September 29, 2005

Microsoft gets hacker feedback on IE7 Beta 2

Microsoft aims to engage the 'security research community' more in the future

Microsoft showed off the preliminary work it has done on the second beta version of its popular Internet Explorer, version 7, at the Hack in the Box Security Conference in Kuala Lumpur, Malaysia, and came away with some good feedback, managers at the company said Thursday.

"It's the first time we've ever come out ahead of a product release to present and get feedback," said Tony Chor, group program manager at Microsoft's Internet Explorer team, referring to the company's presentation to a hacker-specific group.

Chor, and colleague Andrew Cushman, director of Microsoft's security engineering and communication group, spoke highly of the feedback they heard at the presentation, and preferred the term "security research community" for attendees, instead of "hacker."

"Hacker has a negative connotation, like a criminal," said Cushman. People such as attendees of the Hack in the Box conference approach security from a very different, very valuable perspective, he added.

"This community is a good source of information and we haven't availed ourselves of that source," said Cushman.

Chor went a step further, saying Microsoft has maintained an "adversarial" relationship with the hacking community in the past, but "that wasn't working. It just made them mad and we didn't benefit from their passion and expertise."

But the Redmond, Washington company is putting that past behind it, and its goal is to engage the "security research community" more in the future, presenting at more hacker conventions and giving them a chance to critique some of Microsoft's work ahead of releases.

Chor and Cushman also handed out their business cards liberally, and hope to get more e-mail responses from people, as well as notes on their blog, they said.

"People had a lot of good suggestions, and asked a lot of good questions," said Chor.

Some hackers at the show gave Microsoft high marks for showing off some new security features on the Web browser and seeking their views, adding they would have liked to hear more technical detail on new features in IE7 Beta 2. But their impression was the presenters appeared almost apologetic, and the hackers don't plan to switch to any Microsoft products near term, at the expense of, say, Mozilla's Firefox browser.

Chor said he planned to increase the amount of technical detail in future presentations.

The Beta 2 version of IE7, currently under construction at Microsoft, will likely be ready by the end of the year, said Chor.

One new feature on the Web browser is it runs in higher security "Protected Mode" by default, set at a lower user privilege. In protected mode, all downloads and other packages are automatically dropped in the "temporary Internet files" folder, so malware can't be deposited on the hard disk. In the temporary folder, IE and Windows treat the files as dangerous and they're given no privileges to move about.

With add-ons like a Google Inc. toolbar or ActiveX, IE7 Beta 2 will offer more permission prompts, since downloads such as ActiveX opt-ins can be an avenue for attack, Chor said.

Microsoft will license its "Protected Mode" innovation to other developers for free to help spread its use, and increase security, said Chor.

For businesses, Microsoft added a "Compatibility Mode" that works when a person is using the company's intranet and allows them to drop files wherever they want to on their PCs.

 

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.