Live data from Hacker News

Retiring Internet Explorer

textslashplain.com

101–110 of 122 posts

Re: Retiring Internet Explorer

#101
post #97

Earlier quoted context omitted.

At least in South Korea some (but not all) rootkits actively check for the presence of VM.

How does once check for the presence of a VM from inside the VM? Doesn't that defeat the purpose of the VM to begin with?

> How does once check for the presence of a VM from inside the VM

for example by enumerating the connected PCI devices and looking for common VM vendors virtual devices.

>Doesn't that defeat the purpose of the VM to begin with

that depends on your use-case. If it's about separating mostly trusted applications and/or servers, then absolutely not.

If it's about investigating known-bad code, then, yes, absolutely - malware is often intentionally disabling itself when it detects it's running in a VM.

Re: Retiring Internet Explorer

#102
>No. Internet Explorer will remain a supported product until its support lifecycle runs out.

which is pretty much going to be "never". IE's support lifecycle says that a version of IE is supported for as long as the version of windows it shipped with is supported.

Windows 10 shipped with IE11 and Windows 10 is going to be the last version of Windows ever released, remaining in constant support.

Companies on the other hand still force users to use IE11 and they will continue to do so while IE11 is supported (which is forever).

We will have to continue to support a browser that came out in the beginning of the last decade for at least another 10 to 15 years.

Re: Retiring Internet Explorer

#103
post #53

Earlier quoted context omitted.

I'm Korean so I glad to see someone speaks out this. Actually it was rather inevitable, partially because of the U.S. gov that time. The Korean gov wanted to grow e-commerce/e-banking in 1999 but the American gov did not allow to export cipher higher than 40 bits. As a result the Korean gov had to develop its own 128 bits cipher (SEED). It was even before AES/SSL/TLS were introduced so the whole crypto stack was impl…

Great to see another Korean here! :-) > I would say it was quite pioneer in 1999 but since then the gov don't even dare to replace the crypto policies. Now we are stuck at this in 2020. AFAIK, the government removed the SEED-only policy some time ago (in the early 2010s) but it’s the price of the system infrastructure that makes them keep using the old, ActiveX based systems. I’m personally thankful for smartphone’s…

Don't you fear running into the trap that instead of IE/ActiveX you end up with only support for Android and IOS¹? That's not quite as bad of course, but it's still limiting in terms of software freedom.

1: Or, more probable, support for modern web browsers on any OS, but with (2FA) authentication handled through proprietary and required Android or IOS apps.

Re: Retiring Internet Explorer

#105

Earlier quoted context omitted.

Great to see another Korean here! :-) > I would say it was quite pioneer in 1999 but since then the gov don't even dare to replace the crypto policies. Now we are stuck at this in 2020. AFAIK, the government removed the SEED-only policy some time ago (in the early 2010s) but it’s the price of the system infrastructure that makes them keep using the old, ActiveX based systems. I’m personally thankful for smartphone’s…

Don't you fear running into the trap that instead of IE/ActiveX you end up with only support for Android and IOS¹? That's not quite as bad of course, but it's still limiting in terms of software freedom. 1: Or, more probable, support for modern web browsers on any OS, but with (2FA) authentication handled through proprietary and required Android or IOS apps.

> Or, more probable, support for modern web browsers on any OS, but with (2FA) authentication handled through proprietary and required Android or IOS apps.

That’s actually a pretty accurate explanation of currently what’s happening, but it’s much better than before as macOS/Linux support is also coming too.

> That's not quite as bad of course, but it's still limiting in terms of software freedom.

I’m not the person who hates programs that aren’t open source or “free”, so for me just being able to tell my friends to use macOS or Linux is a pretty great progression.

Re: Retiring Internet Explorer

#106

Earlier quoted context omitted.

Don't you fear running into the trap that instead of IE/ActiveX you end up with only support for Android and IOS¹? That's not quite as bad of course, but it's still limiting in terms of software freedom. 1: Or, more probable, support for modern web browsers on any OS, but with (2FA) authentication handled through proprietary and required Android or IOS apps.

> Or, more probable, support for modern web browsers on any OS, but with (2FA) authentication handled through proprietary and required Android or IOS apps. That’s actually a pretty accurate explanation of currently what’s happening, but it’s much better than before as macOS/Linux support is also coming too. > That's not quite as bad of course, but it's still limiting in terms of software freedom. I’m not the person w…

I'm not as much bothered by the software being non-free, rather making the ownership of either an Android or IOS smartphone a requirement for digital citizenship too solve the 2FA puzzle is something that worries me.

We're moving in that direction in the Netherlands with our national citizen's accounts (DigiD: mandatory if you want to file taxes, gain access to your health care records, or handle your insurance digitally).

Re: Retiring Internet Explorer

#107
The Japanese electronic tax filing system's browser support policy is to support browsers that come preinstalled with the OS, period, actual marketshare be damned. This makes them support IE, Edge and Safari, but not Chrome nor Firefox. (While some newer parts of the system do support them, most of the critical parts still do not. Additionally, since the system still only supports the EdgeHTML Edge, the Chromium Edge automatic rollout is delayed to April specifically for Japan, to avoid confusion during the February-March tax filing season.)

The only way to make them stop supporting IE is to have the OS itself stop bundling it - which, like it was mentioned elsewhere in this discussion, is probably never going to happen.

Re: Retiring Internet Explorer

#108
post #59

Earlier quoted context omitted.

VBScript and HTA files (HTML Applications) come to mind. HTAs were actually an interesting direction, once used them to ship a simple application (a very visual FTP upload). It was unsandboxed HTML and JS that could access all the ActiveX APIs. A bit like Electron now. Can't image there not being a few niches out there that heavily rely (or relied) on HTAs

I have a small niche... a calculator that opens fast :-P http://runtimeterror.com/tools/calc/calc.hta.txt (yes, running an HTA "calc" is faster than the UWP Windows 10 calculator... and uses less RAM :-/).

That's nice. I once wrote a clone of Active Directory Users & Computers (dsa.msc) as a HTA, as I was working on a contract where I was expected to design stuff for the AD, but they wouldn't let me install the AD tools...

If all you have is Notepad, and you know how to write HTAs, the world is your oyster (or something).

Re: Retiring Internet Explorer

#109
post #9
post #2

> I printed out the source code for the network stack and sat > down with a red pen. Does anyone still do this to get to know new code base?

I have done this once before too, with a particularly hairy multi-page function from a legacy system. Spreading all the pages over a large meeting room desk allows you to view the whole code at once, instead of being constrained by the physical size of a computer monitor. And there's something hard to describe about being able to physically manipulate the code (rearranging the sheets of paper, scribbling over the cod…

Probably you would be interested in https://dynamicland.org/ or Bret Victor fame.

Re: Retiring Internet Explorer

#110

> Burndown List >> Banking, especially in Asia My bank in China requires Windows + IE + a custom ActiveX control to use their Internet banking. As a result, I don't use it. One of my accounts can be used via their mobile app (if you read Chinese or have another phone to use camera translation). My business account cannot be, and I am therefore required to visit a branch along with my official chop (seal / stamp) when…

"My bank in China requires Windows + IE + a custom ActiveX control to use their Internet banking. As a result, I don't use it." Why not have a VM just for internet banking? Surely that's easier than taking the chop out of the safe and waiting in line at the branch.

Yeah, I thought about it. But I don't know how I could keep the VM secure, so I might end up doing my Internet banking on a malware-infested system.

I wouldn't trust myself to keep the latest version of Windows secure, given that I haven't used Windows in over a decade, so I'm pretty sure I can't be trusted to keep XP safe. (As far as I'm aware, the "security" software that the bank's ActiveX control communicates with only runs on XP.)

Post reply on HN