ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Google shares Chrome browser security principles

By | January 13, 2012, 9:39am PST

Summary: Google provides a useful document that helps users understand what’s under the Chrome browser’s hood, especially as it relates to keeping hackers at bay.

Earlier this week, I declared Google Chrome the most secure browser available today based on its sandbox, auto-update mechanism and the speed with which the Google Security Team patches vulnerabilities.

I received a lot of e-mail feedback questioning that claim so today I’m happy to see Google sharing its Chrome security principles, a very useful document that helps users understand what’s under the browser’s hood, especially as it relates to keeping hackers at bay.

[ SEE: 10 things to secure your online presence ]

Some key highlights:

  • follow Ryan Naraine on twitterDefense in depth: Our goal in designing Chrome’s security architecture was to layer defenses, and avoid single points of failure. Chrome’s sandbox architecture represents one of the most effective parts of this strategy, but it’s far from the only piece. We also employ the best available anti-exploit technologies—including ASLR, DEP, JIT hardening, and SafeSEH—along with custom technologies like Safe Browsing, out-of-date plugin blocking, silent auto-update, and verified boot on Chrome OS. And we continue to work towards advancing the state of the art with research into areas like per-origin sandboxing and control flow integrity.
  • Transparency: We do not downplay security impact or bury vulnerabilities with silent fixes, because doing so serves users poorly. Instead, we provide users and administrators with the information they need to accurately assess risk. We publicly document our security handling process, and we disclose all vulnerabilities fixed in Chrome and its dependencies—whether discovered internally or externally. Whenever possible, we list all fixed security issues in our release notes, and make the underlying details public as soon as other affected projects have an adequate amount of time to respond. When we do not control the disclosure timeline for a security issue and cannot list it at the time of release, we make the details of the issue public as soon as disclosure occurs.
  • Community engagement: No software is perfect, and security bugs slip through even the best development and review processes. That’s why we’re grateful for the work of the independent security research community in helping us find and fix vulnerabilities. In response, we do our best to acknowledge and reward their contributions by ensuring proper attribution, paying out bounties, and sponsoring security conferences. We leverage the community to even greater extent where we can, by hiring members directly onto our team and contracting with industry leading, independent security consultancies.
Computer users should always seek to reduce attack surface for attackers and indepth knowledge of under-the-hood security features can help with these decisions.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

14
Comments

Join the conversation!

Just In

sdsfdd
jywhy888 7th Mar
Stuffed Animals Audio Video Equipment http://www.chinawholesaletown.com/wholesale-Pure-Cotton-Compressed/ Kitchenware
Wholesale Clocks Wholesale T-Shirts http://www.chinawholesaletown.com/wholesale-Carabiner/ Calendar
Inflatable Products Wholesale Keychain http://www.chinawholesaletown.com/wholesale-Scarf/ iPod iPhone
Wholesale Gift Bags Voice Recorder http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Promotional Products
Wholesale Belt Wholesale Pen http://www.chinawholesaletown.com/wholesale-Lunch-Box/ Health Care Products
Solar Products Lady Beauty Care http://www.chinawholesaletown.com/wholesale-Mouse-Pad/ Mat
Wholesale Kitchenware Wholesale Tag http://www.chinawholesaletown.com/wholesale-First-Aid-Kit/ Cards
Computer Accessories Wholesale Ashtray http://www.chinawholesaletown.com/wholesale-Muslim-Products/ Silicone Products
Wholesale Cap Wholesale Frisbee http://www.chinawholesaletown.com/wholesale-Glass/ USB Products
Wholesale Watch Wholesale Poncho http://www.chinawholesaletown.com/wholesale-Lighter/ Cup
Wholesale Ruler Valentine Gifts http://www.chinawholesaletown.com/wholesale-Hair-Products/ Crystal Gifts
Safety Products Patient Care Products http://www.chinawholesaletown.com/wholesale-Money-Bank/ Sport Support Products
Gift Box Beauty Equipment http://www.chinawholesaletown.com/wholesale-Belt/ Tie
Safety Suppliers Wholesale Shoe http://www.chinawholesaletown.com/wholesale-Stress-Ball/ Magnifier
Pen Holder Wholesale Clothes Rack http://www.chinawholesaletown.com/wholesale-iPod---iPhone/ Flag
Wholesale Thermometer Poncho Raincoat http://www.chinawholesaletown.com/wholesale-Coaster/ Vocal Concert Products
Promotional Items Wholesale Swimming Products http://www.chinawholesaletown.com/wholesale-Clap-Hands/ Flash Gift
Mouse Pad Wholesale Thermometer http://www.chinawholesaletown.com/wholesale-World-Cup-Horn-Vuvuzela/ Home Appliances
Wholesale Cup Wholesale First Aid Kit http://www.chinawholesaletown.com/wholesale-Safety/ Bottle Opener
Voice Recorder Wholesale Kitchenware http://www.chinawholesaletown.com/wholesale-Mat/ Cleaner Products
Consumer Electronics Cleaner Products http://www.chinawholesaletown.com/wholesale-Sport-Support/ Bag
Wholesale Glove Recorder Pen http://www.chinawholesaletown.com/wholesale-Pedometer/ CD Holde
Wedding Favors Wholesale iPod iPhone http://www.chinawholesaletown.com/wholesale-Earphone/ T-Shirts
Wholesale Mug Wholesale Mat http://www.chinawholesaletown.com/wholesale-Shoes/ Toys
Wholesale Binoculars Wholesale Mirror http://www.chinawholesaletown.com/wholesale-Vase/ Promotional Gifts
Wholesale Calculator Wholesale Album http://www.chinawholesaletown.com/wholesale-Vocal-Concert-Products/ Shoe
Coin Bank Photo Frame http://www.chinawholesaletown.com/wholesale-Garden-Decorations/ Gift Box
Photo Frame Pet Supplies http://www.chinawholesaletown.com/wholesale-Hardware-Tools/ Compass
Wholesale Magnifier Gift Box http://www.chinawholesaletown.com/wholesale-Tape-Measure/ Golf Products
Wholesale Scissors Arts Crafts http://www.chinawholesaletown.com/wholesale-Reflective-Safety-Vest/ Safety Suppliers
Wholesale Pom Poms Lighting Products http://www.chinawholesaletown.com/wholesale-Magnifier/ Mp3
Industrial Supplies Wholesale Cap http://www.chinawholesaletown.com/wholesale-Voice-Recorder/ Business Gift
Wholesale Bookmark Safety Products http://www.chinawholesaletown.com/wholesale-Mirror/ Pen
Wholesale Tableware Vocal Concert Products http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Lighting Products
Wholesale Clothes Rack Wholesale Carabiner http://www.chinawholesaletown.com/wholesale-TelePhone/ Industrial Supplies
Sport Support Products Wholesale Towel http://www.chinawholesaletown.com/wholesale-Gift-Bags/ Stress Ball
Men Beauty Care Safety Suppliers http://www.chinawholesaletown.com/wholesale-Men-Beauty-Care/ Safety Products
0 Votes
+ -
But its spyware....
techsdfdsblogger 13th Jan
How can spyware be considered secure?
@techblogger
Use Chromium then. Start by examining its fully open source code to rule out that there's spyware. Do you use firefox, ok then do the same there. Next, look through windows source code and prove to yourself that windows isn't spying on you. Do you use IE? Look through its source code. Oh wait, can't do either. Ok, *now* I agree with you. MS spyware is not secure.
@willyampz
You are quite right. I principally use Firefox because of the many add-ons, but also use Chromium which is FOSS.

But, techblogger is also right. All Google apps and services are designed to be secure from others so only Google can spy on you. But, can you blame Google. That is their business model. No spying, no revenue.
@jorjitop
Google can spy on you

You have supporting links to what you claim?
0 Votes
+ -
RE: Google can spy on you
Rabid Howler Monkey 14th Jan
@daikon Due to past privacy violations, Google has submitted to 20 years of monitoring by the U.S. FTC:

"Google to be monitored by Feds for privacy for 20 years
http://www.electronista.com/articles/11/10/25/ftc.case.prompted.by.google.buzz.fiasco/

If you trust the U.S. FDA to look out for your interests (as opposed to corporate interests) with food and drugs, then you will similarly trust the FTC to watch over Google's privacy practices. And if you don't, well ...
0 Votes
+ -
sdsfdd
jywhy888 7th Mar
Stuffed Animals Audio Video Equipment http://www.chinawholesaletown.com/wholesale-Pure-Cotton-Compressed/ Kitchenware
Wholesale Clocks Wholesale T-Shirts http://www.chinawholesaletown.com/wholesale-Carabiner/ Calendar
Inflatable Products Wholesale Keychain http://www.chinawholesaletown.com/wholesale-Scarf/ iPod iPhone
Wholesale Gift Bags Voice Recorder http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Promotional Products
Wholesale Belt Wholesale Pen http://www.chinawholesaletown.com/wholesale-Lunch-Box/ Health Care Products
Solar Products Lady Beauty Care http://www.chinawholesaletown.com/wholesale-Mouse-Pad/ Mat
Wholesale Kitchenware Wholesale Tag http://www.chinawholesaletown.com/wholesale-First-Aid-Kit/ Cards
Computer Accessories Wholesale Ashtray http://www.chinawholesaletown.com/wholesale-Muslim-Products/ Silicone Products
Wholesale Cap Wholesale Frisbee http://www.chinawholesaletown.com/wholesale-Glass/ USB Products
Wholesale Watch Wholesale Poncho http://www.chinawholesaletown.com/wholesale-Lighter/ Cup
Wholesale Ruler Valentine Gifts http://www.chinawholesaletown.com/wholesale-Hair-Products/ Crystal Gifts
Safety Products Patient Care Products http://www.chinawholesaletown.com/wholesale-Money-Bank/ Sport Support Products
Gift Box Beauty Equipment http://www.chinawholesaletown.com/wholesale-Belt/ Tie
Safety Suppliers Wholesale Shoe http://www.chinawholesaletown.com/wholesale-Stress-Ball/ Magnifier
Pen Holder Wholesale Clothes Rack http://www.chinawholesaletown.com/wholesale-iPod---iPhone/ Flag
Wholesale Thermometer Poncho Raincoat http://www.chinawholesaletown.com/wholesale-Coaster/ Vocal Concert Products
Promotional Items Wholesale Swimming Products http://www.chinawholesaletown.com/wholesale-Clap-Hands/ Flash Gift
Mouse Pad Wholesale Thermometer http://www.chinawholesaletown.com/wholesale-World-Cup-Horn-Vuvuzela/ Home Appliances
Wholesale Cup Wholesale First Aid Kit http://www.chinawholesaletown.com/wholesale-Safety/ Bottle Opener
Voice Recorder Wholesale Kitchenware http://www.chinawholesaletown.com/wholesale-Mat/ Cleaner Products
Consumer Electronics Cleaner Products http://www.chinawholesaletown.com/wholesale-Sport-Support/ Bag
Wholesale Glove Recorder Pen http://www.chinawholesaletown.com/wholesale-Pedometer/ CD Holde
Wedding Favors Wholesale iPod iPhone http://www.chinawholesaletown.com/wholesale-Earphone/ T-Shirts
Wholesale Mug Wholesale Mat http://www.chinawholesaletown.com/wholesale-Shoes/ Toys
Wholesale Binoculars Wholesale Mirror http://www.chinawholesaletown.com/wholesale-Vase/ Promotional Gifts
Wholesale Calculator Wholesale Album http://www.chinawholesaletown.com/wholesale-Vocal-Concert-Products/ Shoe
Coin Bank Photo Frame http://www.chinawholesaletown.com/wholesale-Garden-Decorations/ Gift Box
Photo Frame Pet Supplies http://www.chinawholesaletown.com/wholesale-Hardware-Tools/ Compass
Wholesale Magnifier Gift Box http://www.chinawholesaletown.com/wholesale-Tape-Measure/ Golf Products
Wholesale Scissors Arts Crafts http://www.chinawholesaletown.com/wholesale-Reflective-Safety-Vest/ Safety Suppliers
Wholesale Pom Poms Lighting Products http://www.chinawholesaletown.com/wholesale-Magnifier/ Mp3
Industrial Supplies Wholesale Cap http://www.chinawholesaletown.com/wholesale-Voice-Recorder/ Business Gift
Wholesale Bookmark Safety Products http://www.chinawholesaletown.com/wholesale-Mirror/ Pen
Wholesale Tableware Vocal Concert Products http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Lighting Products
Wholesale Clothes Rack Wholesale Carabiner http://www.chinawholesaletown.com/wholesale-TelePhone/ Industrial Supplies
Sport Support Products Wholesale Towel http://www.chinawholesaletown.com/wholesale-Gift-Bags/ Stress Ball
Men Beauty Care Safety Suppliers http://www.chinawholesaletown.com/wholesale-Men-Beauty-Care/ Safety Products
0 Votes
+ -
Oh that's irony, Google sharing security.
0 Votes
+ -
We know where you are. We know where you've been. We can more or less know what you're thinking about ... Google policy is to get right up to the creepy line and not cross it."

~ Google CEO Eric Schmidt, October 1, 2010 [interview]

*Obligatory Google disclaimer: Don't be evil*
But doesn't IE always surpass it in the detection of malicious downloads, with it's smart screen filter technology? Just that alone is a big downfall for Chrome because most of the malicious stuff that comes from the internet requires downloading a malicious file, usually through social engineering tricks, and most of such stuff is blocked by IE.

Conclusion: IE is the most secure browser out there but I don't need that much protection (common sense n AVG IS covers all that) and all I want is a slim, fast and extendible browser and that's what Chrome has got happy
@MrElectrifyer But, like you, I prefer Chrome...IE is annoying to use.
0 Votes
+ -
Chrome's blacklisting might not be as good as Microsoft's, but it ships with both Flash Player and PDF Reader plug-ins that are both sandboxed and transparently updated. (While IE9 does sandbox Flash Player, it does not transparently update Flash Player like Chrome does.) And, seriously, blacklisting web sites (just like blacklisting malware using AV sigs) is *always* a step or two behind the miscreants.

In addition, Chrome blocks Java-enabled web sites from loading if the Java plug-in (read JRE) is out-of-date. And neither Chrome nor IE9 sandbox Java.

This is why I run Firefox/NoScript sandboxed on my Windows and Linux systems using either a 3rd party sandbox or OS-supplied sandbox. All plug-ins, including Java, are sandboxed. However, I will admit to having applied some elbow grease to further Firefox's default security.

Out-of-the-box, both Chrome and IE9 are more secure than plain vanilla Firefox.
@MrElectrifyer

No, that's not necessarily the case... as the title of this section indicates: Zero Day. A socially engineered piece of malware typically isn't classified as a zero day exploit. However compromised web sites are, and most zero day malware does not require user interaction in order to be installed. And IE is the only browser that allows (via known SIDs) direct kernel access.
Thank you for sharing .I send this address to avant browser developer's mail .I think they should more care about security principles.
Google products are not even worth discussing...they are not better than pirates and thieves...

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix