Microsoft's $521 Million Dollar Patch
In 2003, a federal court ruled that Microsoft must pay $521 million to a Chicago-based Eolas Technologies company and the University of California. (Source: cnet.com)
Eolas sued Microsoft on the basis that the software giant infringed upon its patent that allows web browsers to embed and execute interactive programs -- what we know today as "ActiveX Technology" for Internet Explorer.
Now almost three years later, the Eolas vs. Microsoft fiasco is finally coming to a close. According to Internet News, on Tuesday, April 11th, Microsoft will be releasing a patch related to the lawsuit that effectively disables ActiveX.
How the April 11th Patch Affects You
The first is a cumulative security update for Internet Explorer, part of which will include code that alters the way the browser interacts with embedded interactive content. This is the code that is being pushed out as a result of the lawsuit.
The second patch related to the lawsuit is actually a "compatibility patch". This patch will temporarily revert Internet Explorer back to previous functionality with regard to how it handles embedded interactive content. This compatibility patch is being written to give Microsoft customers a 60 day grace period to rewrite their affected web applications. The patch will function until the June security update, at which time the changes brought upon by the lawsuit will become permanent.
ActiveX: an Open Invitation for Spyware
Besides being an interesting modern day David vs. Goliath, the lawsuit and Microsoft's response reminds us of the dangers of embedded interactive content. ActiveX is the primary technology Microsoft uses to deliver this content, and is the technology directly affected by the code change. Though ActiveX is responsible for bringing us "flashy" features, it is an inherently insecure way to deliver content.
Because ActiveX allows web sites to download and install software onto a user's computer -- sometimes without the user even knowing -- it has become a very popular method for Spyware authors to distribute their malicious code.
Though ActiveX was developed to make it easy to display interactive multimedia, its risks often outweigh the potential benefits. Moreover, with the code changes Microsoft is pushing out in response to the lawsuit, the effectiveness of ActiveX will not be what it once was.
For more great tips like this one, be sure to download David's free security newsletter to your mailbox, today!
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.