5 ms·
Really tired of all the different versions of IE. Why oh why can't it just be "Internet Explorer" without all these individual versions that pigeonhole themsel
by thesis 13y ago
Really tired of all the different versions of IE. Why oh why can't it just be "Internet Explorer" without all these individual versions that pigeonhole themselves?
- venomsnake 13y agoBecause of the "brilliant" decision to integrate the IE engine way too deep into windows to the point of unseverability. So you get one-two IE versions per OS lifecycle. Enjoy ...
- trafficlight 13y agoAt the very least they could push real updates more than once a Service Pack.
- yuhong 13y agoThey have to support all these versions for the lifecycle of the underlying Windows version. Trivia: I personally reported a security bug in IE6/7 that was fixed in the May 2013 security update.
- comex 13y agoI like how this was such a big issue when Microsoft did it, but nobody cares that there is a systemwide WebKit.framework on OS X that various applications use internally. I know there are some differences, but it's pretty much the same thing.
- TylerE 13y agoMaybe because Webkit is open source and was developed independently?
- ksk 13y agoWhat does it being open source have anything to do with it? People didn't like it when MS did it because it introduced additional unwanted bloat in the OS that was annoying to decouple.
- TylerE 13y agoThat's not what I remember. It was more about it having remotely-exploitable vulnerabilities without being uninstallable.
- ksk 13y agoYou're incorrect. And technically speaking the browser wasn't integrated with the OS (and never was), it was the rendering engine (shdocvw.dll and mshtml.dll). The Windows UI featured HTML elements that the OS rendered via this. The rendering engine is not itself connected to any TCP/IP stack, so remote exploits are impossible. But ofcource if you went to web sites with malicious HTML you could get ownzored because of bugs in the rendering engine. Also you could delete the browser (iexplore.exe) but not the engine as the OS relied on certain UI elements that used this engine. Ofcource if you went ahead and deleted the DLLs anyway, you could make the OS work without the added HTML UI layer (as the judge in the MS antitrust case demonstrated). One could argue that this wasn't the "full" Windows experience but hey.. all that is water under the bridge now. The case is resolved and MS got slapped with a hefty fine.
- yuhong 13y agoActually IE6 and older tied the IE user interface to the Explorer user interface which shared the same SHDOCVW. IE7 created IEFRAME to separate the Explorer user interface from the IE user interface, but it is still in system32, and so are all the other core IE components like MSHTML, WININET, etc...
- ksk 13y agoAre you talking about the UI controls or the browser?iexplore.exe could be deleted at any time. Ofcource because explorer.exe also could handle URLs you could technically still browse via it. (Though I'm pretty sure that by default only URLs in the local/trusted zone were allowed) And then I believe the help component also relied on the rendering engine. Although the hcp:// vulnerabilities were in the protocol handler (helpctr.exe) and the ms-help:// vulnerabilities were also in the protocol handler which allowed the attacker to bypass ASLR/DEP.
- deleted 13y ago[deleted]