Showing posts with label IE. Show all posts
Showing posts with label IE. Show all posts

Saturday, September 6, 2008

IE8 compatibility looking good...so far

I downloaded the first beta of Microsoft Internet Explorer a couple of months ago to check out the new features and, while I was at it, find out how well AdvancedMD runs in it. (I blogged earlier about some of my fears about IE8.)

This is an important issue for us, because, historically, new versions of IE and (especially) Windows have caused us a few problems.

Most of the hurdles have come in the form of security enhancements. For example, we sometimes pop up dialogs outside the viewable area of the screen to test for the existence of controls, measure window title bars and borders, etc. Well, a couple of years ago (IE6 SP2), Microsoft decided to stop allowing windows to be opened outside the visible area of the screen (by default). Not a big deal--the only impact was that screens that used to be invisible suddenly started popping up on our users' screens. (Well, they would have if we hadn't identified and addressed the issue before SP2 was released to our customers.) But it was annoying.

Quite often, we see changes in behavior early in the beta process, and the behavior continues through the second beta, or even the release candidate, but the previous behavior returns in the final release. That happened in IE7, where the beta releases blocked pop-ups in the Trusted Sites zone (and we were scrambling to figure out what to do about it), but then the final release restored the previous behavior. (Pop-ups should not be blocked in the Trusted Sites zone by default.)

So, given this history, I was more than a little concerned when, after downloading and installing IE8 Beta 1, I couldn't run AdvancedMD. At all. I couldn't even log in. In fact, the user name, password, and office key text boxes didn't appear, just a scary-looking security alert of some kind.

Well, a few days ago I installed IE8 Beta 2, certain that I'd see the same behavior, and we would have to start exploring the problem and devising solutions.

To my astonishment, though, AdvancedMD runs perfectly under IE8 Beta 2, at least in all of the areas that I tested. Our QA team will continue to validate my findings, but at the moment, I'm very encouraged.

Perhaps the best explanation for this is that Microsoft invested extremely heavily in IE6 SP2 and IE7 to restrict javascript behavior to avoid the wide array of exploits that had become prevalent (and that seriously, perhaps permanently, damaged Microsoft's security credibility). That work is largely done, so they've begun to focus more on the feature set again. And javascript has been so severely restricted at this point that few further changes are required.

Whatever the reason, it looks like the upcoming release of IE8 will be uneventful for AdvancedMD and our users...unless they introduce something in the final release.

Thursday, May 8, 2008

An IE security improvement that doesn't make our lives more difficult?

One of the key advantages of AdvancedMD over other (generally client/server) practice management systems is the fact that it is a browser-based application, built on the ubiquitous Microsoft Internet Explorer. That means that anyone can pick up a commodity PC at Best Buy or Costco, take it home, and run AdvancedMD without inserting a CD or contacting their PC support people.

AdvancedMD does, however, use a few ActiveX controls that allow us to do things that aren't normally permitted by the browser. Things like transparently saving temporary files to the local disk, compressing data, and managing printers.

When we first released AdvancedMD (as PerfectPractice.MD) back in 2000, Internet Explorer was on Version 5.0. Back in those days, the Internet was still relatively new, and Microsoft hadn't yet become every hacker's favorite target. So, security was a topic of discussion, but not the huge focus that it became in the months leading up to the release of Windows XP in August of 2001. (I'm relying on a Wikipedia article for these dates.)

In those good ol' days, ActiveX controls just worked. Sure, it helped to sign them (or, rather, the CAB files that contained them), but aside from that it was a piece of cake to deploy a control that could access the registry, read and write files, format the hard drive, beat the dog, stampede the horses, etc. The Wild, Wild West of the World Wide Web.

Since that time, the wizards at Microsoft have had a little fun at our expense (albeit, to be fair, to the benefit of IE users):

  • AdvancedMD domain must be added to Trusted Sites zone in order for ActiveX controls and many other functions to work.
  • The ActiveX controls within CAB files must be signed, not just the CAB files themselves.
  • By default, windows can't be sized or positioned in such a way that they appear off-screen, even in Trusted Sites zone.
  • A website can't be added to the Trusted Sites zone via javascript (IE6) or ActiveX controls (IE7).
  • On and on and on...

As a general rule, the AdvancedMD Engineering team emits a collective groan whenever a new version of IE comes out, because it means days of testing and retrofitting to comply with new security features.

IE8 will no doubt present some new challenges, but at least one new feature mentioned on the IEBlog may actually help us out.

For quite some time, some of our larger customers (the ones who actually have IT staff) have complained that, every year or so, we deploy new versions of our ActiveX controls. Since they have restricted their users' Windows accounts from installing software, their users are unable to install the new controls. Instead, an IT person has to walk from machine to machine, logging in as an administrative user and allowing the AdvancedMD browser application to install the controls.

IE8 has a new feature called "Per-User (Non-Admin) ActiveX" that, presumably, will make this a thing of the past. According to the IEBlog post:

"Running IE8 in Windows Vista, a standard user may install ActiveX controls in their own user profile without requiring administrative privileges."

Sounds pretty good to me. Now if we could just get away from ActiveX controls altogether...