Platinum Edition Using Windows 98

Previous chapterNext chapterContents


- 32 -

Internet Security


by Ed Bott

Setting a Security Policy

By its very nature, the Internet is an insecure place. Packets of data move from machine to machine across connections that anyone with a little technical knowledge can tap into. On the Internet, clicking a link can download and run a program written by someone you've never met, whose motives you can't even begin to guess. When you transmit sensitive data over the Internet, it can be intercepted by complete strangers. If you run a server program, a stranger can connect directly to your computer, with consequences you might not be aware of. There's no need for paranoia, but everyone who accesses the Internet should have a healthy respect for its risks.

Windows 98 and Internet Explorer 4.0 include a broad set of security tools. Before you can properly configure these options, however, you need to establish a security policy. This policy should balance the need to protect sensitive data against the undeniable value of open access to information and the wealth of information available on the world's largest network. Different environments have different security requirements as well. With a dial-up Internet connection at home, you might not worry about the risk of break-ins, but on a corporate network, firewalls and other sophisticated security precautions are a must.

These elements should be central to any security policy:

Protecting Your PC from Attack

The idea that your computer might fall victim to a random attack from a stranger sounds like the stuff of science fiction or sensationalist headlines. Unfortunately, this scenario is depressingly common on the Internet, especially where users use direct connections to Internet service providers.

Mainstream news stories stress incidents in which hackers break into a system and steal data, such as credit card numbers. A far more common form of mischief on the Internet, however, is the so-called denial of service attack. The specific techniques vary, but in general these attacks exploit bugs in the way Windows handles TCP/IP packets. When an attacker targets an unprotected Windows machine, the result might be a fatal crash, or the flood of data might cause the system to slow to nearly a halt, forcing the user to reboot.

How Denial of Service Attacks Work

There's nothing new about denial of service attacks; users of UNIX-based computers have been fighting off attacks of this nature for years. Because Windows 95, Windows 98, and Windows NT are so widely used, they're logical targets for new attacks, and would-be attackers spread the details of successful new techniques with shocking speed.

Since the original release of Windows 95, Microsoft has issued several patches to Windows' TCP/IP networking components. Each of these updates was a direct response to a popular denial of service attack. For example, an underground program called Winnuke sends packets that contain out-of-bounds data; without the corrective patch, a Windows system crashes with a blue-screen error when it encounters this type of data. Other attacks include Teardrop, which works by sending fragmented packets of data that cause unpatched Windows systems to crash when they try to reassemble them; Land, which uses phony IP addresses to slow Windows to a crawl as it tries to handle a flood of unidentified data; and Ssping, also known as the "Ping of death," which uses a bug in the popular Ping utility to crash Windows.

The good news is that Windows 98 is invulnerable to these and all other known attacks as of the date it was first released. The bad news? History demonstrates conclusively that there are more networking bugs in Windows, just waiting to be discovered; when they emerge, Microsoft will need to develop and distribute patches to keep Windows users safe from the newly discovered exploits, and users will need to install those patches to avoid data loss and downtime.


TIP: Whenever a new Windows security hole is discovered, Microsoft publishes security alerts with links to downloadable patches. To keep abreast of the latest developments, visit the Microsoft Security Advisor web site, at

http://www.microsoft.com/security


Are You Vulnerable?

Before a would-be attacker can target your PC, he (most are young males) has to identify your IP address and discover an unprotected TCP port. The surest way of protecting yourself from denial-of-service attacks, therefore, is to make sure you have neither a public IP address nor any accessible TCP ports. In other words, never open a direct, modem-based Internet connection. Of course, that's a drastic step that most users of dial-up Internet connections would hardly be willing to take.

For most users, the risks of Internet attacks are low. If you use a modem to access the Internet for brief online sessions, during which you simply browse web pages, your risk of attack is relatively low. The odds that an attacker will stumble across your IP address during a short online session are small.

Users who are most vulnerable to Internet attacks are those with direct, full-time connections, those who run web and FTP servers, and those who use interactive services like Internet Relay Chat (IRC). In all these cases, your IP address is easily available, and an attacker has ample opportunity to probe your system in search of weak spots.

Protecting Yourself from Attack

To keep mischief-makers out of your physical offices, you install and use secure locks. To keep cyber-vandals from breaking into your network, you install, configure, and use a firewall, a secure gateway computer that sits between your network and the router at your Internet service provider. This combination of hardware and software is designed to intercept and filter packets of information, letting through only those that meet your strict standards of security.

There are practically an infinite number of firewall designs, ranging in price from absolutely free to well into six-figure territory. In general, though, firewalls fall into one of two broad categories:

Firewalls can do much more than simply keep out intruders. Because they serve as a central point of access for all traffic in and out of the network, they can enforce business-level restrictions on Internet use--denying access to X-rated sites, for example, or restricting FTP access to trusted sites only. Full-featured firewall packages typically include detailed usage logs and audit reports as well, making it possible to detect attacks as they happen. If you can spot a successful break-in early enough, you can take steps to boot out the bad guys and shore up security as needed.


ON THE WEB: Want more information about firewalls? You'll find links to the definitive Firewalls FAQ and mailing list at
http://www.greatcircle.com.

Configuring Internet Explorer to Use a Proxy Server

With ordinary dial-up Internet connections, client machines connect directly to web or FTP servers, making it possible for a would-be hacker to break into the network. To minimize that risk, most corporate networks include a firewall and one or more proxy servers.

Before Internet Explorer 4.0 can use a proxy server, you must specify its name or IP address. Some proxies (Microsoft Proxy Server 2.0 or later, for example) can automatically configure client machines; in that case, you need to enter the name of the machine that contains the configuration files.


TROUBLESHOOTING:

You're connected to a corporate network and some or all of the options described in this chapter are unavailable. That's usually a sign that the network administrator has used Microsoft's Internet Explorer Administration Kit to enforce security policies from a central server. In that case, most security settings (and many other options, for that matter) will be grayed out and inaccessible. See your network administrator if you need to change one of these settings.


Follow these steps to set up Internet Explorer for use with a proxy server:

1. Choose View, Internet Options, and click the Connection tab. A dialog box like the one in Figure 32.1 appears.

FIG. 32.1 Check this box and enter the name or IP address of your proxy server; port 80 is the standard setting for virtually all web proxies.

2. Check the box labeled Access the Internet Using a Proxy Server.

3.
If your network includes a server that can automatically configure Internet Explorer, click the Configure button, enter the full URL of the server, and click OK. No additional configuration is necessary.

4.
If your network does not include an autoconfiguring proxy server, click in the Address text box and enter the name or IP address of the proxy machine.


NOTE: When configuring a proxy server, you may use either the server's name or its IP address. The effect is identical no matter which technique you use. The administrator in charge of the proxy server can supply information about your network's configuration. 
5. Click in the Port text box and enter the name of the TCP port that the proxy server uses. In the overwhelming majority of cases this will be port 80, the standard for web traffic.

6.
If your network uses separate proxy servers to handle other protocols, click the Advanced button to open the dialog box shown in Figure 32.2. Enter those settings here.

FIG. 32.2 Click the Exceptions text box and specify URLs that you want to access directly, without using the proxy server.

7. Your network administrator might provide direct access to some sites and block access through the proxy server. If instructed to do so, click the Exceptions text box and enter the names of any domains that do not require access through the proxy server. Be sure to enter a protocol prefix (typically http:// or https://) for each address. Use semicolons to separate entries in this list.

8.
Click OK to close the Advanced dialog box.

9.
Click OK to close the Internet Options dialog box and begin using the proxy server.


TIP: On most corporate networks, you should check the box labeled Bypass Proxy Server for Local (intranet) Addresses. The proxy's safety features shouldn't be necessary inside the firewall, and routing intranet requests through the proxy will hurt performance without improving security.

Establishing and Maintaining Internet Security Zones

Internet Explorer 4.0 includes dozens of security settings. Applying each of those options to individual web sites would be impractical; instead, the system lets you group sites into four security zones, each with its own high, medium, or low security settings. Initially, as Table 32.1 shows, all sites are divided into two groups: those inside your company's intranet and those on the Internet. As part of a comprehensive security policy, you can designate specific web sites as trusted or restricted, giving them greater or less access to machines inside your network.

Table 32.1  Security Zones at a Glance

Security Zone Default Locations Included in Zone Default Security Settings
Local intranet zone Local intranet servers not included in other zones; all network paths; all sites that bypass proxy server Medium
Trusted sites zone None Low
Internet zone All web sites not included in other zones Medium
Restricted sites zone None High

As you move from one address to another by using Internet Explorer, the system checks to see what zone the address has been assigned to and then applies the security settings that belong to that zone. If you open a web page on a server inside your corporate intranet, for example, you can freely download files and work with ActiveX controls or Java applets. When you switch to a page on the Internet, however, your security settings might prevent you from using any kind of active content or downloading any files.

There are three built-in security levels, plus a Custom option that lets you pick and choose security settings for a zone. Table 32.2 summarizes the security options available when you first start Internet Explorer 4.0.

Table 32.2  Default Security Levels

Security Level Default Settings
High ActiveX controls and JavaScript disabled; Java set to highest safety level; file downloads prohibited through browser; prompt before downloading fonts or logging on to secure site.
Medium ActiveX enabled for signed controls only, with prompt before downloading; file and font downloads permitted; Java set to medium safety level; all scripting permitted; automatic logon to secure sites.
Low Enable all ActiveX controls, but prompt before using unsigned code; Java set to low safety; desktop items install automatically; file and font downloads permitted; all scripting permitted; automatic logon to secure sites.
Custom Enables user or administrator to select security settings individually.

Adding an Internet Domain to a Security Zone

Initially, Internet Explorer includes every external web site in the Internet zone. Over time, you'll identify some sites that are extremely trustworthy, such as a secure server maintained by your bank or stockbroker. On these sites, you might want to relax security settings to allow maximum access to information and resources available from that domain. Other sites, however, might earn a reputation for transferring unsafe content, including untested software or virus-infected documents. On a network, in particular, you might want to tightly restrict access to these unsafe sites.

To add the addresses for specific web sites to a given security zone, open the Internet Options dialog box, and click the Security tab; the dialog box shown in Figure 32.3 appears.

FIG. 32.3 Adding a web site to the Restricted Sites zone lets you tightly control the site's ability to interact with your PC and network.

By definition, the Internet zone includes all sites not assigned to other zones. As a result, you can't add sites to that zone. Follow these steps to assign specific sites to the Trusted Sites or Restricted Sites zones:

1. Open the Internet Options dialog box and click the Security tab.

2.
Choose a zone from the drop-down list at the top of the dialog box.

3.
Click the Add Sites button.

4.
Enter the full network address of the server you want to restrict in the text box and click the Add button.

5. Repeat steps 3 and 4 to add more server names to the selected zone.

6.
Click OK to close the dialog box.


TIP: To remove a web server from either the Trusted Sites or Restricted Sites zone, click the Add Sites button, select the address from the list, and click the Remove button. Any addresses you remove from a zone again belong to the default Internet zone.

Some special considerations apply when adding sites to the Trusted sites or Local Intranet zone:

FIG. 32.4 Clear one or more of these check boxes to move sites from the Local Intranet zone to the default Internet zone.


TIP: The status bar always displays the security zone for the current page. After you add a site to a security zone, load the page to confirm that the change was effective.

Changing Security Settings by Zone

When you first run Internet Explorer 4.0, all web pages use the same Medium security settings, but it doesn't have to stay that way. If your intranet is protected by a reliable firewall and you use ActiveX components developed within your company, you might want to reset security in the Local Intranet zone to Low. Likewise, if you're concerned about the potential for damage from files and programs on the Internet, you can reset security for the Internet zone to High.

To assign a different security level to any of the four built-in zones, follow these steps:

1. Open the Internet Options dialog box and click the Security tab.

2.
Choose the appropriate zone from the drop-down list.

3.
Click the High, Medium, or Low option button.

4.
Click OK to save your new security settings.

When you choose the High option for the Internet zone (or use custom options to choose similar security settings), don't be surprised if many pages don't work properly. Because ActiveX controls are disabled by default, for example, you're likely to see dialog boxes like the ones in Figure 32.5 when you load an ActiveX-enabled page or attempt to download and play a streaming audio file.

FIG. 32.5 With the security level set to High, many forms of rich content simply won't work. Instead of hearing multimedia files, for example, you'll see a dialog box like this one.

Setting Custom Security Options

If none of the built-in security levels is quite right for the policy you've established, you can create your own collection of security settings and apply it to any of the four security zones. Instead of choosing High, Medium, or Low, use Internet Explorer's Custom option to step through all the security options and choose the ones that best suit your needs. Follow these steps:

1. Open the Internet Options dialog box and click the Security tab.

2.
Choose the appropriate zone from the drop-down list.

3.
Click the Custom option button.

4.
The Settings button, which is normally grayed out, should now be available. Click it, and the Security Settings dialog box appears (see Figure 32.6).

FIG. 32.6 Internet Explorer includes a long list of security settings for each zone. Use context-sensitive help for a concise explanation of what each one does.

5. Scroll through the list and choose the options that best apply to your security needs. If you're not sure what an option means, right-click its entry and choose What's This for context-sensitive help.

6.
After you've finished adjusting all security settings, click OK to apply the changes to the selected zone.


TIP: Have you experimented with security settings to the point where you're afraid you've done more harm than good? Just start over. Open the Security Settings dialog box, choose a security level in the Reset To box, and click the Reset button. That restores the custom settings to the default security settings for that level and lets you begin fresh.

Restricting ActiveX Controls

The single most controversial feature of Internet Explorer 4.0 is its support for ActiveX controls. ActiveX technology, an extension of what was known in previous versions of Windows as Object Linking and Embedding (OLE), commonly refers to component software used across networks, including the Internet. Internet Explorer 4.0 uses ActiveX components in the browser window to display content that ordinary HTML can't handle, such as stock tickers, cascading menus, or Adobe Acrobat documents. An ActiveX chart control, for example, can take a few bits of data from a distant server and draw a chart at the speed of the local PC, instead of forcing you to wait while downloading a huge image file. The Microsoft Investor page (see Figure 32.7) offers a particularly rich example of this capability to quickly gather and manipulate data.

FIG. 32.7 An ActiveX control on this page makes it possible to quickly analyze and display complex data such as stock prices.

When you view a page that includes an ActiveX control, you don't need to run a setup program and restart your browser; the program simply begins downloading, and then offers to install itself on your computer. That's convenient, but automatic installation also allows poorly written or malicious applets free access to your computer and network. Internet Explorer security options let you take control of ActiveX components and apply security settings by zone. You can completely disable all such downloads, or you can rely on digital certificates to decide which components are safe to install.

Customizing ActiveX Security Settings

Whenever Internet Explorer encounters an ActiveX control on a web page, it checks the current security zone and applies the security settings for that zone:


CAUTION: Low security settings put your computer and network at risk. The only circumstance in which we recommend this setting is in the Local Intranet zone, to allow access to trusted but unsigned ActiveX controls developed by other members of your organization.

In zones where some or all ActiveX controls are disabled, Internet Explorer downloads the prohibited control but refuses to install it. Instead, you'll see an error message like the one in Figure 32.8.

FIG. 32.8 Unless you set security options to Low, you'll see this dialog box anytime you encounter an unsigned ActiveX control. With High security, all ActiveX components are disabled.

Table 32.3 shows default ActiveX settings for each security zone. If you don't see a mix of options appropriate for your security policy, choose a zone and use Custom settings to redefine security levels.

Table 32.3 ActiveX Security Settings by Zone

Security Setting Option High Medium Low
Download unsigned ActiveX controls Prompt X
Disable X X
Enable
Script ActiveXPrompt controls marked safe for scripting Disable
Enable X X X
Prompt X X
Initialize and script ActiveX controls not marked as safe Disable X
Enable X
Download signed Prompt ActiveX controls Disable X
Enable X
Prompt
Run ActiveX controls and plugins Disable X
Enable X X
Custom security settings offer a way to take advantage of only the ActiveX controls you specifically approve, while prohibiting all others. Choose the Custom security level for the Internet zone, click Settings, and enable two options: Run ActiveX Controls and Plugins, and Script ActiveX Controls Marked Safe For Scripting. Disable all other ActiveX security settings. With these security settings, currently installed ActiveX controls function normally. When you encounter a new page that uses an ActiveX control, it refuses to install; you can choose to install it by temporarily resetting the security options for that zone.

Using Certificates to Identify People, Sites, and Publishers

Internet Explorer uses digital certificates to verify the publisher of an ActiveX control before determining how to handle it. This feature, called Authenticode, checks the ActiveX control for the existence of an encrypted digital signature. IE4 then compares the signature against an original copy stored on a secure web site to verify that the code has not been tampered with. Software publishers register with certifying authorities such as VeriSign, Inc., who in turn act as escrow agents to verify that the signature you're viewing is valid.


ON THE WEB: For more information about how Authenticode uses digital signatures and certifying authorities, see
http://www.verisign.com/developers/authenticodefaq.html

If Internet Explorer cannot verify that the signature on the ActiveX control is valid, you see a Security Warning dialog box (see Figure 32.9). Depending on your security settings for the current zone, you might be able to choose to install the control anyway.

FIG. 32.9 You'll see this warning when Internet Explorer can't verify that a certificate is valid. Click Yes to install the software anyway or No to check again later.

If the Certifying Authority verifies that the signature attached to the control is valid, and the current security zone is set to use Medium settings, you will see a dialog box like the one in Figure 32.10.

FIG. 32.10 Use the links on this certificate to see additional information about the publisher of ActiveX controls you download.

The Security Warning dialog box confirms that the signature is valid. In addition, it offers links that you can follow for more information about the publisher and gives you the option to add that publisher to a list of trusted sites.


NOTE: To view and edit the full list of trusted publishers and certifying authorities, choose View, Internet Options, click the Content tab, and look in the Certificates box. 


CAUTION: A valid certificate provides no guarantee that a signed ActiveX control is either bug-free or safe. The certificate simply identifies the publisher with reasonable certainty. Based on that identification and the publisher's reputation, you can decide whether to install the software, and in the event something goes wrong you know who to call for support.

Managing ActiveX Components on Your Computer

Every time Internet Explorer adds an ActiveX control, it downloads files to the local computer and makes adjustments to the Windows Registry. Unlike conventional programs, you can't use the Control Panel's Add/Remove Programs applet to remove or update components; but there is a way to manage this collection. Follow these steps:

1. Choose View, Internet Options and click the General tab.

2.
In the box labeled Temporary Internet files, click the Settings button. The Settings dialog box appears.

3.
Click the View Objects button to open the Downloaded Program Files folder. You'll see a list of all installed ActiveX controls and Java class libraries (see Figure 32.11). If you're not sure what a control does, right-click and choose Properties to see additional information.

FIG. 32.11 All installed ActiveX controls appear in this folder. Use the right-click shortcut menus to inspect the file's properties, update it, or remove it.

4. To delete one or more components, right-click the entry or entries and choose Remove from the shortcut menu. This step deletes each component's executable file and clears out any registry settings as well.

5.
To update one or more components with the most recent versions, right-click the entry or entries and choose Update from the shortcut menu. This step checks the original source for each file (usually an Internet address), replaces the component with new versions, and updates applicable registry settings as needed.

6.
Close the Downloaded Program Files window and click OK to close the Settings dialog box.

Limiting Java Applets

Like ActiveX controls, Java applets extend the capabilities of Internet Explorer by displaying and manipulating data and images in ways that HTML can't. There's a significant difference between ActiveX and Java, though. Java applets run in a virtual machine with strict security rules. The Java Security Manager (sometimes referred to as the sandbox) prevents applets from interacting with resources on your machine, whereas ActiveX controls are specifically designed to work with files and other applications.

Unlike ActiveX controls, Java applets are not stored on your machine. Instead, every time you access a Java-enabled page, your browser downloads the applet and runs the program in the Java virtual machine. When you are finished with the applet, it disappears from memory, and the next time you access the page you have to repeat the download. Over slow links, large Java applets can take excruciatingly long times to load, although the results can be impressive, as the example in Figure 32.12 shows.

FIG. 32.12 This stock-charting page is an excellent illustration of the rich capabilities of Java applets.

Internet Explorer's Security Settings dialog box lets you control specific aspects of the Java interface. Like the security settings for ActiveX controls, you can assign ready-made Low, Medium, or High options to Java applets, or disable Java completely. There's even a Custom option, although most of its settings are meaningful only to Java developers. To adjust Java security, follow these steps:

1. Choose View, Internet Options, and click the Security tab.

2.
Choose a zone from the drop-down list and click the Custom option button.

3.
Click the Settings button.

4.
Scroll through the Security Settings dialog box until you reach the Java section.

5.
Choose one of the five safety options.

6.
If you select the Custom option, a new _Java Custom Settings button appears at the bottom of the dialog box. Click this button and the Custom Permissions dialog box appears (see Figure 32.13).

FIG. 32.13 Internet Explorer lets you tightly control the Java virtual machine, but only an experienced Java developer will be able to work comfortably with these options.

7. To change permissions in the Permissions dialog box, click the Edit Permissions tab. Select individual security options from the top of the dialog box, or use the drop-down list at the bottom of the box to select High, Medium, or Low security settings.

8.
Close all three dialog boxes to apply the changes you've made.


ON THE WEB: Earthweb's Gamelan site is the best place on the Internet to look for Java applets and detailed information about the Java language. You'll find a link to these pages at

http://www.developer.com/directories/directories.html


Blocking Dangerous Scripts and Unsafe File Downloads

In addition to its ability to host embedded controls and applets, Internet Explorer supports simple scripting, using JavaScript and VBScript. With the help of scripts, web designers can create pages that calculate expressions, ask and answer questions, check data that users enter in forms, and link to other programs, including ActiveX controls and Java applets.

Although the security risks posed by most scripts are slight, Internet Explorer gives you the option to disable Active scripting as well as scripting of Java applets. You'll find both options in the Security settings dialog box when you choose Custom settings.

A far more serious security risk is the browser's ability to download and run files. Although the risk of executing untrusted executable files is obvious, even document files can be dangerous. Any Microsoft Office document, for example, can include Visual Basic macros that are as powerful as any standalone program. To completely disable all file downloads, select the built-in High security level. With this setting turned on, you'll see a dialog box like the one in Figure 32.14 whenever you attempt to download a file from a web page.

FIG. 32.14 With the security level set to High, no file downloads are allowed. When you attempt to download any file, including programs and documents, you'll see this dialog box instead.

Working with Secure Web Sites

When is it safe to send confidential information over the Internet? The only time you should transmit private information, such as credit card numbers and banking information, is when you can establish a secure connection by using a standard security protocol called Secure Sockets Layer (SSL) over HTTP.

To make an SSL connection with Internet Explorer 4.0, the web server must include credentials from a designated Certification Authority. The URL for a secure connection uses a different prefix (https://), and Internet Explorer includes two important indications that you're about to connect securely. You'll see a warning dialog box each time you begin or end a secure connection, as well as a padlock icon in the status bar (see Figure 32.15).

FIG. 32.15 Internet Explorer warns you when you switch between secure and insecure connections.

After you negotiate a secure connection, every bit of data is encrypted before sending and decrypted at the receiving end; only your machine and the secure server have the keys required to decode the encrypted packets. Because of the extra processing time on either end, loading HTML pages over an SSL connection takes longer.


ON THE WEB: For more information on certificates for commercial web servers, visit
http://www.verisign.com/microsoft

Although the built-in encryption capabilities of Internet Explorer 4.0 are powerful, one option can help you ensure even greater security. Because of United States Government export restrictions, the default encryption software uses 40-bit keys to scramble data before transmission. That makes it difficult to decode, but a determined hacker can break 40-bit encryption in relatively short order. A much more powerful version of the encryption engine uses 128-bit keys, which are nearly impossible to crack; some banks and brokerage firms require the stronger encryption capabilities before you can access personal financial information online.

At this writing, the 128-bit security software is available only in the United States and Canada, although Microsoft has won permission to make this code available to banks and financial institutions overseas as well. To check which version you have, find a file called Schannel.dll, normally stored in the \Windows\System folder. Right-click the file icon and choose Properties; then inspect the Version tab (see Figure 32.16).

FIG. 32.16 If your copy of Internet Explorer includes the Export version of this security code, your commercial transactions are not as safe as they could be.

The weaker, 40-bit encryption code includes the words Export Version on the Properties tab. The stronger 128-bit security engine includes the label U.S. and Canada Use Only. You can download the 128-bit upgrade, as long as you do so from a machine that is physically located within the United States or Canada. You'll find complete download instructions for the 128-bit upgrade at

http://www.microsoft.com/ie/ie40.

How Safe Are Cookies?

When you view a page in your web browser, some servers give you more than you asked for; quietly, without your knowledge, they record information about you and your actions in a hidden file called a cookie. In more formal terms, these data stores are called client-side persistent data, and they offer a simple way for a web server to keep track of your actions. There are dozens of legitimate uses for cookies. Commercial web sites use them to keep track of items as you add them to your online shopping basket; the New York Times web site stores your username and password so you can log in automatically; still other sites deliver pages tailored to your interests, based on information you've entered in a web-based form.

The first time you access a cookie-enabled server, the server creates a new cookie file in the Temporary Internet Files folder. That record contains the server's domain name, an expiration date, some security information, and any information the webmaster chooses to store about the current page request. When you revisit that page (or access another page on the same site), the server can read and update information in the cookie record. Although information stored in each cookie is in plain text format, most sites use codes, making it nearly impossible to decipher exactly what's stored there.

If you're troubled at the thought of inadvertently sharing personal information with a web site, you can disable cookies completely, or you can direct Internet Explorer to ask your permission before setting a cookie. To control your cookie collection, follow these steps:

1. Choose View, Internet Options, and click the Advanced tab.

2.
Scroll to the Security heading and find the section labeled Cookies (see Figure 32.17).

FIG. 32.17 If you'd prefer not to share personal information with Web sites using hidden cookie files, change this default option.

3. Choose the option you prefer: Disable All Cookie Use or Prompt Before Accepting Cookies.

4.
Click OK to record the new security settings.

Should you be overly concerned about cookies? The privacy risks are minimal, thanks to strict security controls built into your web browser that limit what the server can and cannot do with cookies. They can't be used to retrieve information from your hard disk or your network; in fact, a server can only retrieve information from a cookie that it or another server in its domain created. A cookie can only track your movements within a given site; it can't tell a server where you came from or where you're going next.

Many web designers set cookies simply because that's the default for the server software they use; the information they collect gathers dust, digitally speaking. So when you ask Internet Explorer to prompt you before accepting a cookie, be prepared for a barrage of dialog boxes like the one in Figure 32.18. Try saying no; the majority of web sites work properly without cookies.

FIG. 32.18 You can ask Internet Explorer to warn you before it accepts a cookie; click the More Info button to see the contents of the proposed cookie file, as shown here.

Simplifying Online Purchases with Microsoft Wallet

A new feature in Internet Explorer 4.0 makes it possible to conduct safe transactions over the Internet without having to continually reenter your credit card and address information. The Microsoft Wallet lets you store address and credit card information in encrypted form on your hard disk. When you encounter a web site that allows payments from the Microsoft Wallet, you select a credit card and address from the lists you created earlier, and then complete the transaction.

You can add multiple addresses and credit card entries to the Address Selector and Payment Selector lists. By entering separate home and work addresses, you're free to order products and services for shipment to either address (see Figure 32.19).

FIG. 32.19 With multiple entries in the Microsoft Wallet Address Selector, you can easily tell a merchant where you want to receive goods you order over the Internet.

To add credit card information to the Payment Selector, follow these steps:

1. Choose View, Internet Options. Click the Content tab.

2.
Click the Payments button to open the Payment Options dialog box.

3.
Click the Add button and choose a payment method--Visa, MasterCard, American Express, or Discover--from the drop-down list.

4.
Use the wizard (see Figure 32.20) to enter credit card information, select a billing address (or create a new address entry), and protect the information with a password.

FIG. 32.20 The display name you enter here identifies this card when you use the Microsoft Wallet. The following screen lets you protect this information with a password.

5. To add another credit card, repeat steps 3 and 4.

6.
Click Close to exit the Payment Options dialog box.

Note that address information is not encrypted; anyone with access to your computer can view, edit, or delete this information. Credit card details, on the other hand, are password-protected; if you forget your password, you'll have to delete the entry from the Payment Selector and re-enter it.

Controlling Access to Undesirable Content

Not every site on the Internet is worth visiting. Some, in fact, are downright offensive. That can represent a problem at home, where children run the risk of accidentally stumbling across depictions of sex, violence, and other inappropriate content. It's also potentially a problem at the office, where offensive or inappropriate content can drain productivity and expose a corporation to legal liability in the form of sexual harassment suits.

Internet Explorer includes a feature called the Content Advisor, which uses an industry-wide rating system to restrict the types of content that can be displayed within the borders of your browser. Before you can use the Content Advisor, you have to enable it: Choose View, Internet Options, click the Content tab, and click the Enable button. You'll have to enter a supervisor's password before continuing. After you've handled those housekeeping chores, you'll see the main Content Advisor window(see Figure 32.21).

FIG. 32.21 Use the Content Advisor's ratings system to restrict access to web sites that contain unacceptable content.

The Content Advisor interface is self-explanatory: You use slider controls to define acceptable levels of sex, violence, language, and nudity. After you click OK, only sites whose ratings match your settings are allowed in the browser window.

Surprisingly, many adult sites adhere to the rating system, and an increasing number of mainstream business sites have added the necessary HTML tags to their sites as well. Unfortunately, many mainstream business sites don't use these ratings; as a result, you'll want to avoid setting the option to restrict unrated sites.


Previous chapterNext chapterContents


© Copyright, Macmillan Computer Publishing. All rights reserved.