Home > Enterprise Desktop Tips > > Web security features of Internet Explorer 8
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Web security features of Internet Explorer 8


Brien M. Posey, MCSE
04.17.2008
Rating: -4.67- (out of 5)


Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


This week, I took the current beta version of Internet Explorer 8 (IE8) for a test drive. Right now IE8 is still in its first beta release, but it is far enough along that we can at least get an idea of what the finished product may look like.

As you read this article, there are two things to keep in mind: First, because this is an early beta release, anything that I've talked about could potentially change by the time Microsoft finally releases the product. Second, I am limiting my discussion primarily to talking about the features that have to do with security.

Figure A

This is what the user interface for Internet Explorer 8 looks like. Click to enlarge.

Now let's talk about these security features. Internet Explorer 7 was designed primarily to address the security shortcomings of the previous IE version. In contrast, though, Internet Explorer 8 is a lot less about security and more about standards. In fact, Microsoft cited better support of Web standards as one of its major goals in creating IE8. Also cited were improvements in RSS, cascading style sheets (CSS) and Ajax support. Although Microsoft mentions better security as one of its goals in creating IE8, that goal seems to be secondary.

Microsoft Web security
Reduce your Web server's attack surface

Tips on hardening and securing IE7

IT Knowledge Exchange

The fact that Microsoft designed Internet Explorer 8 to better support various Web standards is both good and bad. It's good from the standpoint that more consistent support of the various standards should enable Web developers to create sites that are more secure because they use standardized code. On the other hand, Internet Explorer has a long history of not enforcing a lot of the Web standards. Therefore, many sites that are in use today won't fully comply with some of the Web standards that will be enforced in Internet Explorer 8 and that means a lot of websites won't function correctly.

As a way of easing the burden caused by this incompatibility, Microsoft has designed Internet Explorer 8 so that it emulates Internet Explorer 7 if necessary. As you can see in Figure B, the Emulate IE7 feature is prominently displayed on the Tools menu. I can't help but wonder if the emulation will expose Internet Explorer 8 to many of the same security threats that made Internet Explorer 7 vulnerable.

Figure B

Internet Explorer 8 can emulate IE7. Click to enlarge.

Another security feature that's shown in Figure B is the Safety Filter. From what I can tell, the Safety Filter seems to have replaced the Phishing Filter found in Internet Explorer 7. The Safety Filter is designed to detect Phishing sites, but it also detects websites that are known to be malicious and analyzes the full URL string looking for malicious code. The idea is to take a more granular approach to preventing attacks.

Another new security feature is called domain highlighting. The basic idea behind this feature is that the address bar displays the domain portion of the URL in black, while the remainder of the URL is grayed out. This feature probably doesn't sound like a big deal, but some websites are designed to conceal their identity by including text in the URL string, which tricks users into thinking they are on a different site. Domain highlighting leaves no doubt as to which site a user is actually on. You can see how the domain highlighting feature works if you look at the address bar in Figure C.

Figure C

The address bar demonstrates the domain highlighting feature. Click to enlarge.

The security features I have mentioned are nice to have, but I would hardly call them life-changing. Sadly, these are the only new security features that Microsoft even mentions on the IE8 beta site. It is possible that there are other security features that work behind the scenes and have not yet been disclosed.

About the author: Brien M. Posey, MCSE, has received Microsoft's Most Valuable Professional Award four times for his work with Windows Server, IIS and Exchange Server. He has served as CIO for a nationwide chain of hospitals and healthcare facilities, and was once a network administrator for Fort Knox.


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Microsoft Internet Explorer (IE)
Admins can wear many hats using Netcat
Patching third-party browsers adds more work in Windows shops
Four Internet Explorer 8 Group Policy security settings
Safe enterprise Web browsing: Five tips in five minutes
Top client security tips of 2006
General security configuration: Step 1
Protection against international domain names, URL handling: Step 3
ActiveX opt-ins, information bar and cross-domain protection: Step 4
Windows Vista and IE7: Step 5
Phishing filter: Step 2

Windows desktop security tips
The right security tools for finding Windows desktop weaknesses
Using BitLocker in Windows 7
20 days to a more secure enterprise
Improvements to offline file synchronization in Windows 7
How to get -- and keep -- user support with security
Structuring patch management in seven steps
Underlying causes of inconsistent patch management
Monitoring user activity with network analyzers
Microsoft's Patch Tuesday brings a bumper crop of security fixes
Using third-party technologies with Microsoft's NAP

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
ActiveX  (SearchEnterpriseDesktop.com)
ActiveX control  (SearchEnterpriseDesktop.com)
Internet Explorer  (SearchEnterpriseDesktop.com)
Internet Explorer Administration Kit  (SearchEnterpriseDesktop.com)
tabbed browsing  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts