Showing posts with label IE8. Show all posts
Showing posts with label IE8. Show all posts

Thursday, May 01, 2014

Out of Band Security Update for IE Zero-Day Vulnerability


Microsoft released an out-of-band security update to address the security vulnerability in Internet Explorer described in Microsoft  Security Advisory 2963983.

Of important note:  Although Windows XP is no longer supported by Microsoft, the decision was made to issue a security update for Windows XP users.

Critical:

  • MS14-021 -- Security Update for Internet Explorer (2965111) 

    This security update resolves a publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using an affected version of Internet Explorer. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


    References




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...




    Sunday, April 27, 2014

    Security Advisory 2963983, IE Zero-Day Vulnerability

    Security Advisory
    Microsoft released Security Advisory 2963983 which relates to a vulnerability in Internet Explorer.

    With the vulnerability, an attacker could cause remote code execution if someone visited a malicious website with an affected browser. Generally, this would occur by an attacker convincing someone to click a link in an email or instant message.

    Although the vulnerability affects all versions of IE, at this time, Microsoft is aware of limited, targeted attacks, in which the exploit observed appears to target IE9, IE10 and IE11.


    Additional details about the exploit are available from the FireEye Blog, New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks.

    Recommendations 

    As illustrated in the "Security Research and Defense Blog" reference below, users of IE 10 and 11 should ensure they haven't disabled Enhanced Protection Mode. 

    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET).  The recommended setting for EMET 4.1, available from KB Article 2458544, is automatically configured to help protect Internet Explorer. No additional steps are required.

    See the Tech Net Advisory for instructions on changing the following settings to help protect against exploitation of this vulnerability:
    • Change your settings for the Internet security zone to high to block ActiveX controls and Active Scripting
    • Change your settings to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone. 

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, September 17, 2013

    Security Advisory 2887505 and Microsoft Fix it

    Security Advisory
    Microsoft released Security Advisory 2887505 which relates to an issue with Internet Explorer.

    It is important to note that there are a limited number of targeted attacks which are specifically directed at Internet Explorer 8 and 9. The issue, however, could potentially affect all supported versions of IE.

    As described by Dustin Childs in the below-referenced MSRC Blog post,
    "This issue could allow remote code execution if an affected system browses to a website containing malicious content directed towards the specific browser type. This would typically occur when an attacker compromises the security of trusted websites regularly frequented, or convinces someone to click on a link in an email or instant message."

    Mitigations

    Microsoft has made available a Fix it solution for users of Internet Explorer.  Additional mitigations include the following advice, also from the MSRC Blog post:

    • Set Internet and local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones
      This will help prevent exploitation but may affect usability; therefore, trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    • Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones
      This will help prevent exploitation but can affect usability, so trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    Below are the links to both apply and uninstall the Fix it solution.  Note:  The Fix it solution applies only 32-bit versions of Internet Explorer.
     
    Apply Fix itUninstall Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

    If you have Windows Vista or Windows 7 installed, you should have updated to IE9 or IE10.  In the event you haven't, it is strongly advised that you update!

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Sunday, June 16, 2013

    Microsoft Fix it to Disable Java in Internet Explorer

    java

    Java, how we love to hate you!  Many people have uninstalled Java and do not miss it.  That is most likely because they do not have desktop applications that require Java. Unfortunately, that is not the situation for those people who use Java-dependent software programs. 

    Until recently, Internet Explorer was the only major browser that did not provide a way to disable Java.  The only way to completely disable Java in IE was to disable Java through the Java Control Panel, which meant re-enabling Java when using Java-dependent programs.  That is no longer true!

    Microsoft released a Microsoft Fix it solution designed to block all Java web-attack vectors through Internet Explorer.  As explained by Cristian Craioveanu in the below-linked Security Research & Defense Blog article, the Fix it solution is made up of two parts. 
    1. The Fix It uses the Windows Application Compatibility Toolkit to change the behavior of Internet Explorer at runtime to prevent Oracle’s Java Web plugins from loading.  As a result, the Java ActiveX dlls are not loaded.
    2. The second part of the Fix it clears the access control list (ACL) in the registry for the Java Network Loading Protocol (JNLP) handler which prevents Internet Explorer from automatically opening  files.  

    Instructions

    Before installing the Fix it solution, please follow the following suggestions:

    1.  Create a restore point

    2.  Back up the Registry
    3.  Apply the Fix it

    Disable the Java web-plugin

    Apply Fix it
    Restore the Java web-plugin
     
    Uninstall Fix it

    4.  Restart Internet Explorer
    For the changes to take effect, restart IE.

    To undo the changes, run Microsoft Fix it 50995 and restart IE.

    The Fix it solution has been tested by Microsoft and will work for all versions of Java from versions 5 and above.  It also works on all supported versions of Internet Explorer, whether 32- or 64-bit.


    References


    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Wednesday, May 08, 2013

    Microsoft FixIt for Security Advisory 2847140

    Security Advisory
    Microsoft released a Microsoft Fix it solution for Security Advisory 2847140, which relates to a vulnerability for IE8.

    Although it is anticipated that there will be an update included with next week's security updates, anyone with IE8 installed is advised to install the Fix it solution.  The Fix it uses the Windows application compatibility toolkit to make a small change at runtime to mshtml.dll every time IE is loaded. 

    Below are the links to both apply and uninstall the Fix it solution: 
     
    Apply Fix itUninstall Fix it

    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

    If you have Windows Vista or Windows 7 installed, you should have updated to IE9 or IE10.  In the event you haven't, it is strongly advised that you update!

    References:



    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Monday, January 14, 2013

    MS13-008 Released for Security Advisory 2794220


    Microsoft released an out-of-band security update to address the issue described in  Security Advisory 2794220.

    The update is to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected.  

    This update is critical if you have Internet Explorer versions 6, 7 or 8 installed on your computer.  Windows XP users of IE6 or IE7 should update to IE8 as soon as possible.  Windows Vista and Windows 7 users should be using IE9.

    Note:  The Advance Notice for this update to Internet Explorer versions 6-8 indicated if the Microsoft Fix it was applied, it was not necessary to uninstall it prior to updating IE. 

    The advice provided now is to disable the Fix it after updating as it is no longer required.

    Fix it


    Disable

    Fix this problem
          Microsoft Fix it 50972

    References:



    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Sunday, January 13, 2013

    Advance Notification for Update to Address Security Advisory 2794220

    Security Bulletin
    On Monday, January 14, 2013, Microsoft is planning to release an out-of-band critical security update for the issue described in  Security Advisory 2794220.

    The update is to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected. 

    Although Microsoft has seen only a limited number of customers affected by the issue, the potential exists that more could be affected.  Thus, it is advised that the update be installed as soon as possible. 

    Even with the update, if your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    If you applied the Fix it released in Security Advisory 2794220, it will not need to be uninstalled before applying the security update.

    References



    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Saturday, December 29, 2012

    Microsoft Security Advisory 2794220

    Security Advisory
    Microsoft released Security Advisory 2794220 to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected.

    At this time, Microsoft is aware of a very small number of targeted attacks.  This issue allows remote code execution if users browse to a malicious website with an affected browser.  Generally, this is a result of an attacker convincing someone to click a link in an email or instant message.

    Recommendations:

    Microsoft is actively working to develop a security update to address the issue.  In the meantime, please consider the following suggestions:

    1.  Update Internet Explorer -- If your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    2.  Update or Uninstall Java -- Current exploits of this type of vulnerability in Internet Explorer use third-party software, including Oracle’s Java, to help obtain reliable exploitation.

    Most home computer users no longer need Java.  Following are reasons why someone may need Oracle Sun Java installed on their computer:

    • Playing on-line games generally requires Java.
    • With OpenOffice, Java is needed for the items listed here
    • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
    • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
    If you need Java, be sure you have uninstalled all old, vulnerable versions and have only the most recent release installed on your computer.  The current version of Java is Version 7 Update 10.
     

    3.  Install and configure EMET -- The Enhanced Mitigation Experience Toolkit was designed to help prevent hackers from gaining access to your system. It prevents exploitation by applying in-box mitigations to help protect against this and other issues and should not affect usability of websites.

    An easy guide for EMET installation and configuration is available in KB2458544.  Additional information about configuring EMET is available in the EMET User's Guide, in the following locations:
    • 32-bit systems -- C:\Program Files\EMET\EMET User's Guide.pdf
    • 64-bit systems -- C:\Program Files (x86)\EMET\EMET User's Guide.pdf
    Additional suggestions are available in the MSRC Blog post and the Security Advisory, referenced below.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Friday, September 21, 2012

    Microsoft MS12-063 – Critical Cumulative Security Update for Internet Explorer


    Microsoft released MS12-063, a cumulative update for Internet Explorer addressing Security Advisory 2757760 as well as four other critical-class remote code execution issues.  The update requires a restart.
      The Bulletin addresses the following issues from the Common Vulnerabilities and Exposures (CVE) list:
      Internet Explorer 10 on Windows 8 and Windows Server 2012 is not affected.  All other versions of Internet Explorer are affected

      Support

      The following additional information is provided in the Security Bulletin:

      References





      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Wednesday, September 19, 2012

      Out of Band Internet Explorer Security Update

      Security Bulletin
      On Friday, September 21, 2012, Microsoft  will release MS12-063, a cumulative update for Internet Explorer addressing Security Advisory 2757760 as well as four other critical-class remote code execution issues.  The update will require a restart.

      Microsoft Fix it

      In addition, a Microsoft Fix it solution is available now for applying ahead of the update to protect your computer.

      Fix it
      EnableDisable
      Fix this problem
      Microsoft Fix it 50939
      Fix this problem
            Microsoft Fix it 50938

      (HT:  ky331)

      References





      Home
      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Sunday, October 09, 2011

      How Windows PCs Get Infected with Malware

      CSIS Security Group in Denmark conducted a study of almost three months where they collected real-time data from various so-called exploit kits that Danish users were exposed to.  As described by Peter Kruse, Partner and Security Specialist at CSIS:
      "An exploit kit is a commercial hacker toolbox that is actively exploited by computer criminals who take advantage of vulnerabilities in popular software. Up to 85 % of all virus infections occur as a result of drive-by attacks automated via commercial exploit kits."

      How PCs Get Infected

      The CSIS study revealed that as much as 99.8 % of all virus/malware infections were a direct result of not updating five specific software packages.  Aside from missing Microsoft security updates, the study revealed the following out of date programs as being the most used by malware:  Java JRE (37%), Adobe Reader and Adobe Acrobat (32%), Adobe Flash (16%) and Microsoft Internet Explorer (10%).

      Third-Party Software

      Setting aside browser and operating system for the moment, what is notable from the CSIS study is the impact of third-party software, notably Java JRE, Adobe Reader and Adobe Acrobat and Adobe Flash.

      Oracle Java JRE
      When it comes to Oracle Java JRE, you may have it installed on your computer but might not even need it.  Following are reasons why someone may need Oracle Sun Java installed on their computer:
      • Playing on-line games generally requires Java.
      • With OpenOffice, Java is needed for the items listed  here . 
      • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
      • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
      If the above does not apply to you, consider uninstalling Java.  In the event you discover that it is needed, you can always download the most recent version.

      Adobe Products
      Regular readers of this blog are familiar with my postings of critical updates for Adobe products.  You may not realize, however, that there have been over a dozen critical updates of Adobe products just this year between February and September.  Combined, out-dated Adobe products were the direct result of 48% of the infections in the analysis.

      Although I will continue providing updates for these products, it is advisable that you check that you have the most recent versions of Adobe products.  Personally, I switched to an alternate PDF reader some time ago.  There are a number of open source readers available from http://pdfreaders.org/.  Others include Nitro Reader and Sumatra PDF.

      Internet Explorer

      Although Internet Explorer is listed as shown in the CSIS analysis as the most affected browser, the report falls short in not breaking down the statistics by browser version.  According to the IE6 Countdown, at the end of September, 2011, 9% of the world is still using IE6.

      It is not very likely that 66% of  reported thousands of users in the analysis who had been exposed to drive-by attacks were using IE9.  Nonetheless, Denmark should be commended with only 0.7% of the users still on IE6.  The percentage still using IE7 is unknown.  Considering the high percentage of affected Windows XP computers, it would not be surprising to learn that the majority have not updated to IE8.

      References

      CSIS: This is how Windows get infected with malware
      IE6 Countdown
      Microsoft Download Center - Windows Internet Explorer 8 for Windows XP


      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Thursday, August 11, 2011

      Microsoft Update Impacts WinPatrol Cookie Monitoring

      WinPatrol fans who monitor cookies in Internet Explorer will discover after installing the latest Microsoft security updates that cookies do not display as expected in WinPatrol.

      Instead of seeing the expected site or cookie name displayed, cookies are identified as alpha-numeric.txt files (i.e., HILD912G.txt).

      In testing, I intentionally started installing the security updates one-by-one, selecting Microsoft Security Bulletin MS11-057 - Critical: Cumulative Security Update for Internet Explorer (2559049) first since it applies to all three operating systems and browsers. Indeed, following a restart, I was able to confirm the change in cookie display for IE9 on Windows 7. 

      Based on feedback from WinPatrol users, this issue has been confirmed in Windows XP, Windows Vista and Windows 7 with IE8 and IE9.  (IE6 and IE7 have not been tested but will likely be impacted the same since the update applies to all versions of Internet Explorer.)

      MS11-057 is a critical security update and it is strongly advised that it be installed. Cookies are a minor issue compared to the fix in this update, which, as described in the MSRC Blog:

      "resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer."
      Bill Pytlovany has been advised of the situation and is actively working on a solution.  




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Friday, March 04, 2011

      Internet Explorer 6 Countdown

      Are you included among the 12 percent of people from around the world who are still using Internet Explorer 6?  Although browser statistics of visitors to Security Garden indicate only 2.6 percent use IE 6, it is long past time for those visitors to update.

      I understand that not everyone has the latest and greatest computer.  These are hard times and we all need to watch our budget.  However, there have been numerous advances in IE since version 6 was introduced ten years ago.  Forget the pretty-pretty new features.  Most significant, from my point of view, are the enhanced security features in the newer versions of Internet Explorer.

      Granted, IE9 is not compatible with Windows XP.  However, you can still upgrade to IE8. IE8 has significant built-in security features, including SmartScreen, Cross Site Scripting (XSS) Filter, Click-jacking prevention, Data Execution Prevention, InPrivate Browsing, and InPrivate Filtering.  (See Internet Explorer 8: Features/ for information about these security and safety features.)  For those who would rather upgrade in stages, if need be, you can start with IE7 (download link below) and then follow up with IE8.

      Although most of the Security Garden visitors are from the United States, United Kingdom and Canada, people from all around the world find their way here.  If you are represented by the list of actual Security Garden visitors in the list of countries below, and are also included among the 2.66 percent of my visitors who use IE6, please update today!

      Security Garden visitors from around the world:

      Australia
      Barbados
      Belgium
      Brazil
      Brunei Darussalam
      Bulgaria
      Canada
      Chile
      Croatia
      Czech Republic
      Denmark
      Dominican Republic
      Finland
      France
      Germany
      Greece
      Hong Kong
      Hungary
      India
      Indonesia
      Iraq
      Ireland
      Italy
      Japan
      Korea, Republic Of
      Libyan Arab Jamahiriya
      Lithuania 
      Macedonia
      Malaysia
      Mexico
      Netherlands
      New Zealand
      Norway
      Pakistan
      Peru 
      Philippines
      Poland
      Puerto Rico
      Romania
      Russian Federation
      Serbia
      Singapore
      South Africa
      Spain
      Sri Lanka
      Sweden
      Switzerland
      Taiwan
      United Kingdom
      United States
      Venezuela
      Vietnam



      Don't be one of these statistics:



      References:

      Clubhouse Tags: Clubhouse, Microsoft, Internet Explorer, IE6, IE7, IE8, IE9, Windows XP, Windows Vista, Windows 7, Information, Windows



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Thursday, January 27, 2011

      Data Privacy

      Data Privacy Day is "an international celebration of the dignity of the individual expressed through personal information."

      There is no doubt that we have evolved into a digital society. Whether it is via a traditional laptop or desktop computer or a mobile device, we are seldom far from being connected to the Internet.

      Computers surround our everyday lives. When we make a credit card purchase, the information is transmitted over the Internet.  Computers are an integral part of the airline reservation services we use to schedule a family holiday.  If we need to contact our local police or fire department, they access directions to our home via a computer.

      Much of our personal information is stored on computers.  The information contained in our medical, insurance, pharmacy, employment and school records, bank and credit reports, tax and government data provide not only a story of our life but also a key to our identity. 

      There is more to online privacy than personal records.  Consider the following activities:
      • Information searches
      • Browsing online for products and services
      • Information shared with friends on social networking sites
      • Travel and location information with location-enabled Smartphone applications

      As any of the above online activities are conducted, information is stored on your computer. This information is potentially available for data collection and manipulation, resulting in targeted advertisements. Advertisements are a “necessary evil”. Maintaining websites is not cost free.  Thus, the need for the subsidy provided website owners by advertisers. Although many free and licensed applications and browser add-ons have been created to block or remove what is commonly referred to as tracking cookies, other means of tracking website visits have evolved.


      The Future

      Particularly due to a year-long study by the Federal Trade Commission (FTC), a lot of attention has been devoted to online privacy. On December 1, 2010, the FTC released a preliminary report entitled "Protecting Consumer Privacy in an Era of Rapid Change". The one hundred twenty-two (122) page PDF file is available for download at http://www.ftc.gov/os/2010/12/101201privacyreport.pdf ). Briefly, the FTC report provides a broad framework centered on three concepts: privacy by design, simplified choice, and greater transparency.

      Within days of the FTC report, the Microsoft Internet Explorer 9 team announced tracking protection for inclusion in the Internet Explorer 9 Release Candidate. Both privacy advocates and consumers alike will see this as a major step forward to providing additional online privacy.

      IE9 and Privacy: Introducing Tracking Protection
      • Opt-in “Tracking Protection” to identify and block many forms of undesired tracking.
      • “Tracking Protection Lists” to enable control of the third-party site content that can be tracked when online.

      clip_image001With Tracking Protection in Internet Explorer 9 (IE9), you will have control of what data is shared as you navigate from one website to another.  This is accomplished by adding Tracking Protection Lists (TPL) to Internet Explorer. Anyone, and any organization, on the Web can create and publish Tracking Protection Lists. 

      Although the default installation of IE9 will not include Tracking Protection lists (TPL), the option will be available to add lists created by others.  In effect, the lists provide a “Do Not Call” indicator for external content, unless you visit those sites directly. The TPL will also include the ability to include “OK to Call” addresses.  This is to ensure you can access these sites even if one of their lists has the site identified as “Do Not Call.”  Tracking Protection is not on by default. Thus, after turning on Tracking Protection, it will remain on until you turn it off.

      The process of change is not simple.  Realize that it will be ongoing.  As a postscript to the IE Blog article, IE9 and Privacy: Introducing Tracking Protection Dean Hachamovitch, Corporate Vice President, Internet Explorer, added:
      "One aspect of the larger tracking discussion involves a change to “HTTP headers.” The key thing to note is that such a change is the start but only part of delivering tracking protection. It is a signal to the web site of the consumer’s preferences. The rest of that solution (defining what that signal from the consumer means, what to do with it, verification, enforcement, etc.) is still under construction."
      Mozilla Firefox "Do Not Track"


      Last week, Mozilla announced “Do Not Track”.  The concept is to provide a way for people to opt-out of online behavioral advertising (OBA) by transmitting a Do Not Track HTTP header every time their data is requested from the Web. This header will notify the website that the visitor wants to opt-out of third-party tracking for behavioral advertising.  When the feature is enabled, advertising networks will be told by Firefox that the user has asked to opt-out of behavioral advertising.

      As indicated in the Mozilla announcement, the "initial proposal does not represent a complete solution" but rather is one step to see if the header approach can work.  The goal is to provide a more nuanced, persistent tool for communicating privacy choices on the web.  Do Not Track (DNT) is expected to be introduced in version 4.1.

      More information is available in the MozillaWiki FAQ: Privacy/Jan2011 DoNotTrack FAQ


      Today

      The Internet Explorer 9 tracking protection will provide a viable option for protecting your privacy. I expect that the other browsers will provide similar methods of providing tracking protection in future releases. In the meantime, there are other options available for protecting your privacy. In the following segments are instructions for restricting tracking cookies as well as examples of options and a few of the available browser extensions for managing DOM Storage and Flash Cookies. Also included are browser settings for private browsing sessions.

      Cookies


      There are considerations when blocking cookies.  Keep in mind that not all cookies are tracking your every move.  As a simple example, website logon cookies remember pages read. Also, note that cookies cannot be used to run code (run programs) or to deliver viruses to your computer.

      Session Cookies
      are also useful. Some websites require session cookies to track your movements on the site. Without the session cookies, you would repeatedly be asked for the same information already provided.  As an example, session cookies are used when shopping online to remember items placed in a shopping cart.  Without the session cookies, the shopping basket would disappear before you reach the checkout.  Session cookies are stored in memory not on the hard drive. They expire when the browser is closed.

      Third-party Cookies
      are cookies that are set by one site, but can be read by another site.  This enables advertisers that use third-party cookies to track your visits to the websites on which they advertise. With third-party cookies, your web surfing habits are logged, allowing advertisers to tailor advertisements to your interests.

      What if you do not want to be tracked?


      The Network Advertising Initiative (NAI) provides a system for opting out of popular ad networks. The Network Advertising Initiative tool identifies the member companies that have placed an advertising cookie on your computer. Using the NAI tool is simple. Merely choose the provided option to Select All member companies or check specific boxes that correspond to the company(s) from which you wish to opt out. After you click the Submit button, the tool will automatically replace the selected advertising cookie(s) and verify your opt-out status.

      TrackBlocker
      is a Firefox extension provided by PrivacyChoice.org. The extension not only blocks cookie tracking by over 200 ad companies it also deletes Flash cookies from these companies.
      Most web browsers have a feature in their settings that lets you disable cookies from third-party websites. Shown below are the instructions for the setting to block tracking cookies for the major web browsers.

      To block third-party cookies in Internet Explorer, do the following steps:
      • Launch Internet Explorer and select the Tools menu
      • Click Internet Options, click Privacy, and then click Advanced.
      • Check the box next to Override automatic cookie handling
      • Check the option to Block in the Third-party Cookies column.
      • Click OK.
      clip_image002

      Firefox
      also has the option to block third-party cookies.  The steps include:
      • Launch Firefox and click the Tools menu
      • Select Options and Privacy
      • Uncheck the option to Accept third-party cookies.
      clip_image003

      Google Chrome
      allows all cookies by default.  Below are the steps for changing the default settings:
      • Launch Google Chrome and click the Tools menu
      • Select Options.
      • Click the Under the Bonnet tab and locate the Privacy section
      • Choose the Content settings button.
      • Click the Cookie settings tab and choose your preferred settings.
      • Click Close.
      clip_image004

      Google Chrome now also has available the recently announced Keep My Opt-Outs.  The extension provides users to out of cookies that are related to personalized online ads. Note, however, that a small percentage of personalized ads also come from companies who do not yet participate in self-regulatory efforts. Thus, do not expect perfection.

      Safari has similar instructions as the other browsers:
      • Launch Safari and go to Preferences and then click the Security tab
      • Click the Show Cookies button
      • Click the radio button for the option Only from sites I visit (Block cookies from third parties and advertisers).

      The terminology used by Opera is similar to Safari.
      • Launch Opera and press CTRL+F12 to open the Opera Preferences menu.
      • Select the Advanced Tab
      • Select Cookies from the left sidebar menu.
      • Select Accept cookies only from the site I visit to disable third-party cookies.
      clip_image005

      Opera also has the option to disable “referrer logging”, which allows a website to know what site you were previously visiting. Some sites depend on referrer logging to work correctly. If you elect to disable referrer logging in Opera, it can be done through Settings > Preferences > Advanced > Network. Uncheck Send referrer information.

      DOM Storage


      Although we generally associate the term cookie with data stored by websites we visit, DOM Storage does not store cookies per se. Rather, DOM storage is per-session or domain-specific data. It is easier to control how information stored in one window is visible to another with DOM Storage. (According to W3C, officially, the term is Web Storage but the common term is DOM for Document Object Model.)

      DOM Storage is comprised of two primary parts, Session Storage and Local Storage. In Session Storage, any data input is stored for the duration of the session. Thus, if a new tab is opened, the data from the Session in the original tab is stored for the new tab. Conversely, Local Storage spans multiple windows and persists beyond the current session. Local Storage allows Web applications to store up to 10 MB of user data. This could include data stored offline for later reading.

      Disable DOM Storage

      It is easy to disable DOM storage cookies in both Internet Explorer and Firefox browsers by following the simple instructions below. It is important to note, however, that some sites (i.e., CNN) may not work correctly with DOM storage disabled.

      Internet Explorer
      • Launch Internet Explorer and open the Tools Menu
      • Select Internet Options
      • Click the Advanced tab
      • Scroll down until you reach Security
      • Uncheck the box for Enable DOM Storage
      • Click Ok

      Firefox


      A simple way to disable DOM Storage in Firefox is with the extension, Better Privacy. To make the change manually, do the following:
      • Launch Firefox and type about:config in the address bar
      • In response to the warning, click I'll be careful, I promise!
      • Scroll down until you reach dom.storage.enabled or copy/paste dom.storage.enabled in the filter
      • Double-click the dom.storage.enabled line item and it will change from its default value True to False
      • Close the about:config tab

      To undo the change to Internet Explorer or Firefox, simply reverse the above steps.

      Recently, Google NotScripts extension was released. It is currently necessary to create a password when using the extension and also make other settings changes back to default. The Opera and Safari browsers use DOM storage but, at this point, it does not appear that either provides a means for disabling it.

      Flash Cookies


      Blocking all or just third-party cookies and clearing browser history does not remove another form of cookies -- Flash cookies. Flash cookies are also known as local shared objects (LSO) or Super Cookies. Because Flash cookies are not as well known as HTTP cookies, they provide the additional advantage for advertisers for tracking and providing targeted advertising. As a result, Flash cookies also jeopardize your online privacy. The same advantages of Flash cookies over HTTP cookies for advertisers are disadvantageous in maintaining privacy.

      A partial list of Flash Cookie/LSO properties includes:
      • Unlike HTTP cookies, Flash Cookies are never expiring
      • HTTP cookies are 4 KB, compared to the default storage availability of 100 KB of storage for LSO’s.
      • Browsers provide control mechanisms for HTTP Cookies, which is not generally the case for LSO's.
      • Highly specific personal and technical information (including system and user name) can be stored via Flash.
      • The stored information can be sent to the appropriate server without permission.
      • There is no easy way to monitor sites following you with flash-cookies.
      • LSO’s work in every flash-enabled application, thus allowing cross-browser tracking via the shared folders.

      Considering the complexity of Flash Cookies, the question in your mind most likely is how to control or remove them from your computer. Below are few options for consideration.

      clip_image006Adobe provides an On-line Settings Manager, illustrated below, to configure Flash Player settings. To use the tool, you need to go to the Adobe Website Storage Settings panel to make the changes to the settings. Although the changes are made via the on-line manager, the settings are only stored on your computer. I have discovered that the Adobe On-line Settings Manager version has changed several times. As a result, it has been necessary after a Flash Player update to revisit the site to verify the settings.


      For on-line game players, note that Flash cookies are used to save a game in progress. In that case, you will want to add an exception to the on-line game site.

      The Taco plug-in is available for both Internet Explorer and Firefox. It helps manage and delete standard cookies as well as Flash and DOM Storage Cookies. The plug-in also lets you see who is trying to follow your online movements and helps you decline targeted ads from more than 100 ad networks.
      Firefox users have the option of using the BetterPrivacy or Flashblock extension.

      Flashblock blocks all Flash content from loading. It then leaves placeholders on the webpage. With that method, if you wish to view the Flash content, you can click to download and then view it.
      The BetterPrivacy extension manages Flash Cookies by removing them on every browser exit. It also provides the capability of reviewing, protecting or deleting new Flash-cookies individually. If desired, the automatic functions can be disabled. BetterPrivacy also protects against the previously discussed DOM Storage.

      Private Browsing


      Private browsing options are available for occasions when you do not want to leave evidence of your browsing or search history. When surfing at an Internet Café or unsecured Wi-Fi location this feature is recommended to protect not only your privacy but also security should it be necessary to access a banking or similar secure site.


      Internet Explorer
      Internet Explorer 8 and Internet Explorer 9 provide several easy ways to start InPrivate Browsing. The feature is available from the Safety menu, by pressing CTRL+Shift+P, or from the New Tab page. Any of those actions will result in launching a new browser session that will not record any information, including searches or website visits. Closing the browser window will end the InPrivate Browsing session.
      Note: InPrivate Browsing is not available in earlier versions of Internet Explorer.

      Firefox


      To access Private Browsing in Firefox, click on the Tools menu and select Start Private Browsing or key CTRL+Shift+P. To end Private Browsing, reverse the process by clicking on the Tools menu and selecting Stop Private Browsing.

      Google Chrome

      Private browsing in Google Chrome is called Incognito mode. To turn on Incognito mode, from the Tools menu, select New incognito window or key CTRL+SHIFT+N. To stop browsing in Incognito mode, close the Chrome window.

      Opera

      Opera provides the option of launching either a private tab or window. Any new tab opened in a private window is a Private Tab. Browsing history is removed when the tab or window is closed. Click the red O in the upper, left corner and select Tabs and Windows | New Private Tab or Tabs and Windows | New Private Window. This feature is also available from the File menu on the menu bar.

      Finally

      clip_image007 It is apparent that there is a long way to go toward online privacy before the tenants proposed in the FTA draft report are accomplished.  Internet Explorer 9 is taking a step forward in design with tracking protection as is Mozilla Firefox.  I anticipate that the other browsers will follow with something similar. A simplified choice and an easier method of changing the settings is needed. Beyond that, and more importantly, a clear understanding of the information advertisers are collecting is needed in order to make informed decisions about what information to allow or block.



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...