<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Rob Franco and team - IE 7 Security</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security/RSS"></atom:link>
	<image>
		<url>http://ecn.channel9.msdn.com/o9/previewImages/100/113117_100x75.jpg</url>
		<title>Channel 9 - Rob Franco and team - IE 7 Security</title>
		<link></link>
	</image>
	<description>There&#39;s a ton of new things in Internet Explorer 7.0 that&#39;ll improve your security. Meet the
IE team and learn what they are doing to protect computer users against phishing and malware and other kinds of attacks. For more about IE 7.0, visit the
IE team&#39;s blog.The interviewer here is Joshua Allen, IE evangelist, and he is well-known because he was Microsoft&#39;s first blogger.</description>
	<link></link>
	<language>en</language>
	<pubDate>Tue, 18 Jun 2013 20:44:17 GMT</pubDate>
	<lastBuildDate>Tue, 18 Jun 2013 20:44:17 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Is it safe to confirm that IE7 will be the moset secure browser?<br /><br />The sheer fact that it can't write a single thing to the hd without user approvable is enough for me to get me to switch back from Firefox.<br /><p>posted by DevilsRejection</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624418100000000</link>
		<pubDate>Fri, 16 Sep 2005 04:30:10 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624418100000000</guid>
		<dc:creator>DevilsRejection</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<p>In the video you show your evil activex control and what it does is issue the &quot;format c:&quot; command. Actually, this command will fail since the C drive is in use by the operating system and cannot be formated and since the format command needs confirmation
 before it formats a harddisk, although the latter might be bypassed I guess. However, you are the IE Security Team and I hope that you know this. After all, hacker do much worse things and I hope that you know much more than you are telling us on their methods
 and on all the harmful senarios that are out there. Because a simple format c: is nothing and you should know that. I hope that your internal testing examples are much more sofisticated than what you say publicly.</p>
<p>posted by nektar</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624590110000000</link>
		<pubDate>Fri, 16 Sep 2005 09:16:51 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624590110000000</guid>
		<dc:creator>nektar</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<p>&quot;Need to get a camcorder with a light&quot;<br /></p>
<p><br />[6]ROBERT <br /></p>
<p><br /></p>
<p>posted by johnbrien</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624631220000000</link>
		<pubDate>Fri, 16 Sep 2005 10:25:22 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624631220000000</guid>
		<dc:creator>johnbrien</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[nektar, I believe that the evil ActiveX control didn't execute the &quot;format c:&quot; command, it installed into the user's startup folder a batch file that executed &quot;format c:&quot;.&nbsp; The demo showed how the ActiveX control was blocked from installing the batch file.<br /><p>posted by Escamillo</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624640540000000</link>
		<pubDate>Fri, 16 Sep 2005 10:40:54 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624640540000000</guid>
		<dc:creator>Escamillo</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<blockquote>
<div>nektar wrote:</div>
<div>
<p>In the video you show your evil activex control and what it does is issue the &quot;format c:&quot; command. Actually, this command will fail since the C drive is in use by the operating system and cannot be formated and since the format command needs confirmation
 before it formats a harddisk, although the latter might be bypassed I guess. However, you are the IE Security Team and I hope that you know this. After all, hacker do much worse things and I hope that you know much more than you are telling us on their methods
 and on all the harmful senarios that are out there. Because a simple format c: is nothing and you should know that. I hope that your internal testing examples are much more sofisticated than what you say publicly.</p>
</div>
</blockquote>
<br /><br />That was just a trivial example -&nbsp;it didn't matter what was in the file, just the fact that the control tried to write a file but IE7 didn't let it.<p>posted by Wells</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624648650000000</link>
		<pubDate>Fri, 16 Sep 2005 10:54:25 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624648650000000</guid>
		<dc:creator>Wells</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<p>The pure evil movie, I have no idea, but <a href="http://www.google.com/movies?hl=en&amp;q=movie%3A&#43;%22pure&#43;evil%22">
this thing</a> might know...<br />I can thing of one of the ghost busters sequels or <a href="http://www.google.com/search?hl=en&amp;c2coff=1&amp;q=seinfeld&#43;newman&#43;pure&#43;evil&amp;spell=1">
Newman</a> (from Seinfeld... he is pure evil)</p>
<p>posted by TheAsher</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624686230000000</link>
		<pubDate>Fri, 16 Sep 2005 11:57:03 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624686230000000</guid>
		<dc:creator>TheAsher</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Why is his phone off the hook, and the reciever is unplugged?<p>posted by CRPietschmann</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624807480000000</link>
		<pubDate>Fri, 16 Sep 2005 15:19:08 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624807480000000</guid>
		<dc:creator>CRPietschmann</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[500MB download.. OMG!!! <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-10.gif' alt='Embarassed' /><p>posted by Kollner</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624833700000000</link>
		<pubDate>Fri, 16 Sep 2005 16:02:50 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624833700000000</guid>
		<dc:creator>Kollner</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Are there any plans to get rid of the registry altogether in the future? Always seemed like a bad idea, once somethings done the damage in there you're a bit screwed. Peoples registrys become such a mess of leftover keys from uninstalled software, hopefully
 Jim Allchins plans on keeping the performance up over time includes something on this.<br /><br /><p>posted by mycroft</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624921210000000</link>
		<pubDate>Fri, 16 Sep 2005 18:28:41 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624921210000000</guid>
		<dc:creator>mycroft</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<p>pure evil:</p>
<p><a href="http://www.imdb.com/title/tt0081633/">Time Bandits</a>?&nbsp; &quot;Mum!&nbsp; Dad!&nbsp; Don't touch it! It's evil!&quot;<br /></p>
<p>posted by Maurits</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624929170000000</link>
		<pubDate>Fri, 16 Sep 2005 18:41:57 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624929170000000</guid>
		<dc:creator>Maurits</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Kollner: sorry. I've been experimenting with higher resolution vids.<p>posted by scobleizer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624937860000000</link>
		<pubDate>Fri, 16 Sep 2005 18:56:26 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632624937860000000</guid>
		<dc:creator>scobleizer</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[It's great that you guys are working hard on security issues, but it's equally important to fix IE bugs. The z-index bug is a well know CSS bug since IE 4 or 5 nearly a decade ago with no easy cross-platform workaround, and it looks that the IE 7 team
 are still not aware of the problem. Please read <a href="http://cdcer.com/?2005/09/brutal-solution-to-ie-z-index-bug.html">
A brutal solution to the IE z-index bug</a> for more details and try to fix it. the world can't afford to fight with the bug for another 10 years! Speaking about bugs, here is another one: While poking around MSN, I did a search for
<a href="http://search.msn.com/results.aspx?q=MSN&#43;sucks&amp;srch_type=0&amp;FORM=QBRE">MSN sucks</a>, and found a grand total of 49 pages! Yes, you heard it right, it's 49 pages, not 49K. As you can imagine, there is no way that I could trust that number, so I immediately
<a href="http://www.google.com/search?num=100&amp;hl=en&amp;lr=&amp;safe=off&amp;c2coff=1&amp;q=MSN&#43;sucks&amp;btnG=Search">
checked with Google</a> and got over 2 million results, and the <a href="http://search.yahoo.com/search?p=MSN&#43;sucks&amp;prssweb=Search&amp;ei=UTF-8&amp;fr=ush-help&amp;fl=0&amp;x=wrt">
same search by Yahoo!</a> reports 3.7 million! But wait, it got much worse! Please read
<a href="http://cdcer.com/?2005/09/bug-or-censorship-in-msn-search.html">Bug or censorship in MSN search</a> for the whole story. These issues cost the industry countless hours of lost productivity (100s of millions hours per year by some estimation) and really
 make Microsoft look so incompetent and evil in the eyes of geeks.<p>posted by The CDCer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632628298020000000</link>
		<pubDate>Tue, 20 Sep 2005 16:16:42 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632628298020000000</guid>
		<dc:creator>The CDCer</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Can anyone tell me why HTML code not working here?<p>posted by The CDCer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632628300320000000</link>
		<pubDate>Tue, 20 Sep 2005 16:20:32 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632628300320000000</guid>
		<dc:creator>The CDCer</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<blockquote>
<div>The CDCer wrote:</div>
<div>It's great that you guys are working hard on security issues, but it's equally important to fix IE bugs. The z-index bug is a well know CSS bug since IE 4 or 5 nearly a decade ago with no easy cross-platform workaround, and it looks that the IE 7 team
 are still not aware of the problem. Please read &lt;a href='http://cdcer.com/?2005/09/brutal-solution-to-ie-z-index-bug.html'&gt;A brutal solution to the IE z-index bug&lt;/a&gt; for more details and try to fix it. the world can't afford to fight with the bug for another
 10 years! Speaking about bugs, here is another one: While poking around MSN, I did a search for &lt;a href='http://search.msn.com/results.aspx?q=MSN&#43;sucks&amp;srch_type=0&amp;FORM=QBRE'&gt;MSN sucks&lt;/a&gt;, and found a grand total of 49 pages! Yes, you heard it right, it's
 49 pages, not 49K. As you can imagine, there is no way that I could trust that number, so I immediately &lt;a href='http://www.google.com/search?num=100&amp;hl=en&amp;lr=&amp;safe=off&amp;c2coff=1&amp;q=MSN&#43;sucks&amp;btnG=Search'&gt;checked with Google&lt;/a&gt; and got over 2 million results,
 and the &lt;a href='http://search.yahoo.com/search?p=MSN&#43;sucks&amp;prssweb=Search&amp;ei=UTF-8&amp;fr=ush-help&amp;fl=0&amp;x=wrt'&gt;same search by Yahoo!&lt;/a&gt; reports 3.7 million! But wait, it got much worse! Please read &lt;a href='http://cdcer.com/?2005/09/bug-or-censorship-in-msn-search.html'&gt;Bug
 or censorship in MSN search&lt;/a&gt; for the whole story. These issues cost the industry countless hours of lost productivity (100s of millions hours per year by some estimation) and really make Microsoft look so incompetent and evil in the eyes of geeks.</div>
</blockquote>
<br /><br />Hi CDCer,<br />The IE team has been very well aware of the z-indexing issue with the select element. If you read the blog post from Chris Wilson on the IE team blog at
<a href="http://blogs.msdn.com/ie/archive/2005/09/13/465338.aspx">http://blogs.msdn.com/ie/archive/2005/09/13/465338.aspx</a>&nbsp;you'll see that this is on the list of issues being addressed in IE7.<br /><br />Thanks<br />-Dave<br /><p>posted by DMassy</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632628362170000000</link>
		<pubDate>Tue, 20 Sep 2005 18:03:37 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632628362170000000</guid>
		<dc:creator>DMassy</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Ok,<br /><br />There has been all this talk about running LUA/LUP whatever you want to call it. <br /><br />But, my understanding was that in XP home there really was not security. Logins are strictly for profiling? You need XP Pro to restrict a certain user from writing or accessing certain parts of the system.<br /><br />Can someone comfirm or deny this? Please show the work of your proff.<br /><br />BOb<br /><p>posted by pilotbob</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632629579620000000</link>
		<pubDate>Thu, 22 Sep 2005 03:52:42 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632629579620000000</guid>
		<dc:creator>pilotbob</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Pure Evil as in&nbsp;the Fifth Element I would Say <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' /><p>posted by ChrisD</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632633025580000000</link>
		<pubDate>Mon, 26 Sep 2005 03:35:58 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632633025580000000</guid>
		<dc:creator>ChrisD</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[Robert once again Great Video <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' /> can i recomend&nbsp; you&nbsp; use a Monopod&nbsp; or a Tripod...for the Camera <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' />). Just to point out&nbsp; i have some of your CLips&nbsp; on the&nbsp; Yahoo site&nbsp; under the User name &quot; Eagle_averro_isme Photo album&quot;&nbsp;&nbsp; Nice seeing&nbsp; you&nbsp; great effort&nbsp;
 in the &quot; Picture speaks a THOUSAND words&quot;&nbsp; keep it&nbsp; up and many thanks&nbsp; to you and the teams.<p>posted by Eagle_Averro</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632636244060000000</link>
		<pubDate>Thu, 29 Sep 2005 21:00:06 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632636244060000000</guid>
		<dc:creator>Eagle_Averro</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[I would like to know if the final version of IE7 will have the toolbars locked or not. As in not giving the end user any way to move around the address toolbar or the buttons where you want them. I read somewhere on Channel9 that it will not be possible
 to move this around because that would make it easy to trick the end user or something.. Sorry i'm not very informative. I'm just not sure on this topic. Anyone with insight? Appreciated <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-2.gif' alt='Big Smile' /><br /><p>posted by KenQ</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632644892170000000</link>
		<pubDate>Sun, 09 Oct 2005 21:13:37 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632644892170000000</guid>
		<dc:creator>KenQ</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<blockquote>
<div>KenQ wrote:</div>
<div>I would like to know if the final version of IE7 will have the toolbars locked or not. As in not giving the end user any way to move around the address toolbar or the buttons where you want them.
</div>
</blockquote>
<br />In Windows, the Explorer windows (aka shell windows), the navigation bar (back, forward, address / breadcrumb bar / search) is fixed at the top.&nbsp;&nbsp; IE will do the same, for consistency with the shell as well as anti-spoofing.<br /><br />For IE7 on XPSP2, we're considering our options.&nbsp; In Beta 1, we've heard a lot of feedback from people who want the ability to move the toolbars around, including the menus and the navigation bar.&nbsp;&nbsp; So no &quot;final answer&quot; on this issue yet.<p>posted by BruceMorgan</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632655524390000000</link>
		<pubDate>Sat, 22 Oct 2005 04:33:59 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632655524390000000</guid>
		<dc:creator>BruceMorgan</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<blockquote>
<div>BruceMorgan wrote:</div>
<div>In Windows, the Explorer windows (aka shell windows), the navigation bar (back, forward, address / breadcrumb bar / search) is fixed at the top.&nbsp;&nbsp; IE will do the same, for consistency with the shell
<strong>as well as anti-spoofing.</strong><br /></div>
</blockquote>
<br /><br />Doesn't toolbar customization make it <strong>harder</strong> to spoof the chrome?<br /><br />I know when I'm surfing on a Mac, and a spoofed Windows dialog pops up, I get a good laugh. <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' /><p>posted by Maurits</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632655873890000000</link>
		<pubDate>Sat, 22 Oct 2005 14:16:29 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632655873890000000</guid>
		<dc:creator>Maurits</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[I still don't exactly understand: &quot;What stops an attacker from abusing the broker?&quot; The broker is trusted and runs with higher privileges?<br /><br />Neelay<br /><p>posted by neelayshah</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632680199370000000</link>
		<pubDate>Sat, 19 Nov 2005 17:58:57 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632680199370000000</guid>
		<dc:creator>neelayshah</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[The broker has only a few methods, which are carefully threat modeled and designed to require user interaction.&nbsp; The point is that you reduce the attack surface area by making the bare minimum code necessary be elevated.<p>posted by JoshuaAllen</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632693477090000000</link>
		<pubDate>Mon, 05 Dec 2005 02:48:29 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632693477090000000</guid>
		<dc:creator>JoshuaAllen</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<p>Great video. Learnt a lot of where you guys are going. I have to say that I expect to see many privilege escalation exploits next....better priv escalation exploits than remote exploits that run under admin privs automatically....</p>
<p>...in the video you were referring to sending in exploits and vulnerabilities, so you guys can verify the threat model of IE. Is the threat model of IE published somewhere? I think if it is would give the security research community a more direct way to
 probe it for weaknesses...</p>
<p>Thanks - <br />Christian</p>
<p>-----</p>
<p><a href="http://www.mcs.vuw.ac.nz/~cseifert/blog/index.php">http://www.mcs.vuw.ac.nz/~cseifert/blog/index.php</a></p>
<p>posted by cseifert</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632895927930000000</link>
		<pubDate>Thu, 27 Jul 2006 10:26:33 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c632895927930000000</guid>
		<dc:creator>cseifert</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<blockquote>
<div>The CDCer wrote:</div>
<div>It's great that you guys are working hard on security issues, but it's equally important to fix IE bugs. The z-index bug is a well know CSS bug since IE 4 or 5 nearly a decade ago with no easy cross-platform workaround, and it looks that the IE 7 team
 are still not aware of the problem. Please read &lt;a href='http://cdcer.com/?2005/09/brutal-solution-to-ie-z-index-bug.html'&gt;A brutal solution to the IE z-index bug&lt;/a&gt; for more details and try to fix it. the world can't afford to fight with the bug for another
 10 years! </div>
</blockquote>
<br /><br />Tell me about it.&nbsp; IE7 is in the wild, and I'm still having to workaround 10 year old z-index bugs.&nbsp; Every other browser seems to work with CSS.<br /><p>posted by antichris</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c633114662680000000</link>
		<pubDate>Fri, 06 Apr 2007 14:24:28 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c633114662680000000</guid>
		<dc:creator>antichris</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<p></p>
<div id="_mcePaste">You guys always deliver useful content. Awesome post. Very interesting and valuable videos. Keep posting more articles. Thanks for sharing useful info.</div>
<p>You guys always deliver useful content. Awesome post. Very interesting and valuable videos. Keep posting more articles. Thanks for sharing useful info.</p>
<p></p>
<p>posted by phentermine 37.</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c634178890640000000</link>
		<pubDate>Fri, 20 Aug 2010 08:17:44 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c634178890640000000</guid>
		<dc:creator>phentermine 37.</dc:creator>
	</item>
	<item>
		<title>Re: Rob Franco and team - IE 7 Security</title>
		<description>
			<![CDATA[
<p></p>
<div id="_mcePaste">You guys always deliver useful content. Awesome post. Very interesting and valuable videos. Keep posting more articles. Thanks for sharing useful info.</div>
<p></p>
<p>posted by phentermine 37.</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c634178892770000000</link>
		<pubDate>Fri, 20 Aug 2010 08:21:17 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/scobleizer/Rob-Franco-and-team-IE-7-Security#c634178892770000000</guid>
		<dc:creator>phentermine 37.</dc:creator>
	</item>
</channel>
</rss>