<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx</link><description>Back in November, we announced our intention to bring Extended Validation SSL Certificates to IE7 . This week at RSA we’ve announced that IE7’s EV SSL support is now live! Many Certification Authorities (CAs), including VeriSign, CyberTrust, Entrust and</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1613846</link><pubDate>Tue, 06 Feb 2007 23:29:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1613846</guid><dc:creator>cooperpx</dc:creator><description>&lt;p&gt;@ Jeremy Dallman&lt;/p&gt;
&lt;p&gt;Have you ever noticed how IE7 no longer provides you any information about an untrusted certificate (ie: self-signed) before accepting it ?&lt;/p&gt;
&lt;p&gt;File -&amp;gt; Properties -&amp;gt; Certificates = Error message saying no certificate is present.&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1613866</link><pubDate>Tue, 06 Feb 2007 23:36:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1613866</guid><dc:creator>cooperpx</dc:creator><description>&lt;p&gt;@ Jeremy Dallman&lt;/p&gt;
&lt;p&gt;(Sorry for the double post) It would also seem that if you install the 'bad' certificate the bar stays red until you restart IE7?&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1613886</link><pubDate>Tue, 06 Feb 2007 23:44:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1613886</guid><dc:creator>SurrealLogic</dc:creator><description>&lt;p&gt;Sorry to be off topic, but does anyone else have an issue with horrible flickering problems in IE7 on Vista Ultimate? Firefox is fine, I think I have the latest drivers, but anything Flash or animated javascript flickers like crazy. Any thoughts?&lt;/p&gt;
</description></item><item><title>Microsoft releases new and updated information about Extended Validation and IE7</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1613918</link><pubDate>Tue, 06 Feb 2007 23:54:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1613918</guid><dc:creator>Spyware Sucks</dc:creator><description>&lt;p&gt;As I have noted a couple of times over the past couple of days, IE7 Extended Validation has gone live:&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1613941</link><pubDate>Wed, 07 Feb 2007 00:03:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1613941</guid><dc:creator>TMaster</dc:creator><description>&lt;p&gt;Strange, my address bar doesn't turn green when visiting those sites, not even when I turn on the automatic phishing filter.&lt;/p&gt;
&lt;p&gt;In fact, when I visit the Woodgrove Bank demonstration site, it turns red, because I haven't accepted the certificate authority.&lt;/p&gt;
&lt;p&gt;Is this normal behavior - I seem to recall Extended Validation not being enabled yet, but I thought it would be fully functioning in february 2007?&lt;/p&gt;
&lt;p&gt;What error am I making? The certificate does say &amp;quot;Extended Validation&amp;quot; in it.&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1614049</link><pubDate>Wed, 07 Feb 2007 00:38:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1614049</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>&lt;p&gt;TMaster: I assume you're using Windows XP?&lt;/p&gt;
&lt;p&gt;Try visiting &lt;a rel="nofollow" target="_new" href="https://www.verisign.com"&gt;https://www.verisign.com&lt;/a&gt; first. &amp;nbsp;&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1614061</link><pubDate>Wed, 07 Feb 2007 00:41:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1614061</guid><dc:creator>Sylva Lisko</dc:creator><description>&lt;p&gt;Since we have downloaded the new EI7 last year&lt;/p&gt;
&lt;p&gt;there is just trouble - error msgs, pages not responding, everything is slow.&lt;/p&gt;
&lt;p&gt;on our other laptop we kept the EI6 and all is perfect.&lt;/p&gt;
&lt;p&gt;can we go back from EI 7 to EI 6 on our PC?&lt;/p&gt;
&lt;p&gt;thank you&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1614086</link><pubDate>Wed, 07 Feb 2007 00:53:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1614086</guid><dc:creator>Tim</dc:creator><description>&lt;p&gt;Taking research from Gartner at face value is NOT wise advice.&lt;/p&gt;
</description></item><item><title>10 Million Phishing Attempts Thwarted Since October</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1614303</link><pubDate>Wed, 07 Feb 2007 01:53:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1614303</guid><dc:creator>Kirk Allen Evans' Blog</dc:creator><description>&lt;p&gt;This is such a cool story. Two years ago, Bill Gates announced IE7 at RSA highlighting the Phishing Filter&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1614688</link><pubDate>Wed, 07 Feb 2007 02:29:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1614688</guid><dc:creator>Sandi Hardmeier</dc:creator><description>&lt;p&gt;Tmaster,&lt;/p&gt;
&lt;p&gt;You need to turn on your phishing filter, and set it to automatic, *and* ensure server certificate revocation checking is not turned off, to see the green bar.&lt;/p&gt;
&lt;p&gt;The red certificate at Woodgrove is to be expected; the *testing* certificate was not issued by a trusted authority, that is, it was issued by &amp;quot;Microsoft Enhanced Validation Testing PCA&amp;quot;. &amp;nbsp;To see the list of trusted authorities, go to tools, internet options, content tab, certificates button, trusted root certification authorities.&lt;/p&gt;
&lt;p&gt;Sandi&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1615191</link><pubDate>Wed, 07 Feb 2007 03:25:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1615191</guid><dc:creator>AK</dc:creator><description>&lt;p&gt;I faced 2 Problems with IE 7&lt;/p&gt;
&lt;p&gt;1. First time when I enter any domain name and press Ctrl+Enter IE7 hangs for almost 30 sec.&lt;/p&gt;
&lt;p&gt;2. If I sign into multiple sites using tabs and logout from any of the sites, I get logged out from all other sites. may be a cookie problem..i guess!??&lt;/p&gt;
</description></item><item><title>Microsoft CardSpace interop with OpenID announced at RSA</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1615565</link><pubDate>Wed, 07 Feb 2007 04:17:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1615565</guid><dc:creator>Microsoft News Tracker</dc:creator><description>&lt;p&gt;Today, Bill Gates and Craig Mundie keynoted the RSA Conference 2007 and announced a variety of security related Microsoft initiatives. Perhaps the biggest news was announced in detail on the blog of Microsoft&amp;amp;#8217;s Kim Cameron where Microsoft p...&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1615615</link><pubDate>Wed, 07 Feb 2007 04:24:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1615615</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>&lt;p&gt;@Sandi: Actually, ~either~ setting the Phishing Filter to Automatic ~OR~ enabling Server Certificate Revocation Checking is sufficient.&lt;/p&gt;
&lt;p&gt;@AK: Do you see the delay if you type the &amp;quot;http://&amp;quot; before the domain name? &amp;nbsp;&lt;/p&gt;
&lt;p&gt;What sites are you logging out of? &amp;nbsp;Logging out of some sites (like Outlook Web Access) will clear your session cookies.&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1616393</link><pubDate>Wed, 07 Feb 2007 08:07:28 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1616393</guid><dc:creator>Jerry Pisk</dc:creator><description>&lt;p&gt;What I don't get is why the need for EV certs? If the existing certificates are being issued to anyone who asks for them without any verification wouldn't the fix to that problem be to start validating cert requests? EV certs are basically an acknowledgment of the fact that regular certs are not trustworthy. As such, those shouldn't be trusted at all.&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1617309</link><pubDate>Wed, 07 Feb 2007 10:24:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1617309</guid><dc:creator>Michael</dc:creator><description>&lt;p&gt;are u sure a GREEN address shows up when navigates to websites like Verisign in WinXP?&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1617794</link><pubDate>Wed, 07 Feb 2007 11:23:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1617794</guid><dc:creator>Tony</dc:creator><description>&lt;p&gt;@ Sylva, visit the IE7 support site for free technical support, &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/windows/products/winfamily/ie/iefaq.mspx"&gt;http://www.microsoft.com/windows/products/winfamily/ie/iefaq.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;@ Jerry, I agree completely. Verification sites must do their job, otherwise we will continue to have escalations of new certificates with new names that eventually become obsolete themselves. The system is flawed, please don't propagate it any further until it's been fixed.&lt;/p&gt;
&lt;p&gt;Also announced today By Bill Gates and Craig Mundie is the continued development of IPv6 and IP/Sec. Mr.gates was even quoted:&lt;/p&gt;
&lt;p&gt;“Passwords are not only weak, the more you get of them, the worse it is,” Mr. Gates said. “We see smart cards, in specific, but certificates in general as the way to go.”&lt;/p&gt;
&lt;p&gt;Are the EV and future certificates what Bill was referring too? If so Jerry's comment has merit and needs to be resolved before standards such as OpenID and CardSpace become compromised as well.&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1618508</link><pubDate>Wed, 07 Feb 2007 13:41:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1618508</guid><dc:creator>Viktor Krammer</dc:creator><description>&lt;p&gt;@IE team&lt;/p&gt;
&lt;p&gt;It would be nice if you could add a new SecureLockIconConstant identifying EV SSL connections to the DWebBrowserEvents2::SetSecureLockIcon event so that security add-ons for IE can take advantage of the new EV certificates as well.&lt;/p&gt;
&lt;p&gt;Regarding UI flickering: The status bar and the small edge between the tab bar and the actual Web content frame still flickers if switching tabs.&lt;/p&gt;
&lt;p&gt;Any plans on allowing us to report bugs we find in IE again? The connect bug database was a good approach, but was unfortunately turned off after RTM.&lt;/p&gt;
&lt;p&gt;Besides, congratulations on launching Vista and EV SSL.&lt;/p&gt;
</description></item><item><title>IE7 is HORRIBLE!</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1618981</link><pubDate>Wed, 07 Feb 2007 15:32:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1618981</guid><dc:creator>islander</dc:creator><description>&lt;p&gt;Since I installed IE7 I have had MAJOR hiccups of one kind or another....... now it won't even load up pages of ANY sort...........&lt;/p&gt;
&lt;p&gt;I am on Windows XP (home) and do NOT intend to go over to VISTA because it is a wannabe MAC platform and I should have gone Mac instead of staying with windows because it just keeps crashing and crashing and hanging and hanging!&lt;/p&gt;
&lt;p&gt;I don't know way there is a new UNimproved version of IE for non techies..........&lt;/p&gt;
</description></item><item><title>re: IE7 and Go button (Address Bar)</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1620327</link><pubDate>Wed, 07 Feb 2007 19:03:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1620327</guid><dc:creator>say2joe</dc:creator><description>&lt;p&gt;How can the Go button (used with the Address Bar on the Taskbar) be removed now that the option to remove it is no longer included with IE7 Advanced Options? I've already done a few searches of the registry with no success.&lt;/p&gt;
&lt;p&gt;I'm using XP Pro with IE7 (/w latest updates).&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1620895</link><pubDate>Wed, 07 Feb 2007 21:17:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1620895</guid><dc:creator>Aedrin</dc:creator><description>&lt;p&gt;&amp;quot;Since I installed IE7 I have had MAJOR hiccups of one kind or another....... now it won't even load up pages of ANY sort...........&lt;/p&gt;
&lt;p&gt;I am on Windows XP (home) and do NOT intend to go over to VISTA because it is a wannabe MAC platform and I should have gone Mac instead of staying with windows because it just keeps crashing and crashing and hanging and hanging!&amp;quot;&lt;/p&gt;
&lt;p&gt;The obligatory car reference:&lt;/p&gt;
&lt;p&gt;If people who owned cars kept buying all these third party components and never got it serviced, how long do you think it would last?&lt;/p&gt;
&lt;p&gt;Do you really think a Mac will improve your experience?&lt;/p&gt;
&lt;p&gt;Are you a victim of marketing lies?&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1622054</link><pubDate>Thu, 08 Feb 2007 01:01:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1622054</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>&lt;p&gt;@say2joe: Remove the &amp;quot;Go&amp;quot; button from the Addressbar in your task bar by opening Windows Explorer (not IE) and right-clicking on the &amp;quot;Go&amp;quot; button there, then unchecking &amp;quot;Go button&amp;quot;.&lt;/p&gt;
&lt;p&gt;@Viktor Krammer: Yes, SecureLockIconConstant would be a good start, but at the moment, we don't expose a good way for extensions to grab the certificate itself, so the constant alone likely would not be enough.&lt;/p&gt;
&lt;p&gt;@Jerry Pisk: The issue is that there's no standard for what type of validation is performed for a non-EV certificate. &amp;nbsp;Each CA sets their own policies, and some are stronger than others. &amp;nbsp;In contrast, the EV guidelines that IE7 supports specify the exact bar for vetting the identity information for all CAs. &lt;/p&gt;
&lt;p&gt;Implying that non-EV SSL isn't trustworthy isn't exactly correct; it's fair to say that it ensures the privacy and integrity of the connection, but provides only limited verification of the identity of the remote server. &amp;nbsp;At a minimum, it ensures that the registered owner of the domain name (which itself be misleading) is able to respond to certificate registration confirmation mails. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Hence, EV was created to offer a higher and standardized level of assurance of the identity of the remote server.&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1623132</link><pubDate>Thu, 08 Feb 2007 04:40:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1623132</guid><dc:creator>Alex</dc:creator><description>&lt;p&gt;I found a very tiny bug in the Address Bar when using EV SSL Certificates, see the image at this url (nevermind the JPEG-corruption):&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://swb.alex-media.nl/photos/C11184B4-C845-E8B2-EB1F-CD4394DB6A82.jpg"&gt;http://swb.alex-media.nl/photos/C11184B4-C845-E8B2-EB1F-CD4394DB6A82.jpg&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;What you're looking at: the company name should be 'Charles Schwab &amp;amp; Co., Inc. [US]'. You see: 'Charles Schwab _Co., Inc. [US]'&lt;/p&gt;
&lt;p&gt;The problem is caused by the company name having an ampersand in it. It is displayed as a _ because that's Windows mnemonic-key. When you click on the icon, the correct company name is displayed.&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1624454</link><pubDate>Thu, 08 Feb 2007 09:23:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1624454</guid><dc:creator>TMaster</dc:creator><description>&lt;p&gt;Sandi, thank you!&lt;/p&gt;
&lt;p&gt;I wasn't so much surprised the Woodgrove Bank side had a red bar, it made sense to me, since I knew it was self-signed. Sorry if I didn't make this clear.&lt;/p&gt;
&lt;p&gt;However, your comment that the certificate revocation has to be enabled solved the problem for me. I doubt this is the default setting anyway, I just cannot remember turning it off.&lt;/p&gt;
&lt;p&gt;I guess this was an obvious case of PEBKAC. And thanks to Eric for the reply as well =)&lt;/p&gt;
</description></item><item><title>Un milion de încercări de phishing pe săptămână</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1627010</link><pubDate>Thu, 08 Feb 2007 15:49:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1627010</guid><dc:creator>Weblogul lui Zoli</dc:creator><description>&lt;p&gt;At&amp;#226;t oprește Phishing Filter-ul din IE7 . De la lansarea lui &amp;#238;n octombrie, Internet Explorer 7 a blocat&lt;/p&gt;
</description></item><item><title>re: IE7 at RSA San Francisco</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#1630118</link><pubDate>Fri, 09 Feb 2007 01:30:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1630118</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>&lt;p&gt;@Alex: Nice catch, and your analysis is spot on.&lt;/p&gt;
&lt;p&gt;This bug was only discovered after we shipped IE7; we'll be fixing it in a future version.&lt;/p&gt;
</description></item><item><title>Extended Validation Guidelines v1 Released!</title><link>http://blogs.msdn.com/ie/archive/2007/02/06/IE7-at-RSA-San-Francisco.aspx#3259939</link><pubDate>Wed, 13 Jun 2007 04:57:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3259939</guid><dc:creator>IEBlog</dc:creator><description>&lt;p&gt;I’ve talked several times in the past about Extended Validation SSL certificates and how they are a great&lt;/p&gt;
</description></item></channel></rss>