5 ms·
From what I can tell about the exploits found at Pwn2Own, there were a total of 4 critical. Looks like FF28 addresses all 4. That was a very quick turnaround.
by mrinterweb 13y ago
From what I can tell about the exploits found at Pwn2Own, there were a total of 4 critical. Looks like FF28 addresses all 4. That was a very quick turnaround.
The fact that FF runs in a single process seems to be a major security issue since the web views are not sandboxed. I know Mozilla is working on their multiprocess project Electrolysis https://wiki.mozilla.org/Electrolysis https://wiki.mozilla.org/Electrolysis that is experimental in FF 30. Hopefully, this project will help harden FF security.
- ris 13y ago"The fact that FF runs in a single process seems to be a major security issue since the web views are not sandboxed." Only to people who don't really understand security. This whole "multi process" "sandboxed" meme started by chrome guys has really got out of hand.
- mrinterweb 13y agoI suppose I was mislead by the mozilla wiki link I posted which states at the top "The goal of the project is to run web content in a separate process from Firefox itself. The two major advantages of this model are security and performance. Security would improve because the content processes could be sandboxed"
- ris 13y agoThe effect is overstated & overrepeated, especially with facilities like e.g. ptrace being available to processes on linux
- fulafel 13y agoNo, ptrace() is not available to Chrome's sandboxed processes. Not in the SUID sandbox and not in the BPF seccomp sandbox. This stuff is described at http://code.google.com/p/chromium/wiki/LinuxSandboxing http://code.google.com/p/chromium/wiki/LinuxSandboxing - if after reading that you still don't think it provides a significant additional layer of security, it would be interesting to hear what flaws you see.
- JoshTriplett 13y ago> The fact that FF runs in a single process seems to be a major security issue since the web views are not sandboxed. Running content in multiple processes, by itself, doesn't help security at all. It does help stability, since if one process crashes the rest of the browser need not; that's particularly important if running plugins like Flash, which crash in a stiff breeze. But if untrusted content manages to exploit a separate browser process that doesn't have any additional sandboxing applied, there's nothing standing between it and the rest of your system. Additional security, however, comes from then applying sandboxing features to those separate processes, following the principle of least privilege.
- mrinterweb 13y agoI suppose there would have been a better way to phrase that sentence. The goal of the Electrolysis is to render the web content in separate sandboxed processes to improve stability and performance.
- voltagex_ 13y agoUnfortunately the bug reports are still 'secret' - https://bugzilla.mozilla.org/show_bug.cgi?id=982906 https://bugzilla.mozilla.org/show_bug.cgi?id=982906
- gcp 13y agoThe autoupdaters are still throttled so not everyone is on Firefox 28 yet.
- blueskin_ 13y agoRunning in a single process (not strictly true; addons are in another) has a lot of performance benefits though. I can get Firefox up to ~1.2GB with a few hundred tabs; Chrome uses that much memory for about 20. Also, splitting process is bogosecurity like "I run SSH on a non-22 port". I thought the general consensus here is that security by obscurity is bad.
- mercurial 13y ago> I thought the general consensus here is that security by obscurity is bad. How is running web views in separate processes "security by obscurity"? I agree that there is nothing inherently secure about it, though it has other benefits, but it doesn't increase obscurity as such (you could argue that the need for well-defined message-passing semantics leads to more decoupled code, decreasing 'obscurity').