Lots of angst floating around because of the latest, buggy patches, but the bottom line is clear: Don’t use Internet Explorer Make some other browser
[See the full post at: Bears repeating: Don’t use Internet Explorer, and make some other browser your default]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Bears repeating: Don’t use Internet Explorer, and make some other browser your default
Home » Forums » Newsletter and Homepage topics » Bears repeating: Don’t use Internet Explorer, and make some other browser your default
- This topic has 43 replies, 20 voices, and was last updated 5 years, 7 months ago by
anonymous.
AuthorTopicwoody
ManagerOctober 5, 2019 at 11:49 am #1975171Viewing 19 reply threadsAuthorReplies-
anonymous
Guest -
Microfix
AskWoody MVP -
Geo
AskWoody Plus -
Microfix
AskWoody MVPOctober 5, 2019 at 2:55 pm #1975281The ms catalog using my browser. Easier patching for me YMMV, as I have three Win8.1 devices and only have to download once, then transfer/copy to other devices and install
However, on Win 7 x64/86 I use WU and don’t have IE or Explorer blocked via firewall rule sets.
Windows - commercial by definition and now function... -
woody
Manager
-
-
anonymous
Guest -
Microfix
AskWoody MVPOctober 6, 2019 at 2:00 am #1975563You’re not entirely off the hook by not using IE.
Absolutely, there are multiple hooks involved that are integral to the OS via IE, dll’s, executables in the Windows and Windows/ system32 folder all interconnected.
Windows - commercial by definition and now function... -
anonymous
GuestOctober 6, 2019 at 8:56 am #1975669anonymous #1975349 said:
Some applications use IE under the hood.
That’s right. For instance, the workaround recommended for mitigating the latest zero-day IE vulnerability — ie. removing SYSTEM user’s permissions from IE’s 32/64-bit jscript.dll — will break the respective 32/64-bit Windows Media Player in Win 7.
Clicking on any video/audio file will lead to the “Server execution failed” error, while clicking wmplayer.exe will result in no response.
Since I use portable 3rd-party media players, I’m fine with leaving jscript.dll in its restricted crippled state.
But what about Microsoft.JScript.dll (basically the the .NET implementation of JScript) ? Is it vulnerable to the latest zero-day remote code execution vulnerability ?
Another precautionary measure I’d taken is to disable the IE browser via ‘Turn Windows Features on or off‘. After a reboot, it is no longer possible to launch IE in any way. in fact, the following items disappear from view:-
- C:\Program Files\Internet Explorer\iexplore.exe
- C:\Program Files (x86)\Internet Explorer\iexplore.exe
- IE’s shortcut links via the START menu search
I use portable 3rd-party web browsers, & to prevent registry entries, I do NOT set any browser as default. As such, with the system’s “default” IE being disabled from launching, it is impossible for any malicious hyperlink to open any web browser w/o triggering a “Windows can’t open this file” prompt.
That being said, to avoid a false sense of security …
https://en.wikipedia.org/wiki/Removal_of_Internet_Explorer#Overview
Starting with Windows 2000, it is possible to disable Internet Explorer. The user can no longer launch it, but its web browser engine remains operational for applications that use it.Here’s a non-exhaustive list of 3rd-party web browsers & non-browser applications that use IE for various purposes.
PS: In Win 7, Windows Explorer (which uses IE’s binaries) works just fine with IE “turned off” (ie. merely prevented from launching). So perhaps it’s only a matter of time before malicious actors come up with payloads that target Win Explorer & IE-dependent applications.
-
rc primak
AskWoody_MVP -
anonymous
GuestOctober 6, 2019 at 3:41 pm #1975859rc primak said:
That list is old, from the Windows 2000 era.The aforementioned Wiki entry is meant to be a historical record, so some of the listed applications are old. Meanwhile, others like SlimBrowser (initial release: Dec 2012) & UltraBrowser (initial release: Sep 2009) did not exist during the Windows 2000 era.
Moreover, many of the listed applications are still actively being developed to this day, such as Skype, Maxthon, Sleipnir, SlimBrowser, WebbIE, Steam client, & Winamp (community update build).
Skype, Steam client & the unofficial Winamp probably have significant number of users. I’m also concerned about WebbIE (latest release: 22 Dec 2018), which caters to visually-impaired users.
Some Internet Explorer-dependent applications not mentioned in the Wiki list include:-
- Tablacus Explorer (latest release: 29 Sep 2019) — tabbed file manager
- Forkle (04 Oct 2019) — web browser
- MyIE9 (06 Oct 2019) — web browser
- BriskBard (27 Aug 2019) — web browser/ email client/ feed reader/ IRC chat client/ multimedia player; installer build uses IE’s Trident & Chromium’s Blink for rendering
Meanwhile, the perfectly functional Malwarebytes v1.75.x has a legitimate iexplore.exe (digitally signed by Malwarebytes) at: C:\Program Files (x86)\Malwarebytes’ Anti-Malware\Chameleon\iexplore.exe
-
-
-
woody
ManagerOctober 6, 2019 at 10:25 am #1975688You’re not entirely off the hook by not using IE. Some applications use IE under the hood.
You’re absolutely right. At some point, you’ll have to install whatever fix Microsoft finally delivers. But for now, all roads lead through IE. If you don’t use IE, and you have a different default browser, the methods for invoking this particular vulnerability become much, much more difficult — and much less likely.
-
anonymous
GuestOctober 23, 2019 at 10:41 pm #1989979I use Firefox, but understand IE still does “stuff”. When I go to the “Internet Properties” box, the “General” tab, down at “Browsing History, click “settings”, I get “Website Data Settings” box. On the “Temporary Internet Files” tab I try to select NEVER check for newer versions of stored pages, but the “apply” button on the “Internet Properties” box is greyed out! it will not save. I reopen Internet Properties and the default “Automatic” is once again checked. Can’t make the changes stick, always goes back to default automatic. I clear cache/history, etc every time I disconnect from the internet, but would like to know I’m not wasting resources collecting and storing new pages somewhere. Any thoughts? Not a techie, but follow directions well!
OS version is Win10 1809 build 17763.805
-
Kirsty
ManagerOctober 24, 2019 at 1:44 am #1990127the “apply” button on the “Internet Properties” box is greyed out! it will not save.
I get the same thing. However, if I toggle the “Delete Browsing History on Exit” option box (on, then off immediately), the Apply works, and saves. Hopefully that works on your machine too
-
anonymous
GuestOctober 24, 2019 at 7:21 pm #1991170Thank you. The “apply” activated, but the “Never” did not save. No big deal, I guess… Not going to bother with it any more. I love this site. Saved me years of win10 upgrade prompt nightmares on my win7 machine (still primary, with ZERO MS updates since about March 2018)!!! Prior to that manual install ‘security only’ updates. Thanks again to all of the commenters and contributors!
-
-
-
-
-
georgea
AskWoody LoungerOctober 5, 2019 at 6:58 pm #1975446For those who like Chrome but not the google snooping, Chromium is a good choice. Chrome without the snoopy parts. Stable builds available here:
-
abbodi86
AskWoody_MVPOctober 5, 2019 at 7:46 pm #1975459 -
anonymous
GuestOctober 6, 2019 at 9:12 am #1975673abbodi86 wrote:
Opera had been my primary browser for ever, but eventually i had to switch to more modern oneIf you’re a long-time Opera user looking for something more modern, have you considered Jon von Tetzchner’s current browser, Vivaldi?
And thank you, abbodi86, for all of your helpful and informative posts on this site… we’re all smarter – or at least better informed
– because of you!
-
abbodi86
AskWoody_MVP
-
-
-
GoneToPlaid
AskWoody Lounger -
anonymous
GuestOctober 6, 2019 at 2:27 am #1975579The problem with making a browser you actually use the default browser is that a rogue application can call it and get internet access. IMHO, you should set as default a browser that is fully blocked at your firewall. Moreover, configure the browser to connect via a proxy to an invalid IP.
-
anonymous
GuestOctober 6, 2019 at 3:59 am #1975614Yeah, that’s exactly what I use edge for. Firewalled as a default browser and epub reader. Of course you don’t even need to dedicate a real browser to this, you may as well make a batch file or something that just echoes its argument back and lets you copy the url if you want it. Far too many programs use this to try and call back home when you install or uninstall them.
-
-
_Reassigned Account
AskWoody LoungerOctober 6, 2019 at 4:45 am #1975634 -
Ascaris
AskWoody MVPOctober 6, 2019 at 8:23 am #1975668I never used IE, even then, except for Windows updates and brief testing.
I used Netscape 2.0 or so with Windows 3.1, then when I got Windows 95 OSR2, I tried the included IE 3.0, but I didn’t like it as much as Netscape. I kept with Netscape until Microsoft had them destroyed, at which time I moved to Netscape’s offspring, Mozilla. Because of Microsoft’s behavior, I never seriously considered using IE 6 for anything other than updating Windows XP. I did try IE7 briefly, but it was seriously wanting compared to Firefox, and that was the last IE version I tried.
I never tried Chrome or any variants thereof until this year, 2019. I was so disgusted by Mozilla’s continued efforts to copy Chrome that I decided to see what was so good that Firefox had to stop being Firefox to copy. I tried Chromium, but it was so lacking in its UI that I soon cut the test short. I’m keeping an eye on Vivaldi, a Chromium based browser that is working on smoothing out the UI issues… they just got the classic menubar working properly in the most recent release, and at this rate, they may one day surpass Firefox proper (though probably never Waterfox).
Dell XPS 13/9310, i5-1135G7/16GB, KDE Neon 6.2
XPG Xenia 15, i7-9750H/32GB & GTX1660ti, Kubuntu 24.04
Acer Swift Go 14, i5-1335U/16GB, Kubuntu 24.04 (and Win 11)1 user thanked author for this post.
-
-
anonymous
GuestOctober 6, 2019 at 6:39 am #1975651? says:
so, does anyone remember this?
https://en.wikipedia.org/wiki/United_States_v._Microsoft_Corp.
just wondering…
-
anonymous
GuestOctober 6, 2019 at 7:42 am #1975661Well, not using ‘Internet Explorer’ on Windows is next to impossible. This is because most of the infrastructure the Internet Explorer Web browser is built on is part of the operating system; and most of the security flaws affect the infrastructure, not the Internet Explorer Web browser itself. In short terms, any software using the ‘Internet Explorer’ infrastructure under the hood is affected. So be sure the Web browser of your choice does not rely on the infrastructure the Internet Explorer Web browser is built on.
-
joep517
AskWoody MVPOctober 6, 2019 at 9:22 am #1975679If you want to use a Chromium-based browser check out the beta version of the new Edge at https://www.microsoftedgeinsider.com/en-us/. I run the Dev channel and it is very solid. The beta channel should be even more solid. It is updated every six weeks. The new Edge is available for all supported versions of Windows and macOS. Microsoft removed all the Google “stuff” and yes they substituted their own for most.
You can add extensions from either the Microsoft Store, the Chrome web store, or both. Some of the Chrome extensions may not work.
--Joe
-
rc primak
AskWoody_MVP -
anonymous
GuestOctober 6, 2019 at 12:23 pm #1975719joep517 wrote:
If you want to use a Chromium-based browser check out the beta version of the new EdgeInteresting suggestion, seems like “new Edge” may have broader appeal than “original Edge”, but I do find myself wondering…
does Microsoft’s new Edge browser suffer on any level from the frequently-referenced (e.g., see many posts above, including woody’s post #1975688) problem still plaguing Internet Explorer (i.e., the over-integration of the web browser application with the underlying Windows OS)? -
b
AskWoody_MVP
-
-
DrBonzo
AskWoody Plus
-
-
anonymous
GuestOctober 6, 2019 at 11:06 am #1975696So Oct 8th is when the new IE cumulative update will be available and I hope that some testers will be scrutinizing that with some more intense vetting so that can be safely installed sooner rather than later. And maybe Oct’s IE CU needs it’s own DEFCON so that vetting can be established sooner rather than later because of all that is zero day.
MS should have long ago made disabling IE a one setting option, including any default application calling for the default browser functionality just for cases like the current issues with IE security. Having any Internet Browser so integrated into the OS, at any elevated privilege level, was a serious security mistake from day one.
Windows Explorer should have its own code and not be sharing any code with any Internet Browser functionality and the OS needs less direct shared Internet Functionality inside with all that is internet based properly sandboxed outside of any OS/Elevated privilege level.
-
rc primak
AskWoody_MVPOctober 6, 2019 at 11:10 am #1975702 -
anonymous
GuestOctober 6, 2019 at 7:56 pm #1975975Firefox and I’ll wait for Oct 2019’s DEFCON3 before installing any patches. And I have completely skipped any months where any Windows 7 Security Only Patches had telemetry.
So now on to Oct’s regular patches and their vetting. September is really been bad anyways so I’m glad I skipped everything that month in addition to the telemetry in the W7 SO update. There’s not may more months to worry about patching Windows 7 that’s just finding some replacement options(8.1, Linux, or BSD based). IE gets cumulative updates anyways so what is skipped one month will be included in the next.
-
anonymous
GuestOctober 6, 2019 at 9:49 pm #1976083And I have completely skipped any months where any Windows 7 Security Only Patches had telemetry.
Telemetry was additional payload riding along with these patches, not the only reason for the update. By skipping the update you are not patched. Please read through AKB2000012. And consider accepting the patches with telemetry, then neutralizing the effects after. You may have reasons for your choice, this is only a suggestion to another option.
-
-
-
-
phaolo
AskWoody LoungerOctober 6, 2019 at 5:37 pm #1975888 -
abbodi86
AskWoody_MVP
-
-
Noel Carboni
AskWoody_MVPOctober 6, 2019 at 9:58 pm #1976089WHATEVER browser you choose to use, I recommend you consider protecting yourself against your computer visiting websites it should not be visiting.
My recommendation: Install UBlock (and for the geeky) UMatrix. Even if you choose to get no other add-ons. The former blacklists a big batch of web sites using information about their bad behavior gathered from all over, and the latter doesn’t allow the execution of scripts from sites other than the one you’re actually visiting unless you allow it (and believe me, the stuff your browser loads comes from ALL over).
Imagine browsing and only seeing the content you want. No ads, no drive by malware. Just what you want to view.
Yes, it really works.
-Noel
-
Tom
AskWoody PlusOctober 7, 2019 at 12:11 am #1976107In addition to all the IE stuff under the hood in other parts of Windows, please be aware that sometimes we in the trenches are required to use and support IE at work. [One large company, with over 25,000 employees per Forbes.com] REQUIRES IE for their web-based document management, accounting and workflow SAAS. (I’m a customer, not an employee.)
1 user thanked author for this post.
-
woody
Manager
-
-
PKCano
ManagerOctober 7, 2019 at 6:52 am #1976232I manage the Office computer for my HomeOwner’s Associaton. The check reader for deposits to the bank, and the tie in to QuickBooks, requires the use of IE11. I have them on Win10, v1809. It is up to date with the original Patch Tues CU KB4512578 Build 17763.737. It will be interesting to see if it stops working once I install the Oct. updates. Not going to rush that one!
1 user thanked author for this post.
-
johnf
AskWoody LoungerOctober 7, 2019 at 9:38 am #1976326Alternative browsers to consider (if you don’t trust ones built from Chrominum, such as Chrome, Edge, etc) are Pale Moon/ WaterFox (I’m not a big fan of the direction Firefox is going). Brave is another good one, though that is built on the Chrominum engine. If you can, follow Noel’s advice about UBlock (or NoScript).
For those of you who need to run IE, using Sandboxie is a good way to isolate IE in a safe, sandbox environment. Sophos recently made it a free tool, and will make it open source later, so no reason not to try it out!
-
This reply was modified 5 years, 7 months ago by
johnf.
1 user thanked author for this post.
-
This reply was modified 5 years, 7 months ago by
-
rowrbazzle
AskWoody LoungerOctober 7, 2019 at 10:03 am #1976353What anonymous #1975669 posted is worth repeating:
To disable the IE browser (in Win 7):
1. Go to Control Panel > Programs and Features > Turn Windows features on or off.
2. Deselect Internet Explorer 11.
3. Reboot.
I still apply the monthly IE11 security updates, and have noticed no problems since disabling the browser >2 years ago.
As always, YMMV.
-
anonymous
Guest
Viewing 19 reply threads - This topic has 43 replies, 20 voices, and was last updated 5 years, 7 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 Insider Preview build 27863 released to Canary
by
joep517
9 hours, 13 minutes ago -
Windows 11 Insider Preview build 26120.4161 (24H2) released to BETA
by
joep517
9 hours, 14 minutes ago -
AI model turns to blackmail when engineers try to take it offline
by
Cybertooth
1 hour, 58 minutes ago -
Migrate off MS365 to Apple Products
by
dmt_3904
5 hours, 23 minutes ago -
Login screen icon
by
CWBillow
38 minutes ago -
AI coming to everything
by
Susan Bradley
9 hours, 23 minutes ago -
Mozilla : Pocket shuts down July 8, 2025, Fakespot shuts down on July 1, 2025
by
Alex5723
1 day ago -
No Screen TurnOff???
by
CWBillow
1 day, 1 hour ago -
Identify a dynamic range to then be used in another formula
by
BigDaddy07
1 day, 1 hour ago -
InfoStealer Malware Data Breach Exposed 184 Million Logins and Passwords
by
Alex5723
1 day, 13 hours ago -
How well does your browser block trackers?
by
n0ads
23 hours, 41 minutes ago -
You can’t handle me
by
Susan Bradley
11 hours, 14 minutes ago -
Chrome Can Now Change Your Weak Passwords for You
by
Alex5723
16 hours, 18 minutes ago -
Microsoft: Over 394,000 Windows PCs infected by Lumma malware, affects Chrome..
by
Alex5723
2 days ago -
Signal vs Microsoft’s Recall ; By Default, Signal Doesn’t Recall
by
Alex5723
1 day, 4 hours ago -
Internet Archive : This is where all of The Internet is stored
by
Alex5723
2 days, 1 hour ago -
iPhone 7 Plus and the iPhone 8 on Vantage list
by
Alex5723
2 days, 1 hour ago -
Lumma malware takedown
by
EyesOnWindows
1 day, 13 hours ago -
“kill switches” found in Chinese made power inverters
by
Alex5723
2 days, 10 hours ago -
Windows 11 – InControl vs pausing Windows updates
by
Kathy Stevens
2 days, 9 hours ago -
Meet Gemini in Chrome
by
Alex5723
2 days, 14 hours ago -
DuckDuckGo’s Duck.ai added GPT-4o mini
by
Alex5723
2 days, 14 hours ago -
Trump signs Take It Down Act
by
Alex5723
2 days, 22 hours ago -
Do you have a maintenance window?
by
Susan Bradley
1 day, 2 hours ago -
Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms
by
Nibbled To Death By Ducks
2 days ago -
Cox Communications and Charter Communications to merge
by
not so anon
3 days, 1 hour ago -
Help with WD usb driver on Windows 11
by
Tex265
12 hours, 39 minutes ago -
hibernate activation
by
e_belmont
3 days, 10 hours ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
3 days, 14 hours ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
3 days, 17 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.