3 ms·
This looks impressive for systems that are supported (Vista and up). I'm not entirely convinced that all attack vectors have been considered though. They appe
by stuntmouse 16y ago
This looks impressive for systems that are supported (Vista and up). I'm not entirely convinced that all attack vectors have been considered though.
They appear to have considered the obvious things: write and execute access to files and other resources from restricted processes, preventing harmful windows message behavior.
But would a process with low integrity have read access to every other resource with low integrity? Or is that further constrained by some other access control mechanism? Also, I don't think it's a feature for an unprivileged process to have registry access, though I understand there may be reasons for it.
It could also be argued that there is a larger attack surface for protected mode processes, because they can call any OS function, but are just denied when they don't have the access level to commit the action.
I must admit I am behind the times with regards to Windows system programming.
- briansmith 16y agoYes, one advantage of Chrome's system is that it can be more restrictive than the operating system. And, the pre-scanning is an extra line of defense. I won't attempt to explain the integrity system in Windows because I am not that familiar with it. But, Wikipedia says that read access can be blocked based on integrity level too. See http://en.wikipedia.org/wiki/Mandatory_Integrity_Control http://en.wikipedia.org/wiki/Mandatory_Integrity_Control
- stuntmouse 16y agoAs a final note, there's no reason why the two couldn't be used in tandem. In fact, they should be.
- briansmith 16y agoI think that Chrome and IE differ in how they split functionality between processes (and thus integrity levels), but both Chrome and IE make extensive use of the various sandboxing tools that Windows offers.