6 ms·
Introducing Windows Defender Application Guard for Microsoft Edge
- CurtHagenlocher 10y agoMicrosoft's excellent word salad naming engine strikes again! (Disclosure: Microsoft is my employer.)
- chrismorgan 10y agoFewest vulnerabilities: I suspect that Chrome and Firefox being open source is a factor here. Thus it seems possible to me that they actually have fewer vulnerabilities than Edge—Edge’s just haven’t been found yet. This is pure speculation on my part; I have no evidence nor any investigation, deep or otherwise.
- nickpsecurity 10y ago"Edge’s just haven’t been found yet." Haven't been introduced and haven't been found. It's both. Microsoft's SDL has dramatically reduced number of 0-days in their products. I speculate that eliminating many common vulnerability classes also eliminates a lot of the low-hanging fruit that's easiest to spot in the binaries by reverse engineers. They have potential to raise the security even higher if they apply MS Research's tools like VCC or Dafny. I don't even know what Edge is written in, though.
- lawnchair_larry 10y agoYou're kind of talking out of your ass here, fyi. They have been introduced and they have been found. Don't underestimate Google's resources on chrome. Especially considering that many Google security folks were previously at MS.
- nickpsecurity 10y agoIm not sure what comment you read as I mentioned they both have 0-days and that number of them dropped sharply due to SDL. The numbers available prove both. Even more true given attackers are focusing on common applications more than Windows itself. That's because they're easier to attack than Windows code.
- ThinkBeat 10y agoChrome and Firefox has a much larger userbase than Edge has. (As of now). As Edge matures and its userbase grows we will have a chance to see how it measures up :)
- WorldMaker 10y agoEdge's JS engine (Chakra) has had the majority of itself open sourced (ChakraCore). Given how central the JS engine is to overall browser security, I wonder if that changes your suspicions at least a bit?
- timmeyh 10y agoAlso keep in mind that almost no-one is using edge: 4 till 5% browser market share (depending on the source used for such data). Whereas Chrome has a 25-35% market share (again, depending on source). It's just plain obvious that people don't want to put in a lot of effort to find a vulnerability as their target audience/ ROI is only so little...
- deleted 10y ago[deleted]
- jasonkostempski 10y ago"We’re determined to make Microsoft Edge the safest and most secure browser." Then open source the whole thing, not just little parts of it. It has the lowest number of vulnerabilities in the National Vulnerability Database because it has the least number of eyes able to look for them.
- pjmlp 10y agoYes, because it has helped OpenSSL a lot.
- michaelbuckbee 10y agoThe point isn't that every open source app is awesome, it is that now you KNOW. You're directing snark towards OpenSSL presumably because you think it's a poorly coded. If it was closed source you might not even be aware of the issues and there certainly wouldn't be the open source efforts to code alternatives.
- nickpsecurity 10y agoIf it was closed-source, we would assume it had lots of issues until reviewed by a qualified, third party that we trust saying otherwise who also gives us signed hash for binary that was reviewed. The way it's been done in proprietary evaluations a long time. It would be done more if companies were actually interested in a real evaluation instead of a stamp that knocks out their liability. ;) Under DOD's TCSEC criteria, the high-assurance systems (A1-class) also had to be delivered in source form to paying customers with evaluation evidence. They can check hashes/signatures, check the evaluation evidence themselves, and build it on site. So, vendors got paid large sums of money to develop the products, independent evaluation ensured you got some pentesting, and you could inspect the source yourself. My modification to the scheme involved evaluators with hacking background in mutually-suspicious countries working side-by-side with developers every step of the way. Traditional open-source development is weak against all of these given there's usually a lack of qualified expertise or just people willing to dig into it. Just open-sourcing something gets people almost nothing in security. Has to be reviewed.
- kenrick95 10y agoIt's using Hyper-V, so does that mean this only applies to Pro and Enterprise edition of Windows 10?
- dahjelle 10y agoAm I reading correctly: WDAGfME (for lack of a better acronum) is essentially starting a VM with a fresh copy of Windows for every site that it is protecting? Does this happen for every open & protected tab/window? What kind of overhead does it have? The idea sounds similar to Qubes OS, with the exception that it's transparent to the user and doesn't have to be configured by the end-user. I presume this kills any of the offline-storage approaches?
- 0xFFC 10y agoThe idea of starting new fresh copy of Windows software stack for every site is kinda naive. I would say they are using something similar to Linux kernel namespace mechanism for sandboxing in Windows kernel, which is quite efficient and secure sandboxing without going through the pain of virtualization(Google uses this mechanism for implementing Android subsystem in ChromeOS). But how hyper-v fits to this equation, I don't know.Maybe something similar to docker service in hyper-v. But anyhow this is quite amazing idea, Microsoft really tries hard to improve Edge. The reason they can overcome technical difficulty of something this cool is because they have very consistent and very limited underlying platform (they don't have to support macOS, Linux, etc). Imagine how hard it would be for Firefox and chrome to pull off something similar. >I presume this kills any of the offline-storage approaches? Not necessarily, it depends on how they did implement this. (I may be wrong,please correct me)
- daeken 10y agoI see two options: 1) they're using Hyper-V and exposing a small number of hypercalls to allow for rendering and interaction. 2) they've overloaded the Hyper-V name for a user space sandbox. I'm really hoping for the former, as it'll mean they finally might expose a KVM-esque API. That would mean a drastic change for virtualization dev on Windows.
- jlgaddis 10y agoMaybe I'm misunderstanding the question, but the article clearly describes that they're using Hyper-V to launch a separate instance of the kernel and the browser in a "container" (which is later "discarded").
- nickpsecurity 10y agoThe one good thing about this is that they're relying on Hyper-V. It may end up much more secure than solutions like Xen simply because Microsoft is investing in so much verification. That started with Verisoft project where they started using their VCC tool to verify the C-level source against specifications. They later extended the tool for assembly. The first report I saw indicated 20% was verified against its spec. So, it should get more robust overtime. People interested in Microsoft Research's work on secure browsers should look at Gazelle browser and Xax plugin architecture: https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/gazelle.pdf https://www.microsoft.com/en-us/research/wp-content/uploads/... https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/xax-osdi08.pdf https://www.microsoft.com/en-us/research/wp-content/uploads/...
- zmanian 10y agoWhy is this enterprise only?
- bboreham 10y agoI sense this is the same feature that is used to implement Docker containers. Possibly browser isolation was the primary driver and it got co-opted for the server.
- mtgx 10y agoWhy is this an enterprise-only feature? Do regular user not deserve the same level of security for their browsers? Will this tech even be available to non-Microsoft apps in the future?
- nneonneo 10y agoIt's not very useful for regular users outside of private browsing - the WDAG windows are unable to persist any state at all since their container is discarded at the end of the browsing session to thwart malware persistence. It does sound like an interesting capability for private browsing, but existing mechanisms mostly cover that. Even if WDAG applied to private Windows, ordinary users aren't so likely to open private browser windows just to check a link from an email. I expect that if you had a copy of Win10 Enterprise you could configure the feature yourself for added security in paranoid cases (e.g. journalist covering abusive regimes who might be targeted by state-level malware).
- sliverstorm 10y agoPerhaps non-enterprise does not have widely deployed support for Hyper-V, for example VT-x/AMD-V support & BIOS enablement.
- transpute 10y agoTwo related projects, both with copy-on-write "forks" of disk storage and OS memory, creating disposable VMs with hardware-enforced memory isolation. Cappsule (open-source for Linux), https://cappsule.github.io https://cappsule.github.io virtualize any software on the fly (e.g. web browser, office suite, media player) into lightweight VMs called cappsules. Attacks are confined inside cappsules and therefore don’t have any impact on the host OS. Applications don’t need to be repackaged, and their usage remain the same for the end user: it’s completely transparent. Moreover, the OS doesn’t need to be reinstalled nor modified. Bromium (proprietary for Windows, based on open-source Xen), https://blogs.bromium.com/2016/09/26/introducing-virtualization-based-security-next/ https://blogs.bromium.com/2016/09/26/introducing-virtualizat... Bromium and Microsoft partnered in 2015 .. extends VBS – isolating the execution of targeted applications such as the browser, documents, executables, downloads, attachments and media files .. to all vulnerable applications on all Windows 7, 8 and 10 endpoints
- brazzledazzle 10y agoI wonder how Bromium is taking this news.
- lawnchair_larry 10y agoUgh, they should know better than to use CVE as a metric. Should we assume that Opera is the most secure browser then?
- webwanderings 10y ago> We’re determined to make Microsoft Edge the safest and most secure browser. You should enable Ad/tracker-block by default and across the board.
- behm 10y agoSo just to be clear, this is basically another sandbox, which starts a private browsing session implicitly for each site and disables the entire password manager?