Chrome Throws Flash Into the Sandbox
wiredmikey writes "Google announced today that it will be extending Chrome's sandboxing technology to include the Flash Player plug-in. 'Sandboxing' technology is a method of isolating an application from the rest of the operating system and tightly controlling its resources. According to Google, the new sandboxing feature adds an additional layer of protection and will help protect users against malicious pages that attempt to hijack systems or steal information from the system."
You have to run it on a completely different machine. Can't get much more secure than that.
In case you missed it, the Chromium Blog talked about this in their December 1st blog entry.
GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
After all, I already run Chrome itself in a sandbox. Firefox, too. Why?
Pretty much every exploit now begins by "the user visits a website". After that, pretty much any technology can be the hole it exploits - Java, Flash, PDF viewing, even JPEG rendering has been exploited. There's an abundance of targets. The modern browser is just too big a platform to secure completely. So, I don't trust any browser more modern than Lynx.
Yes, they mentioned it earlier, today it appears to actually be in action and built into the latest beta of the product.