andrew Jaquith a Senior Analyst with Yankee Group, told BetaNews.

"That said, Microsoft isn't going far enough. Microsoft should do two more things," said Jaquith. "First, Microsoft should declare victory and retire ActiveX in favor of .NET- only technologies---things that run in their Common Language Runtime sandbox rather than as native code. Native code will always be prone to buffer overflows and other types of attacks. For now, it's best to simply turn off ActiveX or run another browser that doesn't support it (like Firefox)."

Microsoft has stated that one of its goals is to maintain compatibility among sites and with add-ons that use ActiveX while attempting to be as secure as possible.

Jaquith also had words about Microsoft's decision not to port Low-Rights IE to Windows XP. "Second, the 'more secure' IE should be offered to Windows XP users too - why leave them out in the cold?"

In the IEBlog, Franco reminded user that even Low-rights IE does not protect them from downloading and installing malware - it just reduces the damage that can be done. It is still possible that a user may grant malware administrative privileges.

A beta of IE7 is expected to be released June 30. Windows XP Service Pack 2 is a requirement for the beta; as previously reported, there will be no IE7 distribution for Windows 2000.

Osiris is offline  
Old 06-14-2005, 04:37 AM   #2 (permalink)
Super Techie
Join Date: Feb 2005
Posts: 432

Meh, Longhorn is going to be the next Windows ME. I'll wait until they release something after Longhorn. They will gut whatever is useable from Longhorn and apply that to the next OS as they did with ME to XP.

tribalsun is offline  
Old 06-14-2005, 10:40 AM   #3 (permalink)
Chillin Techie
Join Date: Nov 2004
Location: USA
Posts: 11,861

firefox already has a safe mode (Low-Rights mode)
The Ultimate Hard Drive Utility PowerMax 4.23. (It now has the ability to clean a Boot Sector virus on the quick erase option.)
The best browser Netscape 8
Have you accidently delete something? Look here (trial. the better one) and here(free)
EricB is offline  
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Copyright 2002- Social Knowledge, LLC All Rights Reserved.

All times are GMT -5. The time now is 06:29 PM.

Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2018, vBulletin Solutions, Inc.