by James Gaskin
Small business

Internet Explorer 8 Privacy Mode Isn't

3 comments | 10I like it!
August 29, 2008, 08:49 PM — 


Pity those users hoping the new “porn mode” in IE8 will cover the tracks left while looking for the uncovered. Once again, Microsoft overpromises and underdelivers in IE 8 and leaves a security hole.

Should we be surprised at this latest security snafu from The House That Bill Built? Only the foolish or hopelessly naïve believes anything Microsoft says about security. Year after year, promises flow from Redmond like they were campaigning for president, and year after year those promises lead to nothing. If you believed Microsoft finally understood real security with IE 8, shame on you.

To be fair, this is officially the beta for IE 8, so Microsoft has time to fix things. The Red-Boys may not be security-savvy, but they do work hard. They can fix this.

But I'm betting Microsoft won't make it work as promised until at least IE 10. Microsoft reacts to criticism with defensiveness first, followed by hard work that actually fixes the weak area receiving the bad reviews. But in security matters, it takes Microsoft an extra iteration or two before the security critics are satisfied.

Perhaps satisfied is the wrong word about Microsoft and security critics. Usually, the security critics go find something worse about Microsoft security to complain about, and the world forgets the earlier problem. I wonder what the next “security sky is falling” screams will highlight?

I like it!
Comments

Jeez, they had to use

Jeez, they had to use "forenic experts" to retrieve the data? Excuse me for not being worried about anybody in my household, or place of work, being able to find anything.

I suspect you missed it, but Microsoft's statement says:

"Microsoft's main goal with InPrivate Browsing is to prevent other users of the same computer to gain access to the browsing history, the company said in an e-mail response. The feature isn't designed to protect a user's privacy from security experts and forensic researchers, the company said."
| reply

Thank you for point this

Thank you for point this out. Mr. Gaskins there are very few things I can't stand worse the people that over state their knowledge. Please do more research before posting anymore blogs. There is a major difference between a regular user of a work station or your home user then a forensic expert trained to find so called hidden files. Needless to say this does not lend well to your credibility.
| reply

One Big Flaw

The biggest flaw I see is that the InPrivate browsing session stills stores cache data on the local machine -- that's a big oversight, even for a Beta product.

As for the rest of it, who cares if a forensic expert can recover the data?
| reply
Free books

Build your tech library with our book giveaways.

Hacking Exposed, Sixth Edition
By Stuart McClure, Joel Scambray, George Kurtz; Published by McGraw-Hill/Osborne

The original Hacking Exposed authors rejoin forces on this tenth anniversary edition to offer completely up-to-date coverage of today's most devastating hacks and how to prevent them. Using their proven methodology, the authors reveal how to locate and patch system vulnerabilities. The book includes new coverage of ISO images, wireless and RFID attacks, Web 2.0 vulnerabilities, anonymous hacking tools, Ubuntu, Windows Server 2008, mobile devices, and more. Enter now!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace