3 ms·
I have no idea how confident I should be in Edge's security. Microsoft just doesn't have a great history there.
by TwoBit 11y ago
I have no idea how confident I should be in Edge's security. Microsoft just doesn't have a great history there.
- inlined 11y agoA major category of IE vulnerabilities involved tricking it into loading COM objects. The Chakra JS engine moved from a COM based implementation to compiled JS. And Edge doesn't support ActiveX or Browser Helper Objects (BHOs) like IE did either. It looks like most of the COM attack vectors have now been shut down, though some components like the clipboard still use COM to interact with the broader OS.
- xg15 11y agoOut of couriosity: As BHOs were the closest IE had to browser extensions, does that mean Edge doesn't support extensions at all - or is there a different system in place?
- Eric_WVGG 11y agoEdge will actually support both Chrome and Firefox extensions,,, http://www.theverge.com/2015/4/29/8515771/microsofts-edge-browser-supports-chrome-and-firefox-extensions http://www.theverge.com/2015/4/29/8515771/microsofts-edge-br... But not until later this year.
- xg15 11y agoI'm just skimming this, but this sounds as if they plan to implement the WebExtension spec. That would really be a remarkable step forward and a distinct difference from IE.
- tracker1 11y agoMicrosoft has actually had a pretty good security record for the past decade now... Most of the truly stupid decisions regarding security were prior to Windows XP. Since Melissa/ILoveYou and several other worms that wreaked havoc on data centers i the late 90's and early 00's there was a massive shift in terms of security conscience at MS. There have been attack vectors since, but that is true of every platform, and since Windows 7 in particular, most of them have been from third party software.