9 ms·
"A functional sandbox for enhanced security" Well, I think if you're running win 2003/XP and actually dare to go into the internet with the machine, you openly
by redder23 3y ago
"A functional sandbox for enhanced security"
Well, I think if you're running win 2003/XP and actually dare to go into the internet with the machine, you openly and proudly do not give a flying fuck about any security. The amount of open holes is insane, and some Chromium project that some dude ported is not going to save you.
Projects like this never made any sense to me.
- Wowfunhappy 3y agoIf the browser is properly sandboxed, and you're only accessing the internet through the browser, you should reasonably safe, no? Obviously it's better to have defense in depth, but I don't see the immediate danger. What is the attack vector you are concerned about? --- I daily drive a 2013-era version of OS X, using a similar modified version of Chromium[1] to browse the web. I'm pretty sure I've plugged the holes I need to plug in order to be reasonably safe, but if you have a specific concern I'd like to hear about it! 1: https://github.com/blueboxd/chromium-legacy https://github.com/blueboxd/chromium-legacy
- jdiff 3y ago> you should reasonably safe, no? No, just as an example, Windows has had multiple kernel exploits that only required crafted fonts to be loaded by the victim computer. Any interaction with the world outside of the sandbox leaves room for a foot in the door, and there's necessarily a lot. Images, video, audio, the multitude of device APIs, and like the font exploits show, even the most basic page rendering.
- Wowfunhappy 3y agoMy understanding is that Chromium renders fonts and other graphics primitives via Skia. Video and audio uses ffmpeg. And all of these libraries are statically linked.
- jdiff 3y agoSupermium in specific will let you render text with GDI (for performance, probably?), videos are played with FFMPEG but that still means hauling untrusted footage outside of the sandbox for hardware decoding, and there's still countless other potentially-pierceable membranes in the sandbox. This (probably) isn't a practical vector for a browser, but kernel exploits have been crafted out of scrollbars in the past. Any time the sandbox calls out to the OS in any capacity it's trusting that the surface it's touching isn't vulnerable, and sometimes it is. For a sandbox to solve this, it's not good enough to just prevent people from misusing the APIs that exist on paper, you have to verify that the API itself isn't bugged and exploitable. And it's not just OS surface, either, Skia's just as penetrable as any other membrane in the sandbox.[0] [0] https://nvd.nist.gov/vuln/detail/CVE-2023-6345 https://nvd.nist.gov/vuln/detail/CVE-2023-6345
- hnlmorg 3y agoIf ffmpeg is statically linked then code isn't leaving the sandbox. Browsers don't use the OS's scrollbars because browser scrollbars are themeable in ways that the system scrollbars are not. I do agree with you in principle but in practice, we aren't talking about a wide attack surface if you're using an older OS + modern browser vs a modern OS + modern browser. It's certainly drifting into the realm of a targetted attack. And if you're the kind of individual that is likely to be targetted in this kind of way, then you'd have a lot more secure defaults than just "modern OS + modern browser". So it all boils down to what your threat model is. If you're Satya Nadella then this would be stupid. But if you're just some random Joe Bloggs who plays a few retro games, then realistically this should be safe enough to load GOG.
- jdiff 3y agoIt does leave the sandbox. How else are you going to get hardware acceleration? That means talking to the hardware, which means talking to the OS, which is outside of the sandbox. I already said scrollbars weren't a practical example, just an example of how benign APIs can be exploited. I heavily disagree about the threat model. It costs next to nothing to cast the net out for users neglecting their computer (and there are very many), and the payout is a hefty botnet.
- redder23 3y ago[flagged]
- deleted 3y ago[deleted]
- hnlmorg 3y agoMost people these days sit behind a firewall on their router. This wasn't nearly as common in 2003. So the only way the OS is exposed is via the browser. I'd hope (expect even) this port to include it's own libraries for things like TLS, JPEG, PNG, PDF, etc. Which I'm pretty sure Chromium does anyway. But type-faces might still be an issue. TTF is Turing complete and I wouldn't be surprised if that was handed by the OS. So there might be an issue there.
- redder23 3y ago[flagged]
- gruez 3y ago>But assuming the Browser is secure, the browser communicates to the internet "hey here is an IP" that fact alone is a security risk as the attack may come directly to the OS not the browser. Heck, this Browser may even send a user agent that actually says it's some old windows that is no longer supported, lol. Can you sketch how you're going to hack a windows XP SP3 that's behind a NAT firewall?
- hnlmorg 3y agoTake a moment to think about this please. I get this is a topic you're passionate about but you're making a number of false assumptions. > NOPE, some "firewall" in a consumer router does not suddenly make a 20+ year old OS secure. That wasn't the claim. The claim was it eliminates a chunk of risk (ie someone connecting to you from outside). So the risk is now "just" code you import and run. > The OS accesses the internet, not the browser Which part of the "OS" are you concerned about? Please be specific. > It's funny how you just mention some 20-year-old technique that even grandma knows about. I don't recall seeing you comment on any techniques. If you're so much wiser than the rest of us, then please do share these techniques that we've all missed. > But assuming the Browser is secure, the browser communicates to the internet "hey here is an IP" that fact alone is a security risk as the attack may come directly to the OS not the browser. How does it? A buffer overflow in the TCP/IP stack? Maybe. Have you got an CVEs to back that claim up? Maybe DNS? But the Browser can easily bypass the hosts DNS resolver so this is a solvable problem. Beyond that, the browser manages the rest. > Heck, this Browser may even send a user agent that actually says it's some old windows that is no longer supported, lol. User agent string is trivial to change. It's literally just a HTTP header and there are numerous browser plugins that support doing just this. --- As I commented in another reply, we need to be clear about attack surface and threat model. In the case of the former, most (nobody said "all") of the security concerns are sandboxed by the browser. In the case of the latter, if your threat model includes targetted attacks then this browser on an older OS would clearly be the wrong choice. But for most people this would appeal to, that isn't a risk worth accounting for. ie this is safe enough for anything not important.
- redder23 3y ago[flagged]
- guestbest 3y agoNot that I recommend using such an old operating system or not getting current patches, what is the likely ways a hacker would own the user is they were otherwise using a host blocker combined with unlock origin and not running any other executables except chrome on their system?