, 5 tweets, 2 min read Read on Twitter
A more serious take on this: What makes me sad is (once again) undermining end-user security to the benefit of corporate dinosaurs who can't be bothered to adapt. The IE Compat View certainly has a long history of abuse, but let's also take a look at some other examples: (1/4)
In 2017 MS disabled VBScript in IE, but left it running in Intranet and Trusted Sites zones for the benefit of said dinosaurs still using it. Guess what? By leaving it in, it could be abused from Internet zone as well: bugs.chromium.org/p/project-zero… and bugs.chromium.org/p/project-zero… (2/4)
Last year, MS disabled Flash in Edge by default, but left a whitelist of "trusted" sites. Guess what? bugs.chromium.org/p/project-zero… (3/4)
But surely, this time it is going to be different. This time it is going to be done right and there will be no way to abuse the whitelists or escape the Intranet zone. Surely. (4/4)
And one more: Empirical evidence suggests that attack surface reduction is one of the most impactful (if not *the* most impatful) things that can be done for product security. Going the opposite way is... disappointing.
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to Ivan Fratric
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!