Chrome Shines Bright In Controversial Security Fight
Major browsers have all made solid strides in security in the past few years, but Chrome's sandbox makes Google's browser a harder target, researchers say at RSA.
RSA CONFERENCE 2012--San Francisco--The major browsers have all made solid strides in security in the past few years, but Chrome's sandbox makes Google's browser a harder target for attackers to exploit with malicious code, four researchers said Thursday in a presentation at the RSA Security Conference in San Francisco.
The group of researchers--all current or former employees of security consultancy Accuvant--gave conference attendees an in-depth tour of their results, which were published late last year. Some controversy has surrounded the security comparison because Google--the maker of the Chrome browser--funded the study.
Microsoft Internet Explorer's and Google Chrome's countermeasures made both browsers more secure on the metrics used by Accuvant, with Google's browser edging out Microsoft's in sandboxing technology, Shawn Moyer, practice manager for Accuvant, said.
"We focused heavily on exploitation mitigation in this paper," Moyer said. "We accepted that users will click on things and the browser will be exploited, but if you have something that you can use to contain the hack, you are going to raise the bar for attackers."
The survey has been criticized by NSS Labs, a security testing firm that came to a different conclusion in a paper last year: Microsoft's SmartScreen URL reputation system helped Internet Explorer catch 96% of all malicious websites. Google's Chrome came in a distant second place, catching about 13% of websites.
At the RSA Conference, the researchers repeatedly stressed that their paper and methods are open. Anyone can review and redo the testing, Moyer argued. Moreover, they also pointed out that they could not replicate NSS Labs' findings. They found all three browsers were equally poor at catching malicious pages.
Chrome distanced itself from other browsers mainly because of its sandbox technology--a virtual playpen in which the browser runs but cannot impact other applications' data or the operating system. Internet Explorer has some sandboxing, but not as completely as Chrome, the researchers said. A strong sandbox helps keep the operating systems secure because a malicious program that runs inside the sandbox cannot access any system resources outside of the virtual machine.
It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)
Published: 2014-07-30 Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 184.108.40.206, Maximo Asset Management 7.5 through 220.127.116.11 and 7.5.1 through 18.104.22.168 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management f...
Published: 2014-07-30 Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 22.214.171.124, and 7.5 through 126.96.36.199; Maximo Asset Management 7.5 through 188.8.131.52 and 7.5.1 through 184.108.40.206 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8...
Published: 2014-07-30 Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.
Published: 2014-07-30 Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive.
Published: 2014-07-30 Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.