4 ms·
It's the lack of defense in depth which I would say is disappointing more than anything. Firefox prior to e10s pretty much ran everything save for NPAPI plugin
by ryuuchin 10y ago
It's the lack of defense in depth which I would say is disappointing more than anything. Firefox prior to e10s pretty much ran everything save for NPAPI plugins in the same process. Perhaps it is "sandboxed" in the code but in practice I'm not sure you could call it a sandbox from the defense in depth standpoint. Simply running stuff in a separate process doesn't count for much if the separate process is not restricted in any way.
When you contrast it with Chrome which uses basically every single operating system mitigation in addition to their sandboxing and the difference really is striking.
I'm looking forward to the future of e10s Firefox since it now enables them to move forward with more advanced security mitigations and better defense in depth. I believe Mozilla released a plan for the future of these things which it showed what they wanted to do step by step (e.g. plugins first, etc).
- ianlevesque 10y ago> Perhaps it is "sandboxed" in the code but in practice I'm not sure you could call it a sandbox from the defense in depth standpoint. Simply running stuff in a separate process doesn't count for much if the separate process is not restricted in any way. Exactly this.
- cptskippy 10y agoBy that definition Chrome is the only browser that sandboxes. But your comment was on how ridiculous it was that Firefox was the only one not doing it. People's hate of Mozilla is very similar and as misguided as their hate for Microsoft and it really shows in your original statement that they can do no right. Instead of a congratulatory "welcome to the club (of one)", it's "why weren't you a member all along?"
- anon1385 10y agoAre you not aware of how Safari works? https://trac.webkit.org/wiki/WebKit2 https://trac.webkit.org/wiki/WebKit2
- cptskippy 10y agoI am, would you like to clarify whatever point it is that you're trying to make?
- anon1385 10y agoWhy are you claiming that Safari uses a single process for everything except plugins?
- cptskippy 10y agoI was talking about sandboxing. Multi-process rendering is not the same thing and does not intrinsically sandbox an app or make it more secure.
- anon1385 10y agoBut Safari uses multiple processes and sandboxes those processes. You keep claiming that there is some difference between it and Chrome but you can't say what it is.
- cptskippy 10y agoSafari is a sandboxed app but that covers everything, I have never read about individual process level sandboxing in Safari beyond the plugin sandbox. Are they using XPC or did they roll something custom?
- comex 10y agoWebProcess does have its own, more restrictive sandbox, although it's not as tight as Chrome's: https://github.com/WebKit/webkit/blob/master/Source/WebKit2/WebProcess/com.apple.WebProcess.sb.in https://github.com/WebKit/webkit/blob/master/Source/WebKit2/... For IPC they use something custom (part of the WebKit repo) called "CoreIPC".
- ryuuchin 10y ago> By that definition Chrome is the only browser that sandboxes. I believe most Chromium based browsers could also fall under that category although I admit that's just being pedantic. Furthermore at least Edge and to the lesser extent IE(11) do have some sandboxing which purpose is to enhance security. Their (renderer) processes do run at a low integrity level and are ran within an Appcontainer. On IE11 this is enabled through the use of Enhanced protected mode with 64-bit processes. This allows it to use AppContainers even with the desktop browser. Edge always uses AppContainers AFAIK. I'm not sure it's sandboxed to the same extent as Chrome but it is a level of defense in depth. Edge also uses some security mitigations that Chrome does not such as CFG (control flow guard) although that's not dependent on a sandbox so CFG, baring performance issues, could be used in any browser sandboxed or not.
- gcp 10y agoI believe Mozilla released a plan for the future of these things which it showed what they wanted to do step by step (e.g. plugins first, etc). Flash and Media Plugins (video decoders, EME/DRM) have already been sandboxed for several releases. There is a content sandbox in the development versions of Firefox. Of course it won't ship before e10s is considered stable, because that's a hard prerequisite for it. The amount of protection also varies by operating system (Windows and Mac OS X are pretty OK, Linux is still pretty crappy) but obviously that is improving week by week.
- ryuuchin 10y ago> Flash and Media Plugins (video decoders, EME/DRM) have already been sandboxed for several releases. Firefox provides its own sandboxing now? Flash used to use a subset of the Chrome sandbox for Flash but that was restricted to the 32-bit version of the browser. As far as I was aware Firefox just ran it in the plugin-container processes for crash protection and nothing else (if protected mode wasn't being used or if you were on 64-bit Firefox). Does Firefox now make use of OS mitigations and integrity levels for sandboxing the plugin process?
- cpeterso 10y agoLike you say, Adobe's Flash sandbox (aka "Protected Mode", based on Chrome's sandbox library) only supports 32-bit Windows. Mozilla wrote its own plugin sandbox for 64-bit Windows because we didn't want to Firefox users to lose sandboxing just because they switched from 32-bit to 64-bit. Adobe's and Mozilla's sandboxes don't use all the same mitigations and some Flash content is currently broken in 64-bit Firefox. Here is the Firefox bug tracking the 64-bit sandbox work: https://bugzilla.mozilla.org/show_bug.cgi?id=1165891 https://bugzilla.mozilla.org/show_bug.cgi?id=1165891