FYI…

Information on New Address Bar Issue
* http://blogs.technet.com/msrc/archive/2006…-bar-issue.aspx
October 31, 2006
"…In this case, we did look at the scenario in question and asked ourselves what we could do to help improve our anti-phishing and anti-spoofing features so that customers can better protect themselves. We decided that one thing we could do was to add a feature to IE 7 where it always shows the actual URL of the web page, even in pop-up windows. So we added a pop-up window address bar, enabling users to more accurately make a trust decision. In fact, there is a test page as part of this claim and if you look at the page using IE7 you can see the actual URL of the page in the pop-up window. They key thing is that what we said about the issue in 2004 still applies: that you should never decide to trust a web page without first verifying both the address of the web page and an SSL connection…"
> http://www.microsoft.com/technet/archive/c…l.mspx?mfr=true

- http://secunia.com/blog/2/
31 October 2006
"…In 2004 the organisations behind Firefox, Netscape, Opera, Konqueror, OmniWeb, and Safari all confirmed the "Windows Injection" issue to be a vulnerability and subsequently issued fixes for this issue… IE6 users had to change the "Navigate sub-frames across different domains" setting to protect themselves. Today, in IE7 this setting has been enabled by default - that is a good thing - but it doesn't work - that is a bad thing! That in itself qualifies for at least a "security bug". Microsoft writes in their blog* that they didn't consider this to be a vulnerability back in 2004 because it potentially could break functionality on websites! Today, in 2006 they still say this isn't a vulnerability.."

- http://secunia.com/product/12366/?task=advisories

.