7 ms·
Microsoft tries to step on WebGL, stumbles on its own feet
- billybob 15y agoSummary: "Microsoft's position is not entirely unreasonable... [But] the same vulnerability exists in Silverlight 5... So, Microsoft, does this mean you are going to kill 3D support in Silverlight, or does it mean you will add WebGL support to Internet Explorer? A little consistency would be nice, you know?"
- burgerbrain 15y agoI know this sounds nuts, but if we're going to have this crap one way or the other, I'd prefer it stay in NSPlugins that already (appropriately) have a bad name and are opt-in, not opt-out.
- marshray 15y agoI see the logic in that but I wouldn't browse without Noscript either way. WebGL is not something I would run without intentionally "trusting" the site that was serving it. Which is not to say I wouldn't ever run it, only that I would surf with it off.
- tzs 15y ago> But since when did a security flaw mean that we throw the entire piece of technology out? Maybe when that piece of technology involves taking large amounts of code running at elevated privilege, and that was written by people who assumed that it would NEVER be exposed to untrusted code, and exposing it to untrusted code?
- VMG 15y agoHe is right though in his analysis that the users won't care. The browsers that let you play shiny games will win, security be damned. So market pressure will force everybody to do WebGL.
- Locke1689 15y agoApple has very successfully marketed OS X as being "virus free." When every browser but IE is suffering serious vulnerability problems, IE will look very good.
- mbrubeck 15y ago...except that there are dozens of other sources of "serious vulnerability problems" besides WebGL. IE has had plenty of critical security holes in the past without WebGL, and avoiding WebGL is not going to magically make them secure in the future. (Just look at the history of the pwn2own contest, for example.)
- deleted 15y ago[deleted]
- TikiTDO 15y agoNote the proof of concept that takes advantage of a similar bug in Silverlight. The instant Microsoft tries to market IE as secure there will be thousands of articles calling them out on it.
- rmc 15y agoSo people who want to crash a browser will do it on Silverlight aswell for the IE crowd?
- tptacek 15y agoThat's an argument that holds ActiveX in high regard, isn't it?
- TikiTDO 15y agoFlash won the early online game battle against ActiveX. We all know how flash is positioned these days. It's not a question of regard, but market penetration.
- nkassis 15y agoI don't buy this at all. First of all, the GPU is a sandboxed environment. I don't know of way to successfully go from shader code on the GPU to actually take over a machine and get elevated privlidges. Secondly, Flash (and I believe Silverlight) will also be allowing users to provide shaders that flash will compile to native languages for GPUs. Which WebGL implementation currently out there do also, they compile the shaders first, check them and test them. (Check out the Angle project). While none of these things eliminate the risks, they are steps in securing the technology and more work is being done to make WebGL as safe as it can be. The fear that shaders provided by the server can lock up your gpu en in effect crash your computer are also something that is being addressed. There was an article by Gregg Tavares that explained how on Windows, it's possible to time the operation on the GPU and reset the GPU if it takes too long to respond. As far as running code at elevated privileges. I don't see how that's true. First of all, the browser is running this code in a process that has no access to the file system, other process etc. Drivers are mostly user space with a little bit of kernel space code. I'm sure the risks do exists that that level but again, securing this level should already be something Microsoft be working on and forcing Nvidia/ATI/Intel to do the same. And this isn't exactly an easy hack to do regardless, you have to code stuff for a wide range of drivers to make your hacks effective and also manage to get a lot of people to visit your site. The worse case here is Intel graphics that use the CPU for some of the work. In this case a bug could be used to execute abitrary code and hack the machine. I hope I don't sound like I'm saying that the security issues don't exists. What I'm trying to say is while they are there, there is work to fix them and render WebGL safe. WebGL just came out, if in 2-3 years it turns into the hell that ActiveX was then I'll agree it was a bad idea but so far I don't see this getting anywhere close to that level.
- Hov 15y agoSilverlight 5 is not a shipping product, making the authors argument moot. He should have waited till they released it. As things stand now, the reported vulnerability in SL5 beta has already been patched.
- kenjackson 15y agoSo, Microsoft, does this mean you are going to kill 3D support in Silverlight, or does it mean you will add WebGL support to Internet Explorer? Or are you going to fix Silverlight? Oh, you already did? Umm... well, then I guess we better get around to fixing our browsers, rather than putting our feet in our mouths.
- windsurfer 15y agoMicrosoft has reported that they fixed silver-light but haven't actually released the fix (for the latest report that I'm assuming you're referring to that was posted on HN yesterday).
- kenjackson 15y agoCorrect. Silverlight 5 is still in beta. They said that they had fixed the issue and will be part of a future release -- of a product that is currently in beta. You typically don't rush out fixes for beta versions of products.
- bad_user 15y agoYou're missing the point - if it's a fundamental architecture flaw that cannot be fixed, then Silverlight in its current (beta) form suffers from the same problems. You typically don't rush out fixes for beta versions of products You can find fixes of open-source projects as soon as they are committed. Microsoft made a bold claim, people are curious about how they fixed Silverlight if indeed they did that. If not a new Silverlight release, than at least write some kind of blog post explaining what's different in Silverlight. But I'd bet this is typical of Microsoft; right hand, meet left hand, please communicate :)
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- sambeau 15y agoIt wouldn't surprise me if MS dropped the Silverlight browser plugin all together: it is becoming their mobile app technology and looks like it will also replace WPF on the desktop. It makes sense for them to drop the plugin and embrace HTML5 like they claim they are. If they did, then where would the argument go?
- contextfree 15y agoI don't think they will do this anytime soon, but they might introduce extra restrictions on where Silverlight can run, like they have with ActiveX. They are still promoting in-browser Silverlight for internal business apps.
- nextparadigms 15y agoFlash 11 will also use the GPU for 3D.
- StrawberryFrog 15y ago> It wouldn't surprise me if MS dropped the Silverlight browser plugin all together It would surpise me if they dropped it any time soon. MS is big on backward compatibility. Even if a MS technology is "dead" and "abandoned", that just means that there aren't any new versions, but exisiting versions keep working for quite a while.
- varunsrin 15y agoThe article linked within the post was much more insightful than the post itself. http://www.realityprime.com/articles/why-microsoft-and-internet-explorer-need-webgl http://www.realityprime.com/articles/why-microsoft-and-inter... It is however, incorrectly cited in the post as support for the author's argument, which it is not. The Reality Prime article makes the case that it is irrelevant how secure the platform actually is - it will likely come into mainstream use, and Microsoft needs to support it, whether they like it or not. Also, the post fails to mention that there was an official Microsoft response to the vulnerability report, which stated that the vulnerability had been fixed in Silverlight 5.
- zeddez 15y agoApple has taken an interesting middle approach on WebGL. They are only enabling WebGL to certified experiences in iOS. That happens to be ads for now, but it would be easy to extend this to other apps distributed through App Store. That way developers have access to WebGL as an API for 3D, but Apple is not exposing the WebGL attack surface to the entire Internet. As the spec matures, GPU drivers are hardened, etc. they always have the option to open it up more.
- yaakov34 15y agoA [somewhat exaggerated] summary: "there are so many security holes in web browsing already, why do you begrudge us a few more?". OK, I admit there is a kind of madhouse logic to this which I can't refute. There is already a flood of patches that I need to apply about every 5 minutes to something or other, and that's just the vulns that got identified and reported. I certainly agree that nobody will be able to stop this - developers want the API, users want the games. WebGL is currently turned on in Chrome 12, and the only way to turn it off is to add -disable-webgl to the command line. Which essentially means you can assume it's on everywhere, including on the computer of your bank's manager. This is what people miss when they say you can turn it off for yourself. The security aspects of WebGL seem like they were banged out in about 10 minutes. I encourage all to read the Khronos paper on security (http://www.khronos.org/webgl/security/ http://www.khronos.org/webgl/security/), and compare the level of presentation to anything which gets accepted at a security conference. I don't know why I keep returning to this. I certainly don't think that WebGL is the end of the world. There will be some more holes and some more patches. I just think this is another case of the web development world shirking its responsibility to bring real security to browsing (what happened to all those projects which used virtualization to isolate sessions, which I first heard about 4 years ago?), and instead piling on more features without thinking the implications through.
- nickolai 15y agoYour bank's manager likely has IE6, so WebGL is probably not the main security issue in that particular area.
- yaakov34 15y agoOh, and since people misunderstood me in the previous thread, let me add that I am not a Microsoft/Silverlight supporter. Frankly, I do not wish success to Silverlight. It's another technology that nobody really asked for, and it brings its own set of security holes, and it doesn't run on a lot of the platforms I want to use. As a user, I also don't like the whole experience of "plugins" or "applets", whether it's Flash or Java or anything else.
- Deestan 15y ago> A [somewhat exaggerated] summary: "there are so many security holes in web browsing already, why do you begrudge us a few more?" Alternative summary: A has X. B has X. It is inconsistent to bash A for X while promoting B.