I'm with you, Tom. ActiveX sends a chill down my spine when I think about security. ActiveX is attracive because it gives you access to many native features of the operating system. But that comes with a pretty steep cost -- it opens up your system to the same kinds of vunerabilities any disk-based app has. And over the Net, well, who knows, right?
Microsoft's answer to this is Digital Signatures -- Explorer will throw a dialog box up warning of the dangers of unsigned controls. And the only way to get controls signed is through a signature authority. But really, when the Strip Poker control is coming down the line, how many people will just dissmiss the warning? And that doesn't take into account bugs in controls that can eat at your system. That's just not possible with a "sandbox" language like Java.
-jeff
![]() | ![]() |
![]() |