Results 1 to 8 of 8

Thread: Microsoft Discloses Chrome Security Bugs, Turning the Table on Google

  1. #1
    #DeSantis2024 Teh One Who Knocks's Avatar
    Join Date
    Jan 2011
    Location
    5280' Above Sea Level
    Posts
    256,055
    vCash
    10966
    Mentioned
    20 Post(s)
    Thanks
    23,819
    Thanked 113,101 Times in 59,908 Posts

    Windows Microsoft Discloses Chrome Security Bugs, Turning the Table on Google

    Microsoft kicked off its vulnerability disclosure policy for non-Microsoft products with two security reports covering products made by Google.
    By Jon Brodkin, NetworkWorld




    Google has a habit of telling the world when it finds a security problem in Microsoft software. The officials in Redmond like to wring their hands and complain about Google putting Microsoft customers at risk, but eventually they just acknowledge the bugs and fix them as best they can.

    But there's nothing stopping Microsoft researchers from poking through Google software and finding bugs of their own. And that's just what they're doing now, announcing a new vulnerability disclosure policy for non-Microsoft products, and kicking off the program with two security reports covering products made by none other than Google.

    Both security reports affect the Chrome browser. Google likes to brag that its sandboxing method keeps users safer than they would otherwise be in Internet Explorer. But no browser is bullet-proof and Microsoft wants Web surfers to know that Chrome has problems of its own.

    In the previous Google/Microsoft dustups, Microsoft has complained that Google didn't give enough warning to Microsoft before disclosing vulnerabilities publicly, while Google officials protested that they had given Microsoft plenty of time and that the company dragged its feet.

    Microsoft is making it clear in its security reports that it discussed them with Google before going public, and in fact says that Google has already fixed the security bugs Microsoft is disclosing. Coputerworld reports that the security holes were fixed by late last year, and a Google spokesperson tells me via e-mail "these issues are actually quite old" and were covered in Google announcements in September and December.

    So from that perspective, the bug reports don't seem all that groundbreaking. But on to the specific Chrome problems. Microsoft's new bug report MSVR11-002 says the "HTML5 implementation in Chrome and Opera could allow information disclosure."

    "An information disclosure vulnerability exists in the implementation of HTML5 in these Web browsers [Chrome and Opera]," Microsoft says. "Specifically, as the World Wide Web Consortium (W3C) describes in the HTML5 specification for security with canvas elements, information leakage can occur if scripts from one origin can access information from another origin."

    The other bug report says a vulnerability in Chrome "could allow sandboxed remote code execution."

    "A sandboxed remote code execution vulnerability exists in the way that Google Chrome attempts to reference memory that has been freed," Microsoft said. "An attacker could exploit the vulnerability to cause the browser to become unresponsive and/or exit unexpectedly, allowing an attacker to run arbitrary code within the Google Chrome Sandbox. The Google Chrome Sandbox is read and write isolated from the local file system which limits an attacker."

    There are limitations to both of these threats. The HTML5 vulnerability for example, requires attackers to "possess the IP address of the network resource that contains the private information." And in the case of the sandboxing risk, "Successful exploitation of this vulnerability does not allow for code to run outside of the Google Chrome Sandbox, which is read and write isolated from the local file system, although other attacks may be possible."

    These are just the first bug reports affecting third-party software we're seeing from Microsoft, so it will be interesting to see which other vendors might fall in Microsoft's cross-hairs.

    But Microsoft is proceeding cautiously. Google researchers on occasion seem to act alone, with no involvement from higher-ups. But Microsoft is dictating standards to its employees for how they can report vulnerabilities, and waiting until the bugs are fixed before disclosing them publicly, at least in these first examples. Still, a shift is evident. After years of being put on the defensive by security researchers pointing out holes in Microsoft software, the hunted has become the hunter.

  2. #2
    Shelter Dweller PorkChopSandwiches's Avatar
    Join Date
    Jan 2011
    Posts
    77,135
    vCash
    5000
    Mentioned
    15 Post(s)
    Thanks
    47,197
    Thanked 29,255 Times in 16,489 Posts
    Grasping at straws

  3. #3
    #DeSantis2024 Teh One Who Knocks's Avatar
    Join Date
    Jan 2011
    Location
    5280' Above Sea Level
    Posts
    256,055
    vCash
    10966
    Mentioned
    20 Post(s)
    Thanks
    23,819
    Thanked 113,101 Times in 59,908 Posts
    I think it's funny...if I was running Microsoft I would have had my programmers doing this a long time ago. Everyone tries to gang up on MS by finding security flaws in their software, so I'd be doing the same to everyone that makes software that runs on Windows.

  4. #4
    Shelter Dweller PorkChopSandwiches's Avatar
    Join Date
    Jan 2011
    Posts
    77,135
    vCash
    5000
    Mentioned
    15 Post(s)
    Thanks
    47,197
    Thanked 29,255 Times in 16,489 Posts
    It is funny, but that's what happens when you're the top dog. Same reason you dont see viruses developed for Apple, Apple fans will try to tell you its because Apple is so fucking fantastic its immune to viruses. The reality is, they have less then a 5% market share compared to a PC. So why would anyone bother You got to go after the top dog for maximum results.

  5. #5
    #DeSantis2024 Teh One Who Knocks's Avatar
    Join Date
    Jan 2011
    Location
    5280' Above Sea Level
    Posts
    256,055
    vCash
    10966
    Mentioned
    20 Post(s)
    Thanks
    23,819
    Thanked 113,101 Times in 59,908 Posts
    Oh I agree with you 100%....if people really wanted to go after Apple, there would be just as many viruses for it as there are for Windows. The fanboys just don't wanna believe it because they are in love with crApple

  6. #6
    Shelter Dweller PorkChopSandwiches's Avatar
    Join Date
    Jan 2011
    Posts
    77,135
    vCash
    5000
    Mentioned
    15 Post(s)
    Thanks
    47,197
    Thanked 29,255 Times in 16,489 Posts

  7. #7
    Hal killed Tormund! Pony's Avatar
    Join Date
    Jan 2011
    Location
    Borneo
    Posts
    17,296
    vCash
    2000
    Mentioned
    7 Post(s)
    Thanks
    7,298
    Thanked 7,742 Times in 4,207 Posts
    Quote Originally Posted by PorkChopSandwiches View Post
    It is funny, but that's what happens when you're the top dog. Same reason you dont see viruses developed for Apple, Apple fans will try to tell you its because Apple is so fucking fantastic its immune to viruses. The reality is, they have less then a 5% market share compared to a PC. So why would anyone bother You got to go after the top dog for maximum results.
    That and there isn't nearly as much third party software for Apple products. They don't want you installing any non-apple apps on their devices. Fact is at the hacker convention every year Mac is always the first system to be compromised, usually in less than a couple minutes.

  8. #8
    Dilly dilly Goofy's Avatar
    Join Date
    Jan 2011
    Location
    On the oche
    Posts
    52,011
    vCash
    5200
    Mentioned
    124 Post(s)
    Thanks
    6,061
    Thanked 13,156 Times in 6,846 Posts
    I bought an apple today........... it was quite tasty

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •