ActiveX

Microsoft ActiveX technology allows software to be distributed over the internet. You'll encounter ActiveX in the form of ActiveX controls and graphic items such as scrolling marquees, on Web sites.  Think of them as small programs (plug-ins) within the site that run on your computer.  Currently they only work in Internet Explorer.

An ActiveX plug-in can be digitally 'signed' by its author in such a way that the signature cannot be altered or repudiated using a system called 'Authenicode'. The digital signature is then certified by a trusted "certifying authority", such as Thawte, to create the equivalent of a shrink-wrapped software package. When a digital certificate is granted, the software developer pledges that the software is free of viruses and other malicious components.

Security settings in Internet Explorer

With Internet Explorer 5.0 or above you can automatically select the security level you fell comfortable with

  1. On the Tools menu, click Internet Options and then click the Security tab.
  2. In the Web Contents Zone, select Internet.
  3. Select a security level and then click OK. (Medium is the recommended level)

To be prompted before any ActiveX control is dowloaded and executed, in the Internet Contents Zone, select Medium.

To set individual aspects of ActiveX control security yourself

  1. On the Tools menu, click Internet Options and click the Security tab.
  2. In the Web Contents Zone, select Internet.
  3. In the Internet Zone area, select Custom and click Settings.
  4. Under ActiveX Controls and plug-ins, select the settings you want, click OK, and click OK again.

Certificates

Digital certificates, granted by certifying authorities such as Thawte, signify that a Web site or elements of a website have been digitally signed by its creator. A certificate lets you know who is responsible for the site or element, and verifies that it is free from malicious components such as viruses and has not been tampered with since it was certified.

When your browser is presented with a certificate, it checks its list of certifying authorities. If it finds a match, it allows your activity to continue.