Disabling IE Scripting in a Useful Manner?
hwyguy2 asks: "Do any Slashdot readers have any insight or pointers on how companies deal
with ActiveX in the IE browser? At the company I'm with, they have taken a
conservative approach, and have the browser configured to only allow ActiveX to internal corporate servers and disallow it anywhere else. Of course, locking that down also locks things like javascript, which the company choses to prompt. This creates many practical problems and user frustrations. It also
makes it a pain for programs that use ActiveX innocously (such as HoTMetal, which seems to like to use an Active X control to get an open file dialog box). Given the number of sites out there that now only work with IE (boo!), this tight configuration is getting harder and harder to support. Are there any good ways to address the ActiveX concerns (maybe filtering servers to block ActiveX or other mobile code concerns)?"
We'd really need more info to answer this.
Are there any ActiveX controls you actually need, or are you just covering your bases by allowing ActiveX inside the company?
What do you need that Mozilla doesn't do?
Why not use Netscape 7 for external access, possibly with the pop-up blocking enabled, and IE for internal use only? Given the continuous security problems found in IE anyhow, using IE on the external internet is a liability anyhow.
Security
Functionality
Guess which side of the fence ActiveX is on.
There isn't an easy answer that isn't going to be flippant.
The opposite of progress is congress
BTW, Proxomitron basically lets you apply regex-like filtering and search/replace to your incoming HTML, so it's useful for a *lot* of stuff.
Google Search for Proxomitron
Please consider making an automatic monthly recurring donation to the EFF
Try Mozilla again. I've removed Internet Explorer from my system, and I have no regrets. I still run into the occasional incompatibility, but no showstoppers. The one inconvenience is that some advertising pops up in the wrong place. Personally, I'm willing to live with it, but of course your milage may vary... :'}
You can control the places where IE looks for ActiveX controls. The magic registry key is
t ernet Settings\CodeBaseSearchPath
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\In
By default you will see CODEBASE in the registry value. That means if there is a CODEBASE parameter in the OBJECT tag on the web page, IE will use it if the correct control version is not installed. However, you can also remove CODEBASE from the string and set this path to a location on your own network, where you place only the small set of trusted ActiveX controls you want your company to use. No other controls will be loaded.
I agree. One thing I love about Mozilla is its absolutely perfect way of handling ActiveX. *grin*
ActiveX and JavaScript are seperate options in my IE:
Tools...->Internet Options->Security->Custom Level...
* Download signed ActiveX controls
Disable Enable Prompt
* Download unsigned ActiveX controls
Disable Enable Prompt
* Initialize and script ActiveX controls not marked as safe
Disable Enable Prompt
* Run ActiveX cotnrols and plug-ins
Administrator approved Disable Enable Prompt
* Script ActiveX controls marked as safe for scripting
Disable Enable Prompt
* Active Scripting (i.e. Javascript)
Disable Enable Prompt
* Allow paste operations via script
Disable Enable Prompt
* Scripting of Java applets
Disable Enable Prompt
It's 10 PM. Do you know if you're un-American?