Retiring Internet Explorer
textslashplain.com
textslashplain.com
Wow. That's... a rather unconventional security architecture.
https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...
https://en.m.wikipedia.org/wiki/Superfish
https://www.eff.org/deeplinks/2015/11/superfish-20-now-dell-...
Actually it was rather inevitable, partially because of the U.S. gov that time. The Korean gov wanted to grow e-commerce/e-banking in 1999 but the American gov did not allow to export cipher higher than 40 bits. As a result the Korean gov had to develop its own 128 bits cipher (SEED).
It was even before AES/SSL/TLS were introduced so the whole crypto stack was implemented using ActiveX.
I would say it was quite pioneer in 1999 but since then the gov don't even dare to replace the crypto policies. Now we are stuck at this in 2020.
That's amazing it's still used per policy, I never would have imagined.
Edit: clarification on which parts were blocked and internationally available.
That thing exactly was export-restricted and was available only in U.S. and Canada: https://jeffpar.github.io/kbarchive/kb/159/Q159709/
But it was true that SSL was introduced before 1999. Thanks for the correction.
However, I think the present situation is possibly the better one as a siloed, South Korea only web, separate and distinct from the rest of the Web, would end up being a much harder one to eventually migrate to the regular global web ecosystem vs. the current problem of just getting banks to stop using SEED and moving users to modern browsers.
There are two major factors in the ubiquity of HWP:
1. Its use of the de facto standard format in the SK government (the de jure standard is the ODF since 2007, but its use is virtually nonexistent). This stems from the fact that it was the most viable word processor supporting Hangul the script back in 1990s.
2. Its excellent support of table-based layout. HWP is a decent word processor in comparison to MS Word, and in some cases it is even superior. Koreans used to produce lots of documents based on tables [1] and HWP's UX was specially tailored to them. MS Word lagged behind for a long time, probably because this use case is not common in English worlds.
[1] You can search for "이력서" (résumé) to see what I mean. Even a plain document tends to be styled in this way.
> I would say it was quite pioneer in 1999 but since then the gov don't even dare to replace the crypto policies. Now we are stuck at this in 2020.
AFAIK, the government removed the SEED-only policy some time ago (in the early 2010s) but it’s the price of the system infrastructure that makes them keep using the old, ActiveX based systems.
I’m personally thankful for smartphone’s to come, as the banks started to consider implementing support for other operating systems. If it wasn’t the abundance of smartphones, I believe there might have not been any non-windows/IE support. Its much better nowadays, with multiple startups in the finance space like Toss, Kakao, etc...
1: Or, more probable, support for modern web browsers on any OS, but with (2FA) authentication handled through proprietary and required Android or IOS apps.
That’s actually a pretty accurate explanation of currently what’s happening, but it’s much better than before as macOS/Linux support is also coming too.
> That's not quite as bad of course, but it's still limiting in terms of software freedom.
I’m not the person who hates programs that aren’t open source or “free”, so for me just being able to tell my friends to use macOS or Linux is a pretty great progression.
We're moving in that direction in the Netherlands with our national citizen's accounts (DigiD: mandatory if you want to file taxes, gain access to your health care records, or handle your insurance digitally).
The Microsoft License Advisor, which has the pricing info for Windows,
on Firefox pops up a box which reads
"Internet Explorer Notification NaN and newer versions. Download latest version of Internet Explorer"
'<table><tr><td width="40" height="40"><img src="images/35x35_information_icon.gif" /></td>' /
+ '<td width="415" height="40"> Microsoft License Advisor is optimized for Internet Explorer 7'Specifically, why is it still shipping IE as the only browser as part of Windows 10 Enterprise LTSC, including LTSC 2019? Yes, that is the version of Windows 10 with an "extended support end date of 9 January 2029"*
* https://support.microsoft.com/en-us/help/13853/windows-lifec...
I expect it's not not that MS believes no one needs IE, it's that they know they're stuck with it and would really rather not be.
My org loaded Chrome on all of the machines for our internal web sites, but according to my logs, almost nobody uses it. They're just too used to clicking on the (e), I guess.
Basically, think of it like: LTSC ships without a browser. If you want a browser, go install one from the App Store. What it does ship with is an ActiveX-enabled-Intranet client.
And then there are all the internal corporate web portals that are still IE-only, and probably will remain so for as long as IE is supported in any shape or form.
Or at the very least, Explorer and the task bar should do everything in its power to hide the existence of Internet Explorer 11. It shouldn't be listed as a program anywhere by default and it shouldn't come up in search.
We have multi-million dollar software that relies on IE to run -- that's why. What good is an OS that can't run our software?
Since Windows 10 we've setup an icon to just launch this application in IE and set the default browser for end-users to Chrome.
Eventually that software will be replaced and we can end our use of IE but today is not that day.
I don't use it so I'd rather not have it on my machine.
(Or alternatively, Microsoft could put some hack into Windows so that attempts to run iexplore.exe are passed to Edge unless the administrator has twiddled with some arbitrary registry key or group policy.)
They could but that goes back to reply about it existing software still requiring IE.
IE will be around for as long as very critical apps still require it. In some form, it might be around forever.
But what's the benefit of complicating the install?
2. A smaller OS.
3. A more secure OS (the wrapper probably isn't bug free).
This probably only matters if it's attempted to be used.
I will concede that you will save a few MB on your multi-GB Windows install.
I'm sure this would not be a big deal for a multi-million dollar company.
My bank in China requires Windows + IE + a custom ActiveX control to use their Internet banking. As a result, I don't use it. One of my accounts can be used via their mobile app (if you read Chinese or have another phone to use camera translation). My business account cannot be, and I am therefore required to visit a branch along with my official chop (seal / stamp) whenever I want to make a transaction.
In every bank branch I've been to, the computers are using ancient versions of Windows and IE. That actually applies to the PSB (a branch of the police) too. I think it might be a while before they get off IE.
Why not have a VM just for internet banking? Surely that's easier than taking the chop out of the safe and waiting in line at the branch.
for example by enumerating the connected PCI devices and looking for common VM vendors virtual devices.
>Doesn't that defeat the purpose of the VM to begin with
that depends on your use-case. If it's about separating mostly trusted applications and/or servers, then absolutely not.
If it's about investigating known-bad code, then, yes, absolutely - malware is often intentionally disabling itself when it detects it's running in a VM.
I wouldn't trust myself to keep the latest version of Windows secure, given that I haven't used Windows in over a decade, so I'm pretty sure I can't be trusted to keep XP safe. (As far as I'm aware, the "security" software that the bank's ActiveX control communicates with only runs on XP.)
It's simple, really.
Set up the VM. Do a snapshot. Every time you need to use the shit website, launch the VM, open the site in IE and nothing else. When you're done, shut down the VM and reset it to the known good snapshot.
There. Secure.
I've heard it said that the official OS of mainland China is a pirated copy of Windows XP. IIRC, there are even 3rd-party vendors there that distribute security patches for it. I doubt those people will be fazed by the actions you suggest.
There is a legal element which may allow them to do so, but it is incredible unresponsible to do so. Even the small Win10 migration process break people.
Mind you, I would totally agree with such a decision, if MSFT decided to enforce it, but I dont think it will necessarily play out in a way that is advantageous to MSFT, hence why they haven’t done so yet.
The only way to make them stop supporting IE is to have the OS itself stop bundling it - which, like it was mentioned elsewhere in this discussion, is probably never going to happen.
As a web designer, IE - since 6 - has been the bane of my existence. It's not nearly as bad as it used to be, but it's there.
It's just that MS ceased investing more than the absolute minimum into their browser after releasing IE 6 - it took until 2009 until a MS browser passed the Acid2 compatibility test.
This is tangential, but I wonder how Chrome got so far ahead, not in market share but in features and quality, even with IE's 10+ year head start. Did Google just throw more programmers at the problem, or was there more to it? I suspect this has already been discussed to death, so pointers to previous discussions would be good.
1. Significantly faster Javascript execution engine (V8) than MSIE and Firefox
2. Process isolation model improved security posture
3. Multi-platform compatibility (Windows/Mac/Linux) very soon after launch
4. Improved usability: browser history search, autocomplete in address bar, etc.
Here's the original announcement (featuring Sundar Pichai, then VP of Product, now CEO): https://www.youtube.com/watch?v=LRmrMiOWdfc
Also, I think they had a fairly good test infrastructure from the beginning ( I think they tested new versions of Chrome against Google's index of top million websites ). Good test infrastructure can give you compounded returns as the project goes on.
"features" and "quality" are subjective metrics. Win the marketshare and you win the mindshare. It's a big part of why the browsers wars have always been monopolistic. The best browser is always just the one "everyone uses". Even its bugs/quirks/oddities become "features" that other browsers need to support, have to "catch up" on, get encoded into standards eventually as "the way it has always been".
Does anyone still do this to get to know new code base?
It would be great to see Github implement a printer friendly view on codebases for this purpose.
That said, sometimes printed code is still better.
Aside from the mentioned advantages about annotations, I find that working with hard copy produces a different mindset, almost as if your brain recognises that this is still a draft and everything is subject to reconsideration. Counter-intuitively, words on a screen seem more "set in concrete".
It also seems that the brain works differently when sat in front of a humming monitor as opposed to literally anywhere else in the world which is where you can edit hard copy.
Being that "a fresh set of eyes" is often so valuable in both writing and programming, anything that can get you a fresh perspective is potentially valuable, particularly with such a low buy-in.
It's tough to get much deader before they just rip it out.
which is pretty much going to be "never". IE's support lifecycle says that a version of IE is supported for as long as the version of windows it shipped with is supported.
Windows 10 shipped with IE11 and Windows 10 is going to be the last version of Windows ever released, remaining in constant support.
Companies on the other hand still force users to use IE11 and they will continue to do so while IE11 is supported (which is forever).
We will have to continue to support a browser that came out in the beginning of the last decade for at least another 10 to 15 years.
The article (and site) from this post is very good.
I still make my sites work in IE, down to IE4, and probably 1-3 too, I just haven't had a chance to test them yet.
I think that in the retro-computing world, IE will be one of the longest browsers still in use.
- no name-based virtual hosting (it does HTTP 1.0 but doesn't send Host headers)
- avoid redundant whitespace (it's not collapsed)
- wrap <style> and <script> contents in <!-- and // -->, otherwise they will be visible
I've had to keep an application's webinterface IE2 compatible ("usable") for longer than I wanted to as the initial configuration (opening up ports and IP addreses) was generally done on the NT4 server in IE itself.
(Once initial setup was done, further configuration could be done remotely with a more 'modern' browser, so fortunately only a few pages needed to be usable by IEs that old)
I will work to find an NT4 original ISO and get IE2 that way.
I've been doing the commenting thing, and found out that Mosaic treats >, not --> as the end of comment token, so I had to remove all > characters from my JS. :D
Today all the malicious garbage moved to e-mail.
Certainly, some things might render brokenly in other browsers, but ActiveX is the only real "IE-only feature" a site might depend on.
Can't image there not being a few niches out there that heavily rely (or relied) on HTAs
http://runtimeterror.com/tools/calc/calc.hta.txt
(yes, running an HTA "calc" is faster than the UWP Windows 10 calculator... and uses less RAM :-/).
If all you have is Notepad, and you know how to write HTAs, the world is your oyster (or something).