-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/332/matasano-interviews-ie-lead-pm-christopher-vaughan/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
Did they fix CSS and generally make IE more standards complient. Surely that was a major reason for redevelopment as well ?
Also how many websites will break the day IE7 autoupdates itself onto users machines.
So, while I'd love to get a PM on the IE team to explain the rationale behind how collapsible margins work in the IE6 box model, I'm going to try to be a model of restraint.
It's not easy for a high-profile team at MSFT to do an interview on a snarky security blog and we're really happy that Chris Vaughan was able to let us pull it off. That said, if you've got to get your LUG cred on, find a way to whack IE on security. On this particular occasion, expect us to circle the wagons and whack you back. Good times!
My blog : http://sansor.wordpress.com
-sansor
Avoid GATES of Hell use LINUX
I still do not understand the rationale for not writing IE7, let alone IE8, in managed code.
what happened to eat your own food? .NET is good for eveybody else but not good enough for the flagship application of its maker? Sorry, a "variety of reasons" does not suffice as a real answer to me
Assuming that commenting on Gecko or anything relative to it wouldn't get him fired^^
i think a lot of vulnerabilities (CSSXSS comes to mind first) are getting confused with browser features... such as cross-domain access. i think cross-domain access attacks will move to the top of clientside security risks in the next year. one of my favorite reads of the year was Zalewski's paper on cross-site cooking [securityfocus].
sure, graphics rendering vulnerabilities and javascript/heap/nopsled/shellcode exploits are going to continue to plague browsers for some time. even vista's uac and pmie won't stop everything.