--On Thursday, April 17, 2003 10:00:35 AM -0700 Michael Steele 
<michaels at ...155...> wrote:

> Robert,
> Server 2003 is SO much more secure by default. By default, using IE you
> can't even hit a website without adding it to your trusted sites.
This is a *horrible* "solution".  How does this improve security?  First of 
all, it makes the browser essentially useless and will encourage moving to 
other browsers.  Secondly it encourages diehard IE users to simply trust 
everything.  It not only doesn't solve a security problem, it creates one.

You don't solve poor programming practices by denying access.  You solve 
them by teaching secure programming practices.

I can't say that I'm surprised, since Microsoft continues to prove that 
they have no comprehension of true security practices.  (And before someone 
kneejerks and calls me a *nix bigot, I am and have always been a 
Microsoft-centric IT person.  I'm just not a blinded Microsoft-centric 
professional.  Which perhaps explains why I'm using Unix more and more 
these days.)

