<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://windowsteamblog.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Windows Security Blog : Internet Explorer 8</title><link>http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Internet+Explorer+8/default.aspx</link><description>Tags: Internet Explorer 8</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP1 (Build: 30619.63)</generator><item><title>Windows 7 Vulnerability Claims</title><link>http://windowsteamblog.com/blogs/windowssecurity/archive/2009/11/06/windows-7-vulnerability-claims.aspx</link><pubDate>Sat, 07 Nov 2009 00:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:527942</guid><dc:creator>Paul Cooke</dc:creator><slash:comments>25</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://windowsteamblog.com/blogs/windowssecurity/rsscomments.aspx?PostID=527942</wfw:commentRss><comments>http://windowsteamblog.com/blogs/windowssecurity/archive/2009/11/06/windows-7-vulnerability-claims.aspx#comments</comments><description>&lt;p&gt;Now that Windows 7 is available, a recent blog by Chester Wisnieski (who works at security vendor Sophos), entitled &lt;a href="http://www.sophos.com/blogs/chetw/g/2009/11/03/windows-7-vulnerable-8-10-viruses"&gt;Windows 7 vulnerable to 8 out of 10 viruses&lt;/a&gt;, which has stirred some interest.&lt;/p&gt;
&lt;p&gt;Here's a quick summary for those who missed Chester's blog. During a test SophosLabs conducted, they subjected Windows 7 to "10 unique [malware] samples that arrived in the SophosLabs feed." They utilized a clean install of Windows 7, using default settings (including the UAC defaults), but did not install any anti-virus software. The end result was 8 of the 10 malware samples successfully ran and the blog proclaims that "Windows 7 disappointed just like earlier versions of Windows." Chester's final conclusion? "You still need to run anti-virus on Windows 7." Well, we agree: users of any computer, on any platform, should run anti-virus software, including those running Windows 7.&lt;/p&gt;
&lt;p&gt;Clearly, the findings of this unofficial test are by no means conclusive, and several members of the press have picked apart the findings, so I don't need to do that. I'm a firm believer that if you run unknown code on your machine, bad things can happen. This test shows just that; however, most people don't knowingly have and run known malware on their system. Malware typically makes it onto a system through other avenues like the browser or email program. So while I absolutely agree that anti-virus software is essential to protecting your PC, there are other defenses as well. &lt;/p&gt;
&lt;p&gt;Let me recap some of the Windows 7 security basics. Windows 7 is built upon the security platform of Windows Vista, which included a defense-in-depth approach to help protect customers from malware. This includes features like User Account Control (UAC), Kernel Patch Protection, Windows Service Hardening, Address Space Layout Randomization (ASLR), and Data Execution Prevention (DEP) to name just a few. The result, Windows 7 retains and refines the development processes, including going through the Security Development Lifecycle, and technologies that made Windows Vista the most secure Windows operating system ever released.&lt;/p&gt;
&lt;p&gt;Beyond the core security of Windows 7, we have also done a lot of work with Windows 7 to make it harder for malware to reach a user's PCs in the first place. One of my favorite new features is the SmartScreen Filter in Internet Explorer 8. The SmartScreen Filter was built upon the phishing protection in Internet Explorer 7 and (among other new benefits) adds protection from malware. The SmartScreen Filter will notify you when you attempt to download software that is unsafe - which the SophosLabs methodology totally bypassed in doing their test.&lt;/p&gt;
&lt;p&gt;So while I'm not a fan of companies sensationalizing findings about Windows 7 in order to sell more of their own software, I nevertheless agree with them that you still need to run anti-virus software on Windows 7.&amp;nbsp; This is why we've made our &lt;a href="http://www.microsoft.com/security_essentials/"&gt;Microsoft Security Essentials&lt;/a&gt; offering available for free to customers. But it's also equally important to keep all of your software up to date through automatic updates, such as through the Windows Update service. By configuring your computers to download and install updates automatically you will help ensure that you have the highest level of protection against malware and other vulnerabilities.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=527942" width="1" height="1"&gt;</description><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx">Security</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Security/default.aspx">Windows Security</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/IT+Pro/default.aspx">IT Pro</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows/default.aspx">Windows</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx">Windows 7</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security+Development+Lifecycle/default.aspx">Security Development Lifecycle</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Internet+Explorer+8/default.aspx">Internet Explorer 8</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Update/default.aspx">Windows Update</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/UAC/default.aspx">UAC</category></item><item><title>Internet Explorer 8 Security</title><link>http://windowsteamblog.com/blogs/windowssecurity/archive/2009/04/24/internet-explorer-8-security.aspx</link><pubDate>Fri, 24 Apr 2009 20:20:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:512160</guid><dc:creator>Paul Cooke</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://windowsteamblog.com/blogs/windowssecurity/rsscomments.aspx?PostID=512160</wfw:commentRss><comments>http://windowsteamblog.com/blogs/windowssecurity/archive/2009/04/24/internet-explorer-8-security.aspx#comments</comments><description>&lt;p&gt;Here is another story from a Microsoft Program Manger discussing their favorite things in Windows 7. This time it is Eric Lawrence (Senior Program Manager on the Internet Explorer Team) to talk about his favorite security features in Internet Explorer 8, the browser that ships in Windows 7.&lt;/p&gt; &lt;iframe height="326" src="http://www.microsoft.com/video/en/us/player/embed/17020a8a-b7e1-43fe-9ade-8179ed4fe3bf" frameborder="0" width="430" allowtransparency="allowtransparency" scrolling="no"&gt;&lt;/iframe&gt;  &lt;br /&gt;&lt;a href="http://www.microsoft.com/video/en/us/details/17020a8a-b7e1-43fe-9ade-8179ed4fe3bf?vp_evt=eref&amp;amp;vp_video=Eric+Lawrence+Discusses+His+Favorite+Internet+Explorer+Security+Features"&gt;Eric Lawrence Discusses His Favorite Internet Explorer Security Features&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=512160" width="1" height="1"&gt;</description><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx">Security</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+7/default.aspx">Windows 7</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx">RSA</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Internet+Explorer+8/default.aspx">Internet Explorer 8</category></item><item><title>End to End Trust and Windows 7</title><link>http://windowsteamblog.com/blogs/windowssecurity/archive/2009/04/21/end-to-end-trust-and-windows-7.aspx</link><pubDate>Tue, 21 Apr 2009 17:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:512016</guid><dc:creator>Paul Cooke</dc:creator><slash:comments>14</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://windowsteamblog.com/blogs/windowssecurity/rsscomments.aspx?PostID=512016</wfw:commentRss><comments>http://windowsteamblog.com/blogs/windowssecurity/archive/2009/04/21/end-to-end-trust-and-windows-7.aspx#comments</comments><description>&lt;p&gt;I attended Scott Charney&amp;rsquo;s keynote this morning at RSA &amp;ndash; &lt;i&gt;Moving Towards End to End Trust: A Collaborative Effort&lt;/i&gt;. I would assume that many of the readers of this blog are not familiar with the End to End Trust story. In a nutshell, End to End trust is Microsoft&amp;rsquo;s vision for creating a safer, more trusted Internet. It&amp;rsquo;s a great vision, but it&amp;rsquo;s also a big job that requires a commitment and focus on the fundamentals&amp;mdash;fundamentals that will help deliver the most secure and privacy-enhanced versions of software and services that we have ever delivered. We&amp;rsquo;re also not going it alone. End to End Trust requires broad collaboration within the industry and Microsoft will continue to share our best practices with the IT communities of our customers.&lt;/p&gt;
&lt;p&gt;Scott talked about how hard we are working across Microsoft to deliver technology innovations that move the needle towards a trusted stack, with security rooted in hardware and an identity metasystem (a big word that means a way of trusting people are who they say they are on the Internet). Even with progress, people still need strong defense in depth security technologies and Scott talked about how Microsoft&amp;rsquo;s Identity and Security Division is delivering integrated identity and security business solutions today to our customers. But maybe the most interesting thing he touched on was how technology innovations alone are not enough. Innovation also needs to align with political, economic and IT forces to enable the change that is truly needed. &lt;/p&gt;
&lt;p&gt;End to End trust is a vision of what&amp;rsquo;s possible if we collectively work together, and it can help address real world problems that people face every day such as ID theft, online fraud and child safety. If you want to learn more about End to End Trust, visit &lt;a href="http://www.microsoft.com/endtoendtrust"&gt;http://www.microsoft.com/endtoendtrust&lt;/a&gt; to find out the entire story. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/Windows7_5F00_h_5F00_rgb_5F00_0EC4F31F.png"&gt;&lt;img height="38" width="240" src="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/windowssecurity/Windows7_5F00_h_5F00_rgb_5F00_thumb_5F00_5BF4ECAA.png" alt="Windows7_h_rgb" border="0" title="Windows7_h_rgb" style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" /&gt;&lt;/a&gt; &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Now, let&amp;rsquo;s talk about Windows 7 and the progress we&amp;rsquo;re making to deliver End to End Trust in the Windows platform. In my &lt;a href="http://windowsteamblog.com/blogs/windowssecurity/archive/2009/04/20/windows-7-security-helping-enable-the-mobile-workforce.aspx"&gt;blog post yesterday&lt;/a&gt; on how Windows 7 helps enable the mobile workforce, I wrote about technologies like DirectAccess, BitLocker To Go, and AppLocker. Each of these technologies plays a part in helping us enable End to End Trust, whether it is strong machine and user authentication with DirectAccess or limiting running software on a system to known, trusted applications with AppLocker. But there are other technologies that help us as well:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Biometric Framework&lt;/b&gt; &lt;br /&gt;Fingerprint scanners are becoming more and more common in standard laptop configurations&amp;mdash;my laptop came standard with one. Windows 7 helps ensure that fingerprint readers work well and that they are easy to set up and use. This is accomplished by taking the common code that everyone needs to write and standardizing it in the platform so that biometric hardware vendors can concentrate on the code they need to write to make their device work and not have to worry about how it ties into Windows. This new framework makes logging on to Windows using a fingerprint more reliable across different hardware providers and makes fingerprint reader configurations are easy to modify. This puts the user in control of how they log on to Windows 7 and manage the fingerprint data stored on their PC.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Improved Smart Card Support&lt;/b&gt; &lt;br /&gt;Password-based authentication has well-understood security limitations; however, deploying strong authentication technologies like smart cards remains a challenge for many. Windows 7 enhances the smart card infrastructure advances made in Windows Vista through support of Plug and Play. This eases deployment of smart card infrastructures because drivers for both smart cards and smart card readers are automatically installed, without the need for administrative permissions or user interaction. I think this new behavior is going to ease the deployment of strong, two-factor authentication for many organizations.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;BitLocker &lt;br /&gt;&lt;/b&gt;I&amp;rsquo;m a big fan of BitLocker, it helps prevent a thief who boots another operating system or runs a software hacking tool from breaking into my laptop if they happen to get a hold of it. This holds true for both the operating system volume (C: drive) and my data volume (D: drive). Most customers I talk to love the encryption protection that BitLocker provides, but many are not aware that BitLocker also does integrity checking of early boot components to help ensure that the system has not been tampered with and that the encrypted drive has not been swapped out to another computer. This integrity checking ties back into the &amp;ldquo;security rooted in hardware&amp;rdquo; that is a part of End to End Trust. This integrity checking utilizes a Trusted Platform Module (a smart card like chip on the system motherboard) to help protect the encryption keys utilized by BitLocker. This is true for BitLocker in Windows 7 as well as Windows Vista.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve also listened to feedback and made enhancements to Windows 7 BitLocker to provide a better experience for IT Pros and for end users. One of the simple enhancements we made is to right-click enable the BitLocker protection of a disk volume. Now I can go to Windows Explorer and right click any disk volume, including my removable BitLocker To Go volumes, and encrypt them right there without having to go to the Control Panel. &lt;/p&gt;
&lt;p&gt;Another big change was the addition of Data Recovery Agent (DRA) support for all protected volumes. The DRA is a certificate-based data recovery agent that can be utilized to recover the contents of any BitLocker protected volume. Since the group policy settings are separate for Operating System Drives, Fixed Data Drives, and Removable Data Drives, customers have flexibility in how they want to configure their recovery options for the different threats that each separate drive type may experience. &lt;/p&gt;
&lt;p&gt;With BitLocker and BitLocker To Go, enterprises can rest assured that their information and data is secure, no matter where their employees are working. I know I feel better knowing my laptop and all of my USB sticks are protected!&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Internet Explorer 8&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;I know folks are more concerned than ever about protecting themselves while online, particularly form identity theft, malware, and other potentially dangerous online threats. I feel like we have done a lot in the platform and the security technologies we have been talking about this week (Firewall, DirectAccess, BitLocker To Go and AppLocker) are a part of the protection equation. But Internet Explorer 8 is also another huge piece of the equation as users spend more time online, in their browsers. IE 8 is the most secure web browser on the market and provides another, vital layer of defense against online threats.&lt;/p&gt;
&lt;p&gt;We built upon the phishing protection in Internet Explorer 7 with the SmartScreen Filter, which now adds protection from malware &amp;ndash; a threat that is growing significantly faster than phishing.&lt;/p&gt;
&lt;p&gt;We also built in support for protecting users against type-1 (or &amp;ldquo;reflection) Cross-Site Scripting (XSS) attacks. XSS threats try to exploit vulnerabilities in the websites we visit and are quickly becoming one of the most prevalent ways web sites can be compromised. The bad news for you and I is that an XSS attack can help a bad guy steal our usernames and passwords for our online bank accounts or other confidential information. The XSS filter in IE 8 uses heuristics to detect such attacks and, when they are detected, prevent their execution. This should help you and I safe from the most common form of XSS attacks in use today.&lt;/p&gt;
&lt;p&gt;Another innovation concerns ClickJacking. While a lot or people have heard of phishing attacks, a new kind of phishing attack called ClickJacking is on the rise. ClickJacking occurs where an attacker&amp;rsquo;s web page deceives a person into clicking on content from another website without realizing it &amp;ndash; so they&amp;rsquo;re clicking on something that, for instance, buys something from the site, changes settings on their browser, or provides advertisements that these cybercriminals get paid for. ClickJacking Protection in IE is a feature that allows Web site content owners to put a tag in a page header that will help prevent ClickJacking. &lt;/p&gt;
&lt;p&gt;I think the IE team has done a great job with the security in IE 8 and love that it puts people in control of their safety and privacy and helps protect them from new online threats. For those of you who are interested, there is a lot more security goodness in IE 8 on the &lt;a href="http://blogs.msdn.com/ie/"&gt;IE blog&lt;/a&gt; and via these links:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx"&gt;IE8 Security Part I: DEP/NX Memory Protection&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/05/07/ie8-security-part-ii-activex-improvements.aspx"&gt;IE8 Security Part II: ActiveX Improvements&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iii-smartscreen-filter.aspx"&gt;IE8 Security Part III: SmartScreen&amp;reg; Filter&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"&gt;IE8 Security Part IV: The XSS Filter&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-v-comprehensive-protection.aspx"&gt;IE8 Security Part V: Comprehensive Protection&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2008/09/02/ie8-security-part-vi-beta-2-update.aspx"&gt;IE8 Security Part VI: Beta 2 Update&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2009/01/27/ie8-security-part-vii-clickjacking-defenses.aspx"&gt;IE8 Security Part VII: ClickJacking Defenses&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2009/02/09/ie8-security-part-viii-smartscreen-filter-release-candidate-update.aspx"&gt;IE8 Security Part VIII: SmartScreen Filter Release Candidate Update&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx"&gt;IE8 Security Part IX - Anti-Malware protection with IE8&amp;rsquo;s SmartScreen Filter&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Got To Run&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I feel great about Windows 7 and the security enhancements we have been able to make. Hopefully as you learn more about the security work that we have put into it, you will reach the same conclusion that I have: Windows 7 is the most robust platform we have ever delivered, it helps support End to End trust, helps keep you and I safe, and was designed to prevent malware from getting onto our PCs to begin with.&lt;/p&gt;
&lt;p&gt;There is a lot going on here at RSA and I want to go spend some more time seeing what&amp;rsquo;s new and exciting. I&amp;rsquo;ll be back with some of my impressions of RSA in a bit.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://windowsteamblog.com/aggbug.aspx?PostID=512016" width="1" height="1"&gt;</description><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Security/default.aspx">Security</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/RSA/default.aspx">RSA</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Clickjacking/default.aspx">Clickjacking</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Windows+Biometric+Framework/default.aspx">Windows Biometric Framework</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/SmartScreen/default.aspx">SmartScreen</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Smart+Card/default.aspx">Smart Card</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/End+to+End+Trust/default.aspx">End to End Trust</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Internet+Explorer+8/default.aspx">Internet Explorer 8</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/BitLocker/default.aspx">BitLocker</category><category domain="http://windowsteamblog.com/blogs/windowssecurity/archive/tags/Biometrics/default.aspx">Biometrics</category></item></channel></rss>