Results 1 to 5 of 5

Thread: google chrome     submit to reddit submit to twitter

  1. #1
    Sea Torques
    Join Date
    Jan 2007
    Posts
    527
    BG Level
    5
    FFXI Server
    Asura

    google chrome

    I tried asking this to the google people first but they just deleted my post without answering it. Does anyone know if Chrome is going to be vulnerable to keyloggers the way any browser sans noscript is vulnerable? Their walk through about the browser makes it sound very cool but seems to say that they have no control over plug-in applications (which i'm guessing means things like flash, realplayer, and other things we've seen exploited) other than to run them in their own tab and I'm guessing that means you're not protected?

  2. #2
    Salvage Bans
    Join Date
    Jan 2005
    Posts
    871
    BG Level
    5

    I can sorta see why they deleted your post, you basically answered your own question.



    Because flash and other stuff is independent of the browser, the exploit itself comes in through the flash content and depends on if it can infect the operating system or not. The only way to protect yourself from this is to keep Flash up to date or block it entirely via noscript or other methods.

  3. #3
    Ive sucked 27 dicks, in a row.
    Join Date
    Apr 2006
    Posts
    1,569
    BG Level
    6

    Quote Originally Posted by Hoshiku View Post
    I tried asking this to the google people first but they just deleted my post without answering it. Does anyone know if Chrome is going to be vulnerable to keyloggers the way any browser sans noscript is vulnerable? Their walk through about the browser makes it sound very cool but seems to say that they have no control over plug-in applications (which i'm guessing means things like flash, realplayer, and other things we've seen exploited) other than to run them in their own tab and I'm guessing that means you're not protected?
    #1 - There's already a thread about Google Chrome. It's the first thing that comes up when you search for "Google" or "Chrome" or "Google Chrome" on the forums. Make a little effort before you post, please.

    #2 - No web browser is 100% secure. NoScript does not make browsers 100% secure. It lowers the area of exposure, much like Google is trying to do via their browser design. If there's a security problem in NoScript itself, a way to bypass NoScript, or simply a way to get your exploit JS code hosted on an already-"trusted" domain, NoScript will not necessarily protect you. I'd imagine that if Google Chrome ends up with a good extensibility architecture, something like NoScript will be entirely possible to write. At the moment, it doesn't have that functionality by default.

    The best that web browser developers can do without writing the mythical "perfectly secure application" is to limit exposure. If a web browser process has access to information, then that information is vulnerable if the process is hijacked by malicious code. Google's multi-process design is an improvement in that regard, but no matter how you write the browser, it needs access to certain types of "sensitive" information, and any malicious code exploiting the browser can gain access to that info.

    #3 - Plugins are a security hole in every browser, because they're basically native code that the browser MUST trust in order to have them function. A big problem with that, although certainly not the only one, is that plugins are almost always binary blobs rather than auditable scripting code or open-source code. They need privileges that the programs they run shouldn't have directly, and any security hole in a plugin means that your browser is potentially compromised. There's no way for a browser maker to check how secure plugin code is, or even to know for sure what the plugins do. Obviously, the best solution depending on your needs is to either run no plugins at all, or as few as you absolutely need.

  4. #4
    DAKPluto
    Guest

    Will it be just as suspect to them? Yes, because the flaws are in the plugins and not the browser.

    All noscript/etc. does is prevent them from loading right away. If you are dumb enough to click them without having your plugin up to date, it is still going to fuck you in the ass.

    Moral of the story, keep your shit up to date and it won't matter.

  5. #5
    Sea Torques
    Join Date
    Jan 2007
    Posts
    527
    BG Level
    5
    FFXI Server
    Asura

    @ Zosi, I did check for google chrome before posting however the other thread is in the general section and as this was a technical question I felt that this was the best place to post it. Thanks everyone for the answers.

Similar Threads

  1. Replies: 1
    Last Post: 2011-04-06, 15:31
  2. Google Chrome goodies
    By Cream Soda in forum Tech
    Replies: 6
    Last Post: 2011-01-12, 00:11
  3. BG and Google Chrome
    By Tharen in forum Tech
    Replies: 5
    Last Post: 2010-02-25, 18:15
  4. Google Chrome Extensions
    By Ratatapa in forum Tech
    Replies: 3
    Last Post: 2010-02-13, 20:23
  5. Favorites Google Chrome
    By Trinsie in forum Tech
    Replies: 2
    Last Post: 2010-02-09, 21:09
  6. Google Chrome Extensions
    By Rhinox in forum Tech
    Replies: 1
    Last Post: 2009-12-17, 02:17
  7. Google chrome
    By Elites in forum Tech
    Replies: 2
    Last Post: 2009-05-02, 19:57