MRDA, naturally.
As long as the default policy for ActiveX controls is for them to be run automatically (trusted/signed or not) then he can't really be serious about security.
I note with despair that someone has released an ActiveX plug-in for Mozilla/Firefox (Windows only of course).
--
simon
|