Web Design - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Web Design arrow A Slow Death for ActiveX?
A Slow Death for ActiveX?
By Larry Seltzer

Rate This Article:
Add This Article To:
Opinion: For many reasons the writing is on the blog for the much-maligned programming interface.

The Microsoft of recent decades has been much more willing than in the past to cast its own bright ideas aside and do what its customers want instead. Every few weeks we see another example of this in Internet Explorer 7.

The more I see of IE 7 the more I think it's going to make a big splash when it hits the scenes. Even though it's a better browser on Windows Vista than on earlier versions of the operating system, it's got some impressive features on Windows XP as well. Many of them come from Microsoft's willingness to adopt a Firefox feature or abandon something that's been in IE for years. Consider the way IE 7 starts what I think is a long-term shift away from ActiveX.

I've always thought ActiveX got a bum rap, all things considered. From Day 1 it has been the subject of dire predictions and warnings, and a conventional wisdom has emerged among some that it's a major source of vulnerability and an object of attack. None of this is true, but truth isn't the only thing that matters.

My interest in all this was piqued by Microsoft's announcement (typically, for these days, through a blog) that IE7 will have a native XMLHTTPRequest object as opposed to one implemented in an ActiveX control, as is the case with IE 6.

Click here to read about how support for AJAX development is rising.

XMLHTTPRequest, which allows Web-based scripts to themselves perform HTTP transactions, is one of the main enabling features of AJAX, a new generation of Web applications with rich (for a browser) user interfaces. Microsoft really is the pioneer of such things starting with their Outlook Web Access.

The fact that XMLHTTPRequest in IE 7 will be a native control will matter very little to programmers who will simply need to include a few lines of script to test for the native control and use it, or the ActiveX version of it isn't. This is something that needs to be done only once, and so can be done once in a central include file or a global.asa, and the bulk of the software will remain unmodified. Actually, they don't even really need to do make that change. If your program uses the ActiveX version it will continue to work, but you will have new possibilities.

Next page: More ActiveX restrictions.

So what's the advantage of the native control? It means you can block all ActiveX controls and still do AJAX. Why would Microsoft do this? Do they think the XMLHTTPRequest object is unsafe? I don't think so. I'm more inclined to believe that customers asked for it, and the company wants their customers to be happy and stick with IE, especially now that Firefox presents a credible alternative. But whatever the merits of their desire to do so, it means that some customers, important ones, want to avoid ActiveX, and Microsoft is willing to help them out.

IE 7 goes further in the move away from ActiveX: A new feature (really more of a design mandate) called "ActiveX Opt-in" dictates that only a few, very popular and well-vetted controls (like Flash) will work at all in the default IE7 setup. All others will be disabled by default, even if they have been previously installed on the system. Pages that invoke these disabled controls will cause IE7 to show one of the now-familiar "information bars" at the top of the browser window, and the user will have to explicitly approve execution of the control.

For advice on how to secure your network and applications, as well as the latest security news, visit Ziff Davis Internet's Security IT Hub.

Opt-In is something that will affect many users, causing them to have to make security decisions and, no matter how hard Microsoft tries, roughing up the user experience. Put another way, it will discourage the use of ActiveX by developers and corporate IT; that's how I would see it if I were a developer or in IT.

I've already said that Microsoft has gone down this road because customers asked for it, and I'm sure that's true, but there might be another reason: the Eolas patent. After losing rulings in a patent suit Microsoft was forced to make the process of invoking embedded content, such as ActiveX controls, more difficult. (The patent itself is famous nonsense, among the most obviously flawed you'll ever see, but lawyers, it seems, can make up the rules as they go along.)

Put another way, these changes will discourage the use of ActiveX by developers and corporate IT; that's how I would see them if I were a developer or in IT.

What are the options? Obviously ActiveX served many legitimate, as well as illegitimate, purposes all these years. I see a series of answers, mostly resolving down to two approaches: AJAX-type interfaces will mitigate the need to resort to native code on the client, especially when combined with richer server-side code.

Also, if enough of the few approved controls provide programming interfaces themselves, then developers who might have gone through ActiveX can use them as alternatives. The obvious ones are Java and Flash (and Sparkle?). Of course, this puts the security onus on the developers of those systems. Neither of them is perfect, and the same corporate types who are nudging Microsoft away from ActiveX probably frown on Java and Flash as well.

This slow march away from ActiveX will probably tend to increase security generally because it will tend to make it harder for developers to get their code running on users' systems, especially for native code on the client. This won't be as big a blow for security as some will think, but it's a step forward, and it's a further admission that default settings for Internet-facing programs should be restrictive. That's the long-term destination for Windows.

Security Center Editor Larry Seltzer has worked in and written about the computer industry since 1983.

Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.

More from Larry Seltzer


Discuss A Slow Death for ActiveX?
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Web Design Articles          >>> More By Larry Seltzer
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT