Netscape 8 to Emphasize Security
wikinerd writes "Netscape is building Netscape 8 which will include several anti-phishing enhancements and will emphasize security. Netscape obtains blacklists of scam and spam sites which will be denied access to ActiveX and cookies. RSS capabilities will also be included in Netscape 8, which will be released on 17 February."
Try just not putting it in at all...
When did THAT happen?
I thought that was one of the reasons to use Netscape/Mozilla/Firefox.... cuz they DIDN'T support ActiveX... ??
Watch the Teaser Trailer for "The Lightning Thief" Her
until fairly recently, most PHBs have never heard of 'firefox' or 'mozilla'. Even now, those who have do not have a clue that all three are related.
The do know the name 'netscape', however; and it's a safe, corporate-friendly name (unlike mozilla or firefox).
I.E.: Speakeasy
e fox/
Just give users an extension:
http://www.speakeasy.net/software/fir
That way, they can keep up to date with Firefox.
Now Netscape, as usual will lag in updates... which means security holes may remain, etc.
If they did an extension, users could likely update with no problems.
The decision to use blacklists with ActiveX is an unfortunate one. In an environment as fluid as the internet scam industry, there will be vastly more new sites set up than human-controlled blacklisting can stop, especially if web servers are set up on botnets of unsuspecting home XP users. Let's just hope the default rendering engine will be Gecko.
Having said that, there are a few javascript phishing techniques that work perfectly well in Firefox with Gecko...
One good turn - gets all the covers.
It seems to me that it would be much, much more secure to allow the user to whitelist sites they wanted to use ActiveX on. For example, Windows Update, and my stupid online paystub page.
I only have a handful of pages that I *need* ActiveX on, and the rest can go pound sand.
Solves the problems of Netscape having to maintain the lists, too.
Keep your friends close.
Keep your enemies in a little jar on your desk.
D3D Games from websites: "Why the fuck would you want to?"
Virus scans from websites: "Why not just have them download and run the fucking executable?"
ActiveX: A virus of a solution still looking for a problem.
How do you make a Direct3D game load from a web site without loading through an ActiveX control?
You don't. You use something that's actually cross-platform and isn't Windows-specific. Not all internet users run Windows (I sure don't). It's the internet, not the Wintelnet.
What about client-side apps that access the file system, such as an ActiveX virus scanner?
They shouldn't. That's not the place for such things. Convenient? Sure. Worth the price? Hell no. There are far better ways to scan for viruses than to give websites full access to every file on your computer.
An analogy would be saying that unless you leave your doors unlocked at all times, how is the cable guy going to fix your TV? Or the telephone guy fix the static on your lines? Or the furnace guy fix the boiler? Sure, we get robbed ever week... but we've GOT to leave our house unlocked for these other things.
And some of us run operating systems that don't get viruses anyhow.