Go Back   This Blue Marble, a Global Current Events Discussion Forum > Main Floor > Technology

Technology Humans are tool-users, and technology is where our science becomes reality, giving us the powerful electronic and mechanical tools that mostly make our lives easier, yet more complex, and at times frustrating.

Reply
 
Thread Tools Search this Thread Display Modes
Old 03-20-2009, 03:38 PM   #1
Potemkin
Omne ignotum pro magnifico
 
Potemkin's Avatar
 
Join Date: Aug 2008
Posts: 20,988
Blog Entries: 3
Thanks: 46
Thanked 785 Times in 546 Posts
Default Google Chrome most secure?

http://arstechnica.com/security/news...wn-contest.ars

Chrome only browser left standing after day one of Pwn2Own

During a contest at the CanSecWest event, security researchers competed to exploit vulnerabilities in web browsers. Firefox, Safari, and Internet Explorer were all successfully compromised, but Chrome was able to withstand the first day of the competition.
By Ryan Paul | Last updated March 20, 2009 9:27 AM CT


Chrome only browser left standing after day one of Pwn2Own

Browser vendors often make strong claims about their responsiveness to vulnerability reports and their ability to preemptively prevent exploits. Security is becoming one of the most significant fronts in the new round of browser wars, but it's also arguably one of the hardest aspects of software to measure or quantify.

A recent contest at CanSecWest, an event that brings together some of the most skilled experts in the security community, has demonstrated that the three most popular browser are susceptible to security bugs despite the vigilance and engineering prowess of their creators. Firefox, Safari, and Internet Explorer were all exploited during the Pwn2Own competition that took place at the conference. Google's Chrome browser, however, was the only one left standing—a victory that security researchers attribute to its innovative sandbox feature.

The contest awards security researchers with hardware and cash prizes for finding efficient ways to trick browsers into executing arbitrary code. During the first day of the competition, the contestants are required to do this in default browser installations without plugins such as Flash or Java, which are commonly used as vectors for attacks. Researchers typically prepare for the event far in advance by finding zero-day exploits ahead of time.

Early this month, prior champion Charlie Miller told reporters that he would be attempting to exploit a Safari vulnerability on Mac OS X. Safari, he said, would be the first to succumb to the contestants. As he promised, Safari went down first: he was able to execute his prepared hack in only a matter of seconds. Another security expert known only as Nils took longer, but was able to successfully exploit all three of the most popular browsers.

These contests contribute to the growing culture of commercialism that surrounds the art of exploitation. In an interview with ZDNet, Miller said that the vulnerability he used in the contest was one that he had originally found while preparing for the contest last year. Instead of disclosing it at that time, he decided to save it for the contest this year, because the contest only pays for one bug per year. This is part of his new philosophy, he says, which is that bugs shouldn't be disclosed to vendors for free.

"I never give up free bugs. I have a new campaign. It's called NO MORE FREE BUGS. Vulnerabilities have a market value so it makes no sense to work hard to find a bug, write an exploit and then give it away," Miller told ZDNet. "Apple pays people to do the same job so we know there's value to this work."

Miller also told reporters that he targeted Safari on Mac OS X because he believes that it is the easiest to exploit. Windows, on the other hand, he claims is tougher because of its address randomization feature and other security measures. As for Chrome, he says that he has identified a security bug in Google's browser but has been unable to exploit it because the browser's sandboxing feature and the operating system's security measures together pose a formidable challenge.

The game isn't over yet. During the second day of the event, the focus will turn towards Chrome. Nils, who demonstrated impressive skill during the first day by conquering the three most popular browsers, might have a few more tricks up his sleeve. According to the official rules, the participants will be permitted to use plugins during the second day.
__________________
Those who would give up essential liberty, to purchase a little temporary safety, deserve neither liberty or safety. Benjamin Franklin

Socialism is the philosophy of failure, the creed ignorance, and the gospel of envy; its inherent virtue is the equal sharing of misery.
Winston Churchill
Potemkin is offline   Reply With Quote
Old 03-20-2009, 04:00 PM   #2
Ought Six
Dismember
 
Ought Six's Avatar
 
Join Date: Oct 2008
Posts: 35,164
Blog Entries: 15
Thanks: 172
Thanked 389 Times in 325 Posts
Arrow

With Google's propensity to collect and compile user info without the user's prior knowlege or permission, I will pass on Chrome.
__________________
* I have the right to live, thus I have the right to defend my life from attackers who would take it from me.
* I have the right to my private property, thus I have the right to defend my property from thieves who would take it from me.
* I have the right to self-determination, thus I have the right to defend my liberty from tyrants who would take it from me.
* The only usable tools for these tasks are guns, and thus I have the right to shoot anyone who would take my guns from me.
Ought Six is offline   Reply With Quote
Old 03-20-2009, 04:39 PM   #3
BirdGuano
H1N1 Crash Dummy
 
BirdGuano's Avatar
 
Join Date: Aug 2008
Location: The I.O.U. State
Posts: 8,961
Thanks: 0
Thanked 0 Times in 0 Posts
Quote:
Originally Posted by Ought Six View Post
With Google's propensity to collect and compile user info without the user's prior knowlege or permission, I will pass on Chrome.
Not to mention their very cozy relationship with the
United States and Chinese governments.
__________________
--

Quote:
"It is better to have lived one day as a tiger than a thousand years as a sheep." -- Tibetan proverb
News and commentary updates on Twitter @guanosphere
BirdGuano is offline   Reply With Quote
Reply

Tags
chrome, google, secure

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 02:46 PM.


Powered by vBulletin®
Copyright © Jelsoft Enterprises Ltd.