Knowledge Vault


Follow us





Security guru says Google well ahead of Microsoft and Mozilla

Chrome 'shows the way' for browser security

Google Chrome's ability to isolate untrusted data from the rest of the operating system, should be followed by all browser manufacturers, according to a noted security researcher.

Dino Dai Zovi, a security researcher and co-author of The Mac Hacker's Handbook, believes that the future of security relies on "sandboxing," the practice of separating application processes from other applications, the operating system and user data.

In an entry on Kaspersky Labs' ThreatPost blog, Dai Zovi described sandboxing, as well as the lesser security technique of "privilege reduction," as "[moving] the bull (untrusted data) from the china shop (your data) to the outside where it belongs (a sandbox)."

The idea behind sandboxing is to make it harder for attackers to get their malicious software onto machines. Even if an attacker was able to exploit a browser vulnerability and execute malware, he would still have to exploit another vulnerability in the sandbox technology to break into the operating system and, thus, get to the user's data.

"Sandboxing raises the bar significantly enough that attackers will have to turn to other [types of attacks], like rogue anti-virus software," said Dai Zovi.

The pervasiveness of web-based attacks calls for browser sandboxing, Dai Zovi argued. "It's crucially important because, in my opinion, the browser will become the OS," he said. " Google is the first to realise that the browser is the operating system, and Chrome is a huge leap forward with its ground-up rewrite."

Chrome has included sandboxing since its September 2008 debut. And while Dai Zovi considers it easily the leader in security because of that, other browser have, or will, make their own stabs at reducing users' risks.

For example, Microsoft 's Internet Explorer 7 (IE7) and IE8 on Vista and Windows 7 include a feature dubbed "Protected Mode," which reduces the privileges of the application so that it's difficult for attackers to write, alter or destroy data on the machine, or to install malware. But it's not a true sandbox as far as Dai Zovi is concerned.

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Currently, Mozilla's Firefox, Apple 's Safari and Opera Software's Opera lack any sandboxing or privilege reduction features. "Apple, for example, has implemented some sandboxing in Snow Leopard , but [although] security researchers were hoping to see some of that technology used in Safari, that hasn't happened," Dai Zovi said.

Mozilla is working on Chrome-like sandboxing for Firefox - the project's dubbed "Electrolysis" - but the feature probably won't make it into the browser until Firefox 4.0, which is now slated to ship in late 2010 or early 2011.

Dai Zovi sees browser sandboxing as an answer to the flood of exploits that have overwhelmed users in the past year. "This isn't perfect, but it's the direction we should be heading in," he said. "The idea of fixing every vulnerability is clearly not working. We can't always win the race to patch."

But sandboxing, or at the least, reducing the browser's ability to affect the rest of the OS, may be the way to block most attacks. "It adds more defense-in-depth and impedes attackers," Dai Zovi said.



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

The financial economics of cloud email

This white paper evaluates cloud computing as a flexible alternative to your current IT capability that delivers tangible benefits including: projects delivered earlier, faster adoption to change, lower risk, reduced costs and easier to scale up or down services.

Beyond Dropbox: Requirements for Enterprise Secure File Sharing

This whitepaper explores the danger “Dropbox” type services pose for enterprises, and the security and compliance requirements for deploying enterprise-wide file sharing solutions.

Top 10 considerations for your IT operations management in the cloud

This paper explores ten questions every IT organization should answer to help determine their cloud based ITOM needs.

How to get your business ready for the 2012 Olympics

IT Manager: "I'm working on contingency plans to ensure that we can keep the business running whatever happens during the Olympics. Hopefully, it'll just be a case of letting people work from home but we need to be ready for anything".


CIO UK - Business - Technology - Leadership

Voice Applications in the Cloud

Watch this webcast to learn about new network and telecoms options.

Register now

Download the CIO BlackBerry App -
Access CIO's Content on the Move


The CIO UK BlackBerry App provides daily business and technology news, opinion and indepth features direct to your BlackBerry device.

Find out more

CIO Transformation Summit

CIO Roundtable:
The Private Cloud

Wed 29 Feb 2012
Tower 42, London, 7pm.

Join a select group of your fellow CIO's to discuss private cloud computing and how best to apply the private cloud to your organisation

Register here to book your place.



Knowledge Vault


* *