AplusWebMaster
Topic Starter
FYI…
How a 'Catch-22' Turns into a 'Shame on You'
- http://isc.sans.org/diary.php?storyid=1230
Last Updated: 2006-03-31 16:27:44 UTC
"We received a submission yesterday from a user who was complaining about a Catch-22 that Microsoft had set up. Microsoft Security Advisory (917077) addresses a vulnerability in Internet Explorer and how it handles HTML objects. The workaround is to change the security setting for ActiveScripting, to either disable it completely or to set it to prompt the user before running each script. On the advisory's web page, there is a link to this feedback page. The potential issue here is that the feedback page is using ActiveScripting. Oops ;-)
Now its not actually that bad for two reasons. First, if you have changed your ActiveScripting setting to "Prompt", you can enable the scripts for this page. Second, even if you have disabled ActiveScripting or choose to not allow it for this page, you will see the error message about needing JavaScript for this page and a link to a page with a non-JavaScript form and you will be redirected to the non-JavaScript page. So while this may be a little annoying, its not a total show stopper…
So why is this bad? Microsoft is using an internal CA to issue the SSL certificate for their web site. Only folks using Internet Explorer to view the page will not get complaints about the certificate. Anyone using any other browser will get an alert. Now since this page deals with security (specifically web browser) security, it is counterproductive to the mindset we are trying to train people to have to use an SSL certificate that they can't verify. If folks just think to them self "Hey this came from Microsoft's security folks, it should be ok" it sets up reinforcement of ignoring SSL certificate errors. The solution is for Microsoft to either use a certificate from a publicly trusted CA or to have their CA certificates included in other browsers. Since there are so many alternative browsers, using a publicly trusted CA is probably the best option. You can export the Microsoft CA certificates from Internet Explorer and import them into Firefox (or another browser) and then you will not see the popup about the server's SSL certificate not being verified."

How a 'Catch-22' Turns into a 'Shame on You'
- http://isc.sans.org/diary.php?storyid=1230
Last Updated: 2006-03-31 16:27:44 UTC
"We received a submission yesterday from a user who was complaining about a Catch-22 that Microsoft had set up. Microsoft Security Advisory (917077) addresses a vulnerability in Internet Explorer and how it handles HTML objects. The workaround is to change the security setting for ActiveScripting, to either disable it completely or to set it to prompt the user before running each script. On the advisory's web page, there is a link to this feedback page. The potential issue here is that the feedback page is using ActiveScripting. Oops ;-)
Now its not actually that bad for two reasons. First, if you have changed your ActiveScripting setting to "Prompt", you can enable the scripts for this page. Second, even if you have disabled ActiveScripting or choose to not allow it for this page, you will see the error message about needing JavaScript for this page and a link to a page with a non-JavaScript form and you will be redirected to the non-JavaScript page. So while this may be a little annoying, its not a total show stopper…
So why is this bad? Microsoft is using an internal CA to issue the SSL certificate for their web site. Only folks using Internet Explorer to view the page will not get complaints about the certificate. Anyone using any other browser will get an alert. Now since this page deals with security (specifically web browser) security, it is counterproductive to the mindset we are trying to train people to have to use an SSL certificate that they can't verify. If folks just think to them self "Hey this came from Microsoft's security folks, it should be ok" it sets up reinforcement of ignoring SSL certificate errors. The solution is for Microsoft to either use a certificate from a publicly trusted CA or to have their CA certificates included in other browsers. Since there are so many alternative browsers, using a publicly trusted CA is probably the best option. You can export the Microsoft CA certificates from Internet Explorer and import them into Firefox (or another browser) and then you will not see the popup about the server's SSL certificate not being verified."