14 ms·
> blit pixels on the screen This is where you lose me. The browser is a bloated beast that incorporates and reimplements so much of the OS. But not that much.
by jdiff 3y ago
> blit pixels on the screen
This is where you lose me.
The browser is a bloated beast that incorporates and reimplements so much of the OS. But not that much. The OS still interacts with the OS far too much for static linking to make much of a difference. And even if there is a modern Chromium 0day, like the Skia exploit I mentioned, sure, that's a Chrome bug. That's still a bigger problem for older OSes that have absolutely no protection once something escapes the sandbox.
- Wowfunhappy 3y ago> The browser is a bloated beast that incorporates and reimplements so much of the OS. But not that much. The OS still interacts with the OS far too much for static linking to make much of a difference. The thing is, we don't actually care about the whole OS, we care about the bits that interact with untrusted remote data, i.e. web content. I really don't think there are many opportunities for Chromium web content to interact with the host OS. Everything goes through Chromium's renderer. If web content is able to affect things on the other side of that renderer, that's a zero day! > And even if there is a modern Chromium 0day, like the Skia exploit I mentioned, sure, that's a Chrome bug. That's still a bigger problem for older OSes that have absolutely no protection once something escapes the sandbox. We agree on this point! A zero day is vastly more dangerous to a Windows XP user than a Windows 10 user. This is the benefit of defense in depth, which you loose by blatantly removing a major layer of defense. However, for regular consumers, I still believe the risk of being hit with a zero day is vanishingly small. A person who daily drives Windows XP but browses the web in Supermium, installs new versions of Supermium within 24 hours of release, keeps his or her passwords in Bitwarden behind a strong master password, and uses a good home router with updated firmware is less vulnerable to cyber threats than the vast majority of the population! Zero days aren't used to create botnets, they're used to launch targeted attacks on high-stakes targets. No one uses them in automated attacks because (A) people would see the attack and patch the vulnerability and (B) it's so much easier to take over insecure wifi routers. https://xkcd.com/538/ https://xkcd.com/538/ is also relevant here. --- Please do share if you think there is a specific attack surface I am overlooking. As I've said, this is directly relevant to me as a user of OS X 10.9, which hasn't been updated by Apple since 2015. If I am currently exposed in a way that leaves me vulnerable to an automated attack (!), I need to either patch the OS myself—I have done this before—or, if I absolutely must, take more drastic measures such as moving all of my web browsing inside VMWare Fusion or migrating off of my favorite platform.
- saagarjha 3y agoOk recent example we had a bunch of 0 days targeting Android where attackers sidestepped basically all of Chrome’s security features because of bugs in Mail GPU drivers. A fully-patched Chrome can only assume that these were written correctly and dutifully calls into them as appropriate (from userspace, of course). If these legitimate calls end up triggering the bug then you have attack surface that is exposed to web content.
- hnlmorg 3y agoYou can configure and even turn off external url handlers in Chromium. But even if you didn’t, the attack becomes even more difficult and niche here because now you’re looking for a machine running a specific version of $email_client on a specific version of Windows. This is something that you can’t even use browser fingerprinting to detect.
- jdiff 3y agoMali, a type of GPU used on mobile devices, not Mail. They made a typo.
- lproven 3y agoI guess you mean Mali GPU?
- saagarjha 3y agoYeah autocorrect broke it