5 ms·
As a Chrome developer, I agree that process-per-tab absolutely should not be a replacement for fixing bugs. However, I think it's important to point out that pr
by zetafunction 12y ago
As a Chrome developer, I agree that process-per-tab absolutely should not be a replacement for fixing bugs. However, I think it's important to point out that process-per-tab is not just for stability: it's also critical for security.
- scobar 12y agoI found your statement very interesting, and would like to learn more. If you're allowed, would you please provide more details or links to resources that further explain the security issues that process-per-tab resolves?
- geofft 12y agoThere's a bunch of good public docs on the Chromium security architecture. One big thing that having a separate process per origin does is that you can use OS sandboxing techniques on each process separately, and even if there are renderer bugs, an exploit can't immediately get to another origin; it provides defense in depth by also requiring a sandbox escape. Here's an old paper that talks about the architecture (it hasn't changed much at a high level): http://seclab.stanford.edu/websec/chromium/chromium-security-architecture.pdf http://seclab.stanford.edu/websec/chromium/chromium-security...
- dmix 12y agoChrome is way ahead of Firefox in terms of security. It's worth the performance trade-offs. Each website is rendered in a separate process with a sandbox, each with an empty chroot + process namespace + network namespace + tiny seccomp-bpf + syscall whitelist. Chrome also has a stronger sandbox, pioneers better SSL, supports PIE on binaries, uses pepper - doesnt use native Flash plugins, the JIT compiler does randomization / encryption tricks to make it hard to heap spray exploit code. They have their own hardened memory allocator called PartitionAlloc. Etc Etc. Firefox also had more critical CVEs in 2014 than Chrome: http://pastebin.com/raw.php?i=2CRyJkmV http://pastebin.com/raw.php?i=2CRyJkmV And reports of sandbox escapes are less common in Chrome for a reason.
- jacobolus 12y agoWorth the performance trade-off for who? For my own use cases, Chrome drags my whole system performance into a gutter and shoots it full of bullets. In other words, it’s not just a “trade-off”, but rather Chrome is completely and utterly unusable, while both Safari and Firefox handle the load with no problem.
- spoiler 12y agoI actually have more problems with Firefox's performance than with Chrome's (in terms of processor power), Chrome definitely uses more memory, but it's super fast; firefox is just abysmally slow and can;t handle more than a few tabs. Tried both browsers on Windows 8.1 and Linux, with different machines (home and work computers), too. However, my high memory consumption in Chrome was due to using AdBlock, which is much lower now that I switched to uBlock. Even back with AdBlock, memory was never an issue with many tabs open. My only problem (which is probably not Chrome's, but my laptop's fault) is that sometimes, when having ~20 tabs open, and certain tabs are idle for a long time, they take a bit of time to re-render once I visit them again, but that also used to happen in Firefox.
- wooger 12y agouBlock is now available on Firefox too, and makes an even more dramatic difference in performance. I really don't know what you're talking about - Chrome is a dog after ~10 tabs are opened, uses crazy memory and becomes unusable fast once it starts paging. Firefox remains stable, backgrounds tabs you're not using in a graceful way, and doesn't try to open and render every single tab at once on a session restore. It's unbelievable that Chrome still does this, after the problem has been reported for years.
- jtblin 12y agoAre you on Windows? I'm not seeing this on Mac, I often have 30+ tabs opened and apart from high memory, I don't suffer of any performance issues.
- 12y ago