Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

7/8/2009
03:53 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Google Discloses Plans For New Malware-Resistant OS

Chrome OS aimed at eradicating malware issues for desktops with lightweight platform and cloud-based application model

Google is building its own operating system aimed at eliminating malware problems at the consumer's desktop.

The company late yesterday announced its work on the new Google Chrome OS, a lightweight OS that sits atop a Linux kernel and will run on X86 and ARM chips.

"We are going back to the basics and completely redesigning the underlying security architecture of the OS so that users don't have to deal with viruses, malware," blogged Google's Sundar Pichai, vice president for product management, and Linus Upson, engineering director. "Most of the user experience takes place on the Web."

Chrome OS code will be available as open source later this year, and Google says it plans to make it available on netbooks by the second half of 2010.

Google wouldn't provide specifics on the OS or its security features beyond the blog post, but security experts say while this Web application-focused OS should eliminate the usual desktop threats, it still will be subject to Web-borne threats. Web application vulnerabilities today are some of the most prevalent, with cross-site scripting (XSS) and SQL injection attacks increasing on Websites.

"[Google Chrome OS] should be immune to most existing PC viruses, but will face Web-based risks and attacks much like any other browser model would," says Rob Enderle, principal analyst with the Enderle Group. "User authentication is probably [the] biggest problem -- even more than a PC -- as this will become a natural key to a lot of large databases and services."

Enderle says the Chrome OS will likely also focus on phishing and Web-borne attacks versus traditional desktop viruses. "It effectively changes the security model for the desktop into something much more similar to a thin client/cell phone model," he says.

Rich Mogull, founder of Securosis, says smart handsets already have paved the way to this type of user model. But the Chrome OS model doesn't necessarily mean safer computing for consumers. "It just shifts the risk," he says. "It's just going to be a shift in attacks [to Web applications]...and we've already seen of lot of that [occurring]. If anything, [Chrome OS is] going to highlight Web application security issues."

Paul Henry, security and forensics expert for Lumension, says Google thus far hasn't provided enough information on the security elements of Google Chrome OS. "There have been claims that it is virus-free or virus-proof -- however, there really is no specific security capability mentioned on the product beyond, perhaps, the reduced threat envelope you would get in using any application-specific OS," he says.

Meanwhile, Google said in its announcement that the Web is the platform for application developers writing for Chrome OS. "All Web-based applications will automatically work and new applications can be written using your favorite web technologies. And of course, these apps will run not only on Google Chrome OS, but on any standards-based browser on Windows, Mac and Linux thereby giving developers the largest user base of any platform," the blog said.

Enderle says Chrome OS is basically a scaled-up Android based on the Linux kernel. "An app store model will limit most of what runs, and an increasing amount of content will be online and not run locally at all," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/5/2020
Abandoned Apps May Pose Security Risk to Mobile Devices
Robert Lemos, Contributing Writer,  5/29/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9074
PUBLISHED: 2020-06-05
Huawei Smartphones HONOR 20 PRO;Honor View 20;HONOR 20 have an improper handling of exceptional condition Vulnerability. A component cannot deal with an exception correctly. Attackers can exploit this vulnerability by sending malformed message. This could compromise normal service of affected phones...
CVE-2020-9859
PUBLISHED: 2020-06-05
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
CVE-2020-11975
PUBLISHED: 2020-06-05
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
CVE-2020-12723
PUBLISHED: 2020-06-05
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
CVE-2020-1883
PUBLISHED: 2020-06-05
Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal.