4 ms·
TL;DR AV infects Chrome processes to the point they can't ship security features because they no longer control the application code.
by devmop 10y ago
TL;DR AV infects Chrome processes to the point they can't ship security features because they no longer control the application code.
- Klathmon 10y agoAnd it's not just breaking the actual code, it's breaking the standard communications and formats that all major browsers use. I've personally seen HSTS, HPKP, HTTP2, TLS1.3 and more all get royally fucked by various AV programs. And that's just from doing tech support for my family. I understand that if an AV wants to protect certain aspects they need to get access to it, but using these hacks, workarounds, and more to do it is not only unprofessional but both a security and usability nightmare. It's also why the only AV i'll ever recommend will be Windows Defender. People like to complain that it doesn't "catch as much as the others", but at least it's not actively breaking shit.
- dblohm7 10y agoFirefox dev here. All browsers have a big bulls-eye on their foreheads with respect to AV, and it's not just security features that are held up. These AV products patch our binaries all over the place such that changing any browser internals that happen to be targeted by AV will cause crashes.
- busterarm 10y agoOn the other hand, users tend to be more hardline about their choice of browser than they are about their choice of antivirus. Perhaps clearly communicating this fact to users and updating your software as you see fit will swing the needle in your favor.
- masklinn 10y agoIt'll work no better than for windows. When the browser crashers after it's been updated, users will blame the browser not the shit AV.
- busterarm 10y agoWindows would never call out a vendor in their ecosystem. It's suicide. Browsers don't have to play by those rules. I'm basically saying they should come out and say "your av is shit". Though obviously with better phrasing. Browsers do have the mandate of system compatibility, but it shouldn't be to the detriment of evolving their product. I guess my strategy would be to find something to patch vs an antivirus vendor with a low install base and put the industry on notice. Edit: Big honking popup that says "Detected Antivirus software X is modifying our software without permission. This compromises the security of your system and the stability of our software."
- Klathmon 10y agoI think starting that war will just end up putting users (especially unknowledgable users) at greater risk. Think about it from a layperson's perspective. A browser maker is saying that the security software isn't secure, but the maker of the security software whose entire company is formed around security says it's fine. Which would you believe if you didn't have the knowledge you have? In the end, if browsers started this fight publicly, AV vendors might start "making" their own browsers which are horribly insecure (Comodo does exactly that already, and about a year ago they shipped it with the same-origin policy disabled [0]). Not to mention that uninstalling/removing AV software is difficult at best and impossible at the worst (If norton is on a machine, i'm reinstalling the OS, because I don't think there's another way to get it off of there), and in some cases people have paid money for their AV through shady upsells and FUD. And they aren't going to give up their paid software (and in their heads their security) for a free browser when there are several others to choose from. It's a shitty situation all around. [0]https://news.ycombinator.com/item?id=11021633 https://news.ycombinator.com/item?id=11021633
- busterarm 10y agoYes, but then if AV companies build their own browsers and crash yours, you can have the government step in and prosecute them for their anti-competitive business practices. I can't imagine any of the AV vendors getting a web browser right to the point that they'd have widespread user adoption. And from the perspective of the Firefox or Chrome or Opera, that user probably wasn't using an updated version of your browser anyway...
- wfh 10y agoChrome Dev here. Still trying, and currently failing, to ship App Container (Low Box Token) for renderer processes. We strongly suspect AV is tampering with renderer process startup causing our attempts to set the low box token to fail (the token manipulation has to occur while the process is suspended, and we suspect AV is injecting threads at this point). Either that or AV is just crashing the process because it does not expect its calls to fail inside the sandbox. Very frustrating. Glad jschuh has come out and said what we all believe.
- eksrow 10y agoDoes windows defender cause any problems for browser devs?