German government urges public to stop using Internet Explorer
webcache.googleusercontent.com
webcache.googleusercontent.com
the "Enhanced Mitigation Experience" = priceless
On Windows XP and Windows Server 2003 operating systems, the Microsoft .NET Framework 2.0 must be installed for EMET to work. There are no other special requirements for any other supported version of Windows.
And in order to have it one needs to install .NET which comes with bunch of its requirements.(Quotes because, as PPK always reminds us, there is no monolithic WebKit in actuality.)
Edit in reply: Hmm, “currently… except for recently.” Then let my comment be in reply to “currently” and not “recently,” I suppose. Not sure if my parent was edited after my reply, or if I was really that bad a reader.
We already know the answer to that - when attackers try to target any browser, they in many cases succeed. All major browsers get hacked at the relevant competitions, and those are just the public hacks we hear about, the private ones are likely far worse.
Mitigation measures do matter though. Adding security makes it harder, and pushing out patches quickly reduces the window of vulnerability. Microsoft has improved in the former but not in the latter.
Yes, they fix and push fixes out faster, but that doesn't inherently mean your browser is more secure, only that there are less people out there with browsers that are publicly known to be exploitable, but is safe to assume that all browsers are exploitable, and that there are people that knows the holes but doesn't make them public because their value (either to governments or criminals) is way too great to even compete in the same league as the rewards offered by browser makers.
Please don't repeat FUD.
It seems the web people have deluded themselves into thinking they really understand the implications of letting webpages interact with video drivers, and some of the graphics industry were just to happy to help along.
This doesn't change the fact that WebGL exposes graphics drivers in ways that they were never meant to, and that there is no real way for third parties to verify how safe it is to turn on WebGL for a given driver.
The whitelists and blacklists of drivers currently used do little more than to fragment the web and frustrate users.
I'm a big fan of how Google introduced much needed decent sandboxing to web browsers, but what they are doing with WebGL is both scary from a security point of view and depressing from the point of view of fragmenting the web, now to access certain websites not only you need the right browser, you also need the right video card and video drivers, is worse than the "best viewed with" nightmare of the 90's.
First, Chrome will fall back to a software emulation that actually works very well. So even if your video driver is blacklisted, you can still see the content.
Second, I'm not sure Carmack has made an effort to really look at the differences between WebGL and OpenGL. Features are limited and the browsers are required to parse and verify input, so that only correct code is sent to the graphics drivers.
(edit:) Let me add some more information here: Array bounds are checked; Array indexes must be constant expressions ; and, most importantly, while-loops are forbidden. If you've taken a course in theoretical CS, you may recall the difference between for and while loops and why applications using only the former can be verified (if there is not recursion - OpenGL shaders also don't support that anyway).
Third, access to WebGL could be easily limited in the future: For example allow access by default for browser extensions and require user confirmation for the rest of the web. Should be fine for games.
1. Only on Windows, not anywhere else
2. It will be very slow. For this reason, I think this might be almost pointless, and worse than showing nothing in some cases.
By "the web people" you mean Google, Microsoft (yes, Microsoft, because it is ok with letting webpages interact with video drivers through Silverlight), Apple, Mozilla, Opera, and Adobe (yes, Adobe, because it is ok with letting webpages interact with video drivers through Stage3D in Flash)?
So basically the entire industry is deluded?
That's one of the reasons I simply avoid Windows.
While this might not mean much to the average user of HN (read: tech literate) - i think it IS quite a big deal for "ordinary" computer users.
I think such warnings, from an official government body no less, will be heeded by many who don't know much and "just want to be safe"
Meanwhile MS choses to tell people that it "is not that bad" and that "not many users will be affected" and no word on when a patch is coming. This despite the fact that all current MS OSes (xp,vista,7) are exposed - is a PR disaster for MS.
http://en.wikipedia.org/wiki/Federal_Office_for_Information_...
My job routinely requires me to utilize Internet Explorer, and I don't think it's all that bad to be honest. I also utilize Chrome and Firefox throughout my day. Is it a little slower? Sure. Is it kind of the big, ugly older sister of Firefox and Chrome? Absolutely. Beyond all that, though, it still works.
Effectively preventing competitors from building accepctable JavaScript-enabled browsers. It's not that you can't make a winrt browser. It's that it'll suck.
IANAL.
An abuse of their monopoly power would be something like denying Windows licenses to PC makers unless they agree to exclusively produce Windows 8 ARM tablets. There needs to be a leverage of the monopoly power in doing something anticompetitive for there to be an illegal act.
I was not speaking of brand, but OEM agreements. IIRC, if the OEM posts "X recommends Windows Y" on every product page, they get a better license price.
> ...would be something like denying Windows licenses to PC makers unless they agree to exclusively produce Windows 8 ARM tablets
Or differentiating their Android patent licenses according to the licensee's willingness to manufacture Windows Phone devices too. Or only licensing Windows 8 to ARM tablets that can never run anything else.