Microsoft nixes ActiveX add-on technology in new Edge browser
computerworld.com
computerworld.com
"Once the Windows shell itself lets you browse the Web, the need for a separate web browser application becomes less apparent. But while web browsers as such might one day fade into the mists of history, that day hasn't yet arrived. And even if browsers per se vanish, [COM] components such as the Web Browser object and the HTML viewer will survive."
Microsoft implemented it, called "The Microsoft Network" (MSNv1): http://en.wikipedia.org/wiki/MSN_Dial-up#The_Microsoft_Netwo... . It used the Win95 Explorer as interface. Internet Explorer 1 (rebranded Mosaic) shipped with Win95b / Win95 Plus add-on CD. http://en.wikipedia.org/wiki/Mosaic_(web_browser)
See MSN1 in action, the introduction film with Jennifer Aniston: https://youtu.be/kGYcNcFhctc?t=17m16s (watch it for 2-3 min to get the idea; or direct link to MSN1: https://youtu.be/kGYcNcFhctc?t=19m16s)
Read Bill Gates (former internal) 1994 memo: "Windows: The Next Killer Application on the Internet": http://www.microsoft.com/about/companyinformation/timeline/t... . "The memo starts with a background on the Internet in general, and then proposes a strategy on how to turn Windows into the next "killer app" for the Internet." -- http://en.wikipedia.org/wiki/Embrace,_extend_and_extinguish
Keep in mind that this wasn't the original NCSA Mosaic
"Spyglass, Inc. licensed the technology and trademarks from NCSA for producing their own web browser but never used any of the NCSA Mosaic source code. Microsoft licensed Spyglass Mosaic in 1995 for US$2 million, modified it, and renamed it Internet Explorer."
Browsers offer a reliable way to use hardware without any configuration. It is easy to forget how difficult something like video playback could be (relying on player software) before sites like Youtube came along.
http://www.theregister.co.uk/2015/04/02/south_korea_to_depor...
For those who need some background: "A law passed in the late 90's to facilitate ecommerce security requires using an ActiveX control, and therefore IE, to shop on Korean sites."
http://www.washingtonpost.com/world/asia_pacific/due-to-secu...
http://www.zdnet.com/article/south-koreans-use-internet-expl...
Edit: nvm didn't load half the page, enterprise version will have ActiveX & BHO support :D
The awesome thing about Edge is that they can make these decisions and start fresh without hurting backwards compatibility (because there IS no backwards in Edge, it's brand new), and they can just say "you want all this legacy stuff? use IE" - IE, with its 4 rendering engines, ActiveX, and various zones and modes to appease IT departments, is not going away.
That "zone" crap is something I never understood anyway. It's a real PITA to setup a Windows Server (tried 2008 and 2008 R2, and I believe its predecessors also had it), because you have to click a dozen different buttons, checkboxes and sliders just to visit a website - and to download stuff like a driver or, heaven forbid, another browser, even more clicks.
Also, these days I don't believe that the whitelisting approach works anymore either, because every website on the web loads content (ohai Jquery and friends) from others... hope it's gone for good in the "new IE".
I'm guessing, like SELinux, what users end up doing is just disabling things completely (or enabling all options) instead of figuring out all the specifics. I understand, no one wants to be responsible for shipping a vulnerability by default, like MS products used to be.
Also see their terrible HTTP.SYS reservation system. Any program can listen on a socket. But if you want to use that socket for HTTP and use the OS-provided functions? Boom, special ACLs apply; enjoy figuring out a special one off utility. Or just run your service as a local admin.
Sockets require very little permissions to bind because binding a socket cannot have adverse affects on the entire system, if it's in use by another app it wont allow you to do it.
Zones were MSFT's vision from the early 2000's in which your internet access will be divided between internal corporate resources, trusted parties preferably trough some sort of AD federation (anyone remembers when MSFT tried to make global AD federation over the internet with Andromeda or w/e it was called?) and the internet. Each zone would have a different security setup which will restrict what kind of information you can pass to a site (e.g. your NTLM/Kerberos credentials) and what kind of actions the site can perform on your browsers. It wasn't a bad idea, the market just never went there and even corporate resources today are accessed via the global internet and not in the intranet or some sort of a federated network.
MSFT has always had some weird things, some were way a head of it's time and like many things which are a head of their time when they miss they miss by a mile. Heck every Windows machine connected to the internet still has (or can have i think in Windows 8 it's not enabled by default any more but i could be wrong) a globally translated name trough PNRP akin to DNS, I've actually used it during the early Vista days for remote access when DyDNS services were still in their infancy and not many trustworthy services were out there. PNRP was also quite a neat idea (especially once they've dropped the IPv6 requirement from it) in which all Windows machines publish their own unique name via DHT's these names can be signed and the address is then quite hard to spoof (ala ToR hidden services), but i doubt that even 5% of Windows power users know about it, and probably less than 5% of those who do use it.
Microsoft Marvel, the Cairo directory service - see Bill Gates (former internal) 1994 memo: "Windows: The Next Killer Application on the Internet": http://www.microsoft.com/about/companyinformation/timeline/t...
"The existing Domain Name System is becomes quickly eclipsed by the Cairo directory service; providing universal resource location services without the need for specialized, arcane applications like archie. Users of the SMTP mail infrastructure take advantage of the advanced features of EMS while remaining backward compatible with their current Internet messaging solutions. Distributed information on the Internet is indexed by Cario and browsed using the Explorer across thousands of information servers worldwide without the need of tools like WAIS and Mosaic. Windows becomes the global infostructure explorer.
The hottest content server on the Internet? Microsoft Marvel. It’s already integrated with all of these services and has a huge content base and commercial vendor support. Perhaps most importantly, Marvel solves the difficult electronic commerce problem well ahead of the Internet: the ability to securely purchase goods in a networked environment. Cairo becomes the clear platform choice for new information providers, offering the most flexibility in both management and technology. OLE Windows applications are now Internet-enabled - people schedule meetings across the Internet and share ideas using Microsoft application products on Windows. No more specialized tools, no more need for Unix to carry the infostructure. Access to the Internet is a natural extension of the base Windows system as well as Microsoft applications."
I personally loath ActiveX, i hate pretty much any tech that require me to load a 3rd party app inside my browsers whether it's the pesky JRE which you can never update because the 1 site you need it for won't support anything past JRE 7.1, or that ancient ActiveX which you need to open in IE10 in IE7 compatibility mode with virtually every security measure disabled. I'm just saying this move might hurt quite a bit of people, but MSFT seems to be moving away from their usual desktop software modus operandai and moving towards becoming more and more of a services providers/SAAS company.
It doesn't mean that if they decide to take out ActiveX it won't hurt allot of people, and even MSFT in the short time, luckily they still will have some sort of backwards compatibility support and i hope it will be available to normal consumers on demand also. Since sorry but once in a while i need to use an ActiveX too, whether it's some old WebEx or Citrix installation or some really outdated SSL VPN and i don't want to keep some Windows XP/7 VM on hand all the time to do it.
I know it's not what the cool kids do, but sadly for people that tend to work with big and sometimes anachronistic enterprises it's a reality.
Right, and nothing will change for those people, because IE will continue to exist for many years. Knowing MS, they'll probably provide patches for it for another 5 years. By then, if people haven't moved on, then some IT folks need to be fired - you've had 15 years to think about upgrading out of ActiveX, really no excuses left.
Is Silverlight proprietary? Is it something that other browsers could not support? Would the maker of this technology put effort in preventing other implementations?
Until all vendors get on board and ditch their idealistic objections (Right or wrong), those plugins will remain.