3 ms·
> I've read that Chrome is more secure, in terms of integrity when attacked, which of course can help privacy (i.e., confidentiality). I've read that it's due t
by ryuuchin 10y ago
> I've read that Chrome is more secure, in terms of integrity when attacked, which of course can help privacy (i.e., confidentiality). I've read that it's due to Chrome's security model, but I'd be interested if someone would be willing to describe it in more detail.
The developer documentation[1] does a pretty good job at describing the security model and the defense in depth that it provides. Edge adopts a similar sandbox model although Chrome's is probably better. Their sandbox model allows them to leverage nearly all of the OS mitigations and security features that Windows[2] (and other's) have to offer.
One example of a major difference that can be enabled because of Chrome's model is the usage of Win32k.sys lockdown which is the only way which you can reduce the kernel attack surface on Windows. This is enabled for all renderer processes and may be enabled on plugin processes as well (not sure if that got enabled globally yet outside of field tests). Win32k lockdown blocks access to the entire GDI subsystem among some other things.
As far as I know Chrome and possibly chromium based browsers are the only ones who currently use the win32k lockdown mitigation.
[1] https://www.chromium.org/developers/design-documents/sandbox https://www.chromium.org/developers/design-documents/sandbox
[2] https://www.chromium.org/developers/design-documents/sandbox#TOC-Sandbox-restrictions https://www.chromium.org/developers/design-documents/sandbox...