C
Cycloid Torus
Secunia.com has posted some exploits on their website - and my current
configuation "failed" their test (Microsoft Internet Explorer Window
Injection Vulnerability and Microsoft Internet Explorer Two
Vulnerabilities). For the first, the advice given is good which I paraphrase
as - "Do not have any other browser windows open when you connect to and use
a secure site". The "solution" to the second is to keep Internet Zone set to
"High".
Several other security advisories (including the US governement) also
recommend setting Internet Zone to "High" - though this makes using most
commercial sites in which you can have a relatively good degree of
confidence impossible
I am wondering if the structure of the IE Security Zones could be better
employed. Please comment on the idea (friendly criticism invited - I already
know I'm ignorant).
Set Internet Zone to "High" - go to "Custom" - disable everything except
"Pop-up Blocker" (sadly, this means some programs which use ActiveX will
stop working - McAfee VirusScan v8 is one such - I failed to find a "fix"
for this and just "gave up" after weeks of trying)
Set Trusted Zone to "Medium" - enter secure (https
sites into Site list
(so "who" are you going to trust??)
Set Intranet Zone to "Medium" - go to "Custom" and tweak anything that looks
too permissive (suggestions?) - select Sites and Advanced and enter only
those websites in which you have high confidence.
Thanks.
CT
configuation "failed" their test (Microsoft Internet Explorer Window
Injection Vulnerability and Microsoft Internet Explorer Two
Vulnerabilities). For the first, the advice given is good which I paraphrase
as - "Do not have any other browser windows open when you connect to and use
a secure site". The "solution" to the second is to keep Internet Zone set to
"High".
Several other security advisories (including the US governement) also
recommend setting Internet Zone to "High" - though this makes using most
commercial sites in which you can have a relatively good degree of
confidence impossible
I am wondering if the structure of the IE Security Zones could be better
employed. Please comment on the idea (friendly criticism invited - I already
know I'm ignorant).
Set Internet Zone to "High" - go to "Custom" - disable everything except
"Pop-up Blocker" (sadly, this means some programs which use ActiveX will
stop working - McAfee VirusScan v8 is one such - I failed to find a "fix"
for this and just "gave up" after weeks of trying)
Set Trusted Zone to "Medium" - enter secure (https

(so "who" are you going to trust??)
Set Intranet Zone to "Medium" - go to "Custom" and tweak anything that looks
too permissive (suggestions?) - select Sites and Advanced and enter only
those websites in which you have high confidence.
Thanks.
CT