4 ms·
> But if not, how is this situation inherently different from running Chromium, which has a strong sandbox and statically links basically everything? I realize
by jdiff 3y ago
> But if not, how is this situation inherently different from running Chromium, which has a strong sandbox and statically links basically everything? I realize that in the virtualization case, Chromium is running on a separate kernel, but does that really make a difference in practice?
This is just not how static linking works. You're not suddenly running on a modern, secure OS because all your web browser dependencies are up to date. And your up-to-date, statically-linked browser is still interacting with your OS, not just the kernel but the OS and userland and everything.
Static linking is not a security measure.
- Wowfunhappy 3y agoStatic linking is not typically a security measure because you would assume the host system's libraries are equally if not more up to date. In the case of modern software designed for Windows XP, I absolutely consider static linking to be a very significant security measure, because every statically linked library decreases the amount of vulnerable userland code in use. For example, Chromium literally doesn't use the Windows SSL stack—it brings its own—so any and all SSL vulnerabilities on the Windows side are irrelevant. On Linux, you could decide to statically link everything and create a binary which literally doesn't touch userland—but I don't know if it's possible to go this far on Windows. Regardless, it's true that at some point Chromium will need to tell the OS to e.g. blit pixels on the screen—as does VMWare, which was the point of that comparison—and you could attack the OS via the pixel blitting function. However, this would be considered a Chromium zero day. A zero-day which is non-exploitable in Windows 11 might be exploitable in Windows XP—this is what you loose by forgoing defense in depth—but it would be fixed in due time regardless.
- jdiff 3y ago> blit pixels on the screen This is where you lose me. The browser is a bloated beast that incorporates and reimplements so much of the OS. But not that much. The OS still interacts with the OS far too much for static linking to make much of a difference. And even if there is a modern Chromium 0day, like the Skia exploit I mentioned, sure, that's a Chrome bug. That's still a bigger problem for older OSes that have absolutely no protection once something escapes the sandbox.
- Wowfunhappy 3y ago> The browser is a bloated beast that incorporates and reimplements so much of the OS. But not that much. The OS still interacts with the OS far too much for static linking to make much of a difference. The thing is, we don't actually care about the whole OS, we care about the bits that interact with untrusted remote data, i.e. web content. I really don't think there are many opportunities for Chromium web content to interact with the host OS. Everything goes through Chromium's renderer. If web content is able to affect things on the other side of that renderer, that's a zero day! > And even if there is a modern Chromium 0day, like the Skia exploit I mentioned, sure, that's a Chrome bug. That's still a bigger problem for older OSes that have absolutely no protection once something escapes the sandbox. We agree on this point! A zero day is vastly more dangerous to a Windows XP user than a Windows 10 user. This is the benefit of defense in depth, which you loose by blatantly removing a major layer of defense. However, for regular consumers, I still believe the risk of being hit with a zero day is vanishingly small. A person who daily drives Windows XP but browses the web in Supermium, installs new versions of Supermium within 24 hours of release, keeps his or her passwords in Bitwarden behind a strong master password, and uses a good home router with updated firmware is less vulnerable to cyber threats than the vast majority of the population! Zero days aren't used to create botnets, they're used to launch targeted attacks on high-stakes targets. No one uses them in automated attacks because (A) people would see the attack and patch the vulnerability and (B) it's so much easier to take over insecure wifi routers. https://xkcd.com/538/ https://xkcd.com/538/ is also relevant here. --- Please do share if you think there is a specific attack surface I am overlooking. As I've said, this is directly relevant to me as a user of OS X 10.9, which hasn't been updated by Apple since 2015. If I am currently exposed in a way that leaves me vulnerable to an automated attack (!), I need to either patch the OS myself—I have done this before—or, if I absolutely must, take more drastic measures such as moving all of my web browsing inside VMWare Fusion or migrating off of my favorite platform.
- saagarjha 3y agoOk recent example we had a bunch of 0 days targeting Android where attackers sidestepped basically all of Chrome’s security features because of bugs in Mail GPU drivers. A fully-patched Chrome can only assume that these were written correctly and dutifully calls into them as appropriate (from userspace, of course). If these legitimate calls end up triggering the bug then you have attack surface that is exposed to web content.
- hnlmorg 3y agoLet me throw the same question to you that I had to redder23: What part of the OS are you specifically concerned about? "Operating system" is a pretty broad description and there isn't a whole lot of surface area between this specific sandbox and the OS-owned APIs. Font rendering is one concern that has already been raised; and by those defending this browser too. But literally no-one who's opposed to this browser has named a single specific vulnerable API in this thread. This is the problem we're having in this conversation. Claims are being made that this is insecure -- made in absolute terms. Yet zero attempts have been made to back up those claims. Just handwavey comments about "the OS is out-of-date".
- jdiff 3y ago> "Operating system" is a pretty broad description That's the problem, and the concern. I've given several concrete examples (both of actual exploitable surface area and more abstract kinds of exploitable surface areas) in this thread already, feel free to refer back to them. A lot of what you're complaining about as handwavy is just common knowledge. Ask questions if you're interested, but out-of-date OSes are factually insecure in known-unfixable and unknown-unfixable ways.
- Wowfunhappy 3y agoWith all possible respect, I don't think you have given concrete examples. You have given general examples, and hnlmorg and I have explained why we don't think there are concrete problems to be found there. The exception is font rendering. I haven't used Supermium specifically and I don't know enough about how it works, but if Supermium is passing remote web fonts directly to the OS for rendering, that needs to stop immediately, and until it does all Supermium users should disable webfonts! As an aside, if there is in fact something like an exploitable buffer overflow in Windows XP's TCP/IP stack, that is something enthusiasts could probably patch.
- hnlmorg 3y ago> That's the problem, and the concern. But the point you keep missing is that browser do not interface with the entirety of the OS. Just because code exists, it doesn't mean the browser calls that code. For example notepad.exe was used as a UAC bypass in early versions of Vista. But there isn't any way a website running in Supermium can elevate itself to run as Administrator, let alone use notepad.exe to bypass the UAC, without exploiting a serious zero-day in Chromium. And if attackers have a zero-day that serious in Chromium, then they're not going to burn it on infecting the 10 people who run Supermium. > I've given several concrete examples (both of actual exploitable surface area and more abstract kinds of exploitable surface areas) in this thread already, feel free to refer back to them. You've given one and even that was impossibly vague. > A lot of what you're complaining about as handwavy is just common knowledge. Nobody is disputing that you should keep your OS fully patched. But what's being said here is that the age of the system ironically actually works in its benefit: it's now a small enough market share that it isn't worth burning a Chromium zero day on. That all said, advise of not running XP / Vista for work is wise. And not connecting them to untrusted networks is wise too. Nobody is disputing that either. What is being said is that having an XP / Vista machine at home (likely for retro gaming or other niche use case) isn't automatically catastrophic. Things don't have to be boolean :) > Ask questions if you're interested, but out-of-date OSes are factually insecure in known-unfixable and unknown-unfixable ways. I have quite a lot of experience hacking Windows and even wrote my own hobby browser a while back. I'm pretty well versed on the topic. The one question I asked is examples of how you would exploit "the OS" from the browser. So maybe it's better we agree to disagree