Home > Windows Security Tips > Internet security (Web security) tips for Windows > Web security features of Internet Explorer 8
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

INTERNET SECURITY (WEB SECURITY) TIPS FOR WINDOWS

Web security features of Internet Explorer 8


Brien M. Posey, MCSE
04.17.2008
Rating: -4.67- (out of 5)


Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


This week, I took the current beta version of Internet Explorer 8 (IE8) for a test drive. Right now IE8 is still in its first beta release, but it is far enough along that we can at least get an idea of what the finished product may look like.

As you read this article, there are two things to keep in mind: First, because this is an early beta release, anything that I've talked about could potentially change by the time Microsoft finally releases the product. Second, I am limiting my discussion primarily to talking about the features that have to do with security.

Figure A

This is what the user interface for Internet Explorer 8 looks like. Click to enlarge.

Now let's talk about these security features. Internet Explorer 7 was designed primarily to address the security shortcomings of the previous IE version. In contrast, though, Internet Explorer 8 is a lot less about security and more about standards. In fact, Microsoft cited better support of Web standards as one of its major goals in creating IE8. Also cited were improvements in RSS, cascading style sheets (CSS) and Ajax support. Although Microsoft mentions better security as one of its goals in creating IE8, that goal seems to be secondary.

Microsoft Web security
Reduce your Web server's attack surface

Tips on hardening and securing IE7

IT Knowledge Exchange

The fact that Microsoft designed Internet Explorer 8 to better support various Web standards is both good and bad. It's good from the standpoint that more consistent support of the various standards should enable Web developers to create sites that are more secure because they use standardized code. On the other hand, Internet Explorer has a long history of not enforcing a lot of the Web standards. Therefore, many sites that are in use today won't fully comply with some of the Web standards that will be enforced in Internet Explorer 8 and that means a lot of websites won't function correctly.

As a way of easing the burden caused by this incompatibility, Microsoft has designed Internet Explorer 8 so that it emulates Internet Explorer 7 if necessary. As you can see in Figure B, the Emulate IE7 feature is prominently displayed on the Tools menu. I can't help but wonder if the emulation will expose Internet Explorer 8 to many of the same security threats that made Internet Explorer 7 vulnerable.

Figure B

Internet Explorer 8 can emulate IE7. Click to enlarge.

Another security feature that's shown in Figure B is the Safety Filter. From what I can tell, the Safety Filter seems to have replaced the Phishing Filter found in Internet Explorer 7. The Safety Filter is designed to detect Phishing sites, but it also detects websites that are known to be malicious and analyzes the full URL string looking for malicious code. The idea is to take a more granular approach to preventing attacks.

Another new security feature is called domain highlighting. The basic idea behind this feature is that the address bar displays the domain portion of the URL in black, while the remainder of the URL is grayed out. This feature probably doesn't sound like a big deal, but some websites are designed to conceal their identity by including text in the URL string, which tricks users into thinking they are on a different site. Domain highlighting leaves no doubt as to which site a user is actually on. You can see how the domain highlighting feature works if you look at the address bar in Figure C.

Figure C

The address bar demonstrates the domain highlighting feature. Click to enlarge.

The security features I have mentioned are nice to have, but I would hardly call them life-changing. Sadly, these are the only new security features that Microsoft even mentions on the IE8 beta site. It is possible that there are other security features that work behind the scenes and have not yet been disclosed.

About the author: Brien M. Posey, MCSE, has received Microsoft's Most Valuable Professional Award four times for his work with Windows Server, IIS and Exchange Server. He has served as CIO for a nationwide chain of hospitals and healthcare facilities, and was once a network administrator for Fort Knox.


Rate this Tip
To rate tips, you must be a member of SearchWindowsSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Internet security (Web security) tips for Windows
ActiveX security improves with Internet Explorer 8's security features
Data protection on the Web: Windows SSL security and other myths
Improve Web security with Group Policy settings
Web security tactics that harden Windows networks
What do you know about Microsoft Internet security?
Scan IP ports without Windows Firewall restrictions
Internet Explorer 7 and its security issues
Pop-ups in IE are hijacking my homepage
Reduce your Web server's attack surface
Internet Explorer 7: Troubleshooting tips

Hardening
Cross-site Scripting 102: How to defend against cross-site scripting
ActiveX security improves with Internet Explorer 8's security features
How can I use Process Explorer as a Web security tool?
New Windows security tool protects users from keyloggers: XecureCK
Cross-site scripting 101: XSS attacks plague Web browsers
What's hot in Windows security? New Microsoft Office Security Guide
Data protection on the Web: Windows SSL security and other myths
What's hot in Windows security: Updating Windows Update; new IE scare
Web security tactics that harden Windows networks
What do you know about Microsoft Internet security?

Other Microsoft Tools
Vista SP1 vs. XP SP3 -- upgrade or business as usual?
Data encryption with EFS and BitLocker, step by step
Windows Integrity Control (WIC) in Vista
Prevent data loss with Encrypting File System (EFS)
PatchGuard defends against rootkits in Windows Vista
What's hot in Windows security: Ins and outs of Windows Server 2008
Security tools that limit user logon in Windows
Windows Vista's security features: One year later
Cheap Microsoft licenses for security pros: Microsoft Action Pack
Conquer forgotten Windows passwords with Password Reset Wizard

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
BitLocker  (SearchWindowsSecurity.com)
Microsoft Antigen  (SearchWindowsSecurity.com)
Next Generation Secure Computing Base  (SearchWindowsSecurity.com)
WS-SecureConversation  (SearchSoftwareQuality.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts