<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx</link><description>As you probably know by now, XP SP2 RC1 is publicly available at http://www.microsoft.com/technet/prodtechnol/winxppro/sp2preview.mspx . Over the next week or so I'll give an overview of a few of the security features the browser UI team has been working</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93440</link><pubDate>Sun, 21 Mar 2004 10:11:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93440</guid><dc:creator>Edward</dc:creator><description>I see some of the add-on just have CLSIDs for names. How do we find out what they are, where they came from, and if they are potentially harmful? &lt;br&gt;Also the name that does appear is under the control of the publisher I assume so we are bound to see more things like &amp;quot;Really Whizzy Cool Toolbar Button&amp;quot; than &amp;quot;Cover You With Advertising Tracker&amp;quot; which doesn't help with the confusion of who is good and who is bad. Not that I think there is much you can do about it.</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93497</link><pubDate>Sun, 21 Mar 2004 16:42:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93497</guid><dc:creator>dr.u</dc:creator><description>Finally, I can block Gator for life!</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93515</link><pubDate>Sun, 21 Mar 2004 18:37:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93515</guid><dc:creator>Pavel Lebedinsky</dc:creator><description>&amp;gt; Not that I think there is much you can do about it.&lt;br&gt;&lt;br&gt;You could probably write a KB article about how I can find the actual DLL that implements an add-on, and link to this article from the help topic that comes up when I click on &amp;quot;Learn more about add-ons&amp;quot;. Or may be add a &amp;quot;File name&amp;quot; column to the list view.&lt;br&gt;&lt;br&gt;Hmm... I just right-clicked on the list view header and there's a CLSID column that's initially hidden. That's nice but the actual binary name would have been even better.&lt;br&gt;&lt;br&gt;It looks like at least some of the add-ons with broken display names are made by Microsoft. Do you already have bugs for these?&lt;br&gt;</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93519</link><pubDate>Sun, 21 Mar 2004 18:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93519</guid><dc:creator>Pavel Lebedinsky</dc:creator><description>My other issue is with the Update ActiveX button. I'm scared to click on it because it's not clear what will happen. Will it always ask for confirmation? Will it tell me what *exactly* it is trying to install?&lt;br&gt;&lt;br&gt;It looks like it's doing the right thing, but you should probably describe it in more detail in the help.&lt;br&gt;&lt;br&gt;Also, can you change the button label to read &amp;quot;Update ActiveX...&amp;quot; to make it clear that it will ask for confirmation?</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93530</link><pubDate>Sun, 21 Mar 2004 19:30:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93530</guid><dc:creator>Tony Schreiner</dc:creator><description>I'll look into the CLSID issue. I believe we show this only when there is absolutely no other information available.&lt;br&gt;&lt;br&gt;Ultimately, we'll look at the information in the digital signature first, fall back on the version info (with a note) if we have to, then the filename, and finally the CLSID as a last resort.&lt;br&gt;&lt;br&gt;And yeah, even with an Authenticode signature it's possible for a spyware/malware provider to name their control &amp;quot;Whizzy Cool Toolbar Button&amp;quot;, making it impossible to discern the good from the bad at a glance. Think of Manage Add-ons as a good first step for giving you control that you didn't have before.</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93531</link><pubDate>Sun, 21 Mar 2004 19:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93531</guid><dc:creator>Tony Schreiner</dc:creator><description>Pavel, I'll see what we can do about the &amp;quot;Update ActiveX&amp;quot; button.</description></item><item><title>IE in XP SP2 (Part 2): Information Bar - Stopping the modal dialog madness</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93552</link><pubDate>Sun, 21 Mar 2004 23:43:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93552</guid><dc:creator>Tony Schreiner's WebLog</dc:creator><description /></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93611</link><pubDate>Sun, 21 Mar 2004 23:50:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93611</guid><dc:creator>Tom Gilder</dc:creator><description>That new authenticode dialog is so well designed and *SUCH* and improvement on the old one.&lt;br&gt;&lt;br&gt;I wouldn't like to even take a guess as to how many computers have been compromised and generally mucked up by users not understanding the previous dialog and trying to make it go away by clicking yes.&lt;br&gt;&lt;br&gt;It's going to seriously annoy companies who have put entire disclaimers in the software name though, I wonder what the legal aspects of that are? Some controls put an entire license in their name, which now simply isn't displayed. Could anyone blame MS for not showing all of the text?&lt;br&gt;&lt;br&gt;Also, whilst on the subject of XP SP2, if you download a signed EXE to the desktop and run it, it gives you a security dialog. But if you do the same with an unsigned EXE, it runs it without a prompt - is this a bug?</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93647</link><pubDate>Mon, 22 Mar 2004 02:06:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93647</guid><dc:creator>Tom Gilder</dc:creator><description>Er, actually, ignore that - now seems to be working again.&lt;br&gt;&lt;br&gt;But if you save an EXE locally and then click open on the completed download dialog, it never shows any of the security warnings, now that surely is a bug? :)</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93654</link><pubDate>Mon, 22 Mar 2004 03:08:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93654</guid><dc:creator>Tony Schreiner</dc:creator><description>Tom, thanks for the comments. I don't want to speculate on the legal issues of truncating the name, except to say that overloading the application name string to include a mini-EULA is dubious to begin with, and probably isn't proper notice.&lt;br&gt;&lt;br&gt;Let me cover the other part in a separate post.</description></item><item><title>Security prompt on downloaded files in XP SP2</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93665</link><pubDate>Mon, 22 Mar 2004 06:50:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93665</guid><dc:creator>Tony Schreiner's WebLog</dc:creator><description /></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93716</link><pubDate>Mon, 22 Mar 2004 05:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93716</guid><dc:creator>Pavel Lebedinsky</dc:creator><description>&amp;gt; we'll look at the information in the digital signature first, fall back on the version info (with a note) if we have to, then the filename, and finally the CLSID as a last resort.&lt;br&gt;&lt;br&gt;Can you make it so that filename is always displayed (or at least make it a column that is hidden by default but can be displayed by right-clicking the list view header)?&lt;br&gt;&lt;br&gt;Somethimes filename is the easiest way to tell where the add-on came from.</description></item><item><title>RE: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#93917</link><pubDate>Mon, 22 Mar 2004 15:28:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:93917</guid><dc:creator>mearls@hotmail.com (Michael Earls)</dc:creator><description>Nice.  This feature got a rabid applause at the Atlanta DevDays 2004 last week.  Good work.</description></item><item><title>IE/XP sp2 changes</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#94123</link><pubDate>Tue, 23 Mar 2004 00:07:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:94123</guid><dc:creator>JD on MX</dc:creator><description>IE/XP sp2 changes: Windows XP is in final testing changes for a significant new updater, and &amp;quot;jeffdav&amp;quot; or Microsoft details how Internet Explorer will change. New window propagation sounds similar to previous implementations: a new window can be opened only...</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#94308</link><pubDate>Tue, 23 Mar 2004 04:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:94308</guid><dc:creator>Tony Schreiner</dc:creator><description>Pavel, we're considering adding the optional filename column as you described.</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#95186</link><pubDate>Wed, 24 Mar 2004 12:34:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:95186</guid><dc:creator>Anyone know if XP SP2 has .NET inbuilt ?</dc:creator><description>Hi All..&lt;br&gt;&lt;br&gt;Does Xp SP2 force .NEt 1.1 install ?&lt;br&gt;&lt;br&gt;It would be nice if it did..&lt;br&gt;&lt;br&gt;Then a software requirement would be..&lt;br&gt;&lt;br&gt;XP SP2 or 2003 etc...&lt;br&gt;&lt;br&gt;Not.. IE6+MDac+.NEt++++++++&lt;br&gt;&lt;br&gt;</description></item><item><title>Windows XP - major security enhancements and more!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#95540</link><pubDate>Thu, 25 Mar 2004 00:14:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:95540</guid><dc:creator>Core/Dump: opinion, babes and bondage...</dc:creator><description>Microsoft has made the Windows XP SP2 &amp;quot;preview&amp;quot; available for downloading, this is a look at what will be happening...</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#95665</link><pubDate>Thu, 25 Mar 2004 01:10:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:95665</guid><dc:creator>Tony Schreiner</dc:creator><description>&amp;quot;Anyone&amp;quot;, I don't think XP SP2 will force .NET 1.1 install.</description></item><item><title>IE in XP SP2 (Part 3): Web Site Compatibility</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#102249</link><pubDate>Tue, 30 Mar 2004 10:24:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:102249</guid><dc:creator>Tony Schreiner's WebLog</dc:creator><description /></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#104448</link><pubDate>Wed, 31 Mar 2004 02:48:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:104448</guid><dc:creator>Jacky</dc:creator><description>Tony,&lt;br&gt;&lt;br&gt;Will we have IE 6 SP2 including all of these new features? Thanks.</description></item><item><title>re: IE in XP SP2 (Part 1): Authenticode - No, and never again!</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#108133</link><pubDate>Tue, 06 Apr 2004 02:23:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:108133</guid><dc:creator>Tony Schreiner</dc:creator><description>Jacky, I can't yet speak for if/when downlevel releases will have these features. If they do, it would probably be a while after SP2 ships.</description></item><item><title>XP SP2 RC1 issues</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#128169</link><pubDate>Sat, 08 May 2004 01:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:128169</guid><dc:creator>Stefan Demetz</dc:creator><description>XP SP2 RC1 issues</description></item><item><title>Security prompt on downloaded files in XP SP2</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#169073</link><pubDate>Tue, 29 Jun 2004 22:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:169073</guid><dc:creator>Tony Schreiner's WebLog</dc:creator><description /></item><item><title>IE in XP SP2 (Part 2): Information Bar - Stopping the modal dialog madness</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#169074</link><pubDate>Tue, 29 Jun 2004 22:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:169074</guid><dc:creator>Tony Schreiner's WebLog</dc:creator><description /></item><item><title>XP SP2 RC1 issues</title><link>http://blogs.msdn.com/tonyschr/archive/2004/03/21/93430.aspx#464232</link><pubDate>Tue, 13 Sep 2005 02:10:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:464232</guid><dc:creator>Digging .NET</dc:creator><description>After playing with XP SP2 RC1 for a while I still have a few things which bother me.I had a look at group...</description></item></channel></rss>