Microsoft Chastises Google Over Chrome Security (pcmag.com)
An anonymous reader quotes PCMag:
In a Wednesday blog post, Redmond examined Google's browser security and took the opportunity to throw some shade at Chrome's security philosophy, while also touting the benefits of its own Edge browser. The post, written by Microsoft security team member Jordan Rabet, noted that Google's Chrome browser uses "sandboxing" and isolation techniques designed to contain any malicious code. Nevertheless, Microsoft still managed to find a security hole in Chrome that could be used to execute malicious code on the browser.
The bug involved a Javascript engine in Chrome. Microsoft notified Google about the problem, which was patched last month. The company even received a $7,500 reward for finding the flaw. However, Microsoft made sure to point out that its own Edge browser was protected from the same kind of security threat. It also criticized Google for the way it handled the patching process. Prior to the patch's official rollout, the source code for the fix was made public on GitHub, a software collaboration site that hosts computer code. That meant attentive hackers could have learned about the vulnerability before the patch was pushed out to customers, Microsoft claimed. "In this specific case, the stable channel of Chrome remained vulnerable for nearly a month," the blog post said. "That is more than enough time for an attacker to exploit it."
In the past Google has also disclosed vulnerabilities found in Microsoft products -- including Edge.
The bug involved a Javascript engine in Chrome. Microsoft notified Google about the problem, which was patched last month. The company even received a $7,500 reward for finding the flaw. However, Microsoft made sure to point out that its own Edge browser was protected from the same kind of security threat. It also criticized Google for the way it handled the patching process. Prior to the patch's official rollout, the source code for the fix was made public on GitHub, a software collaboration site that hosts computer code. That meant attentive hackers could have learned about the vulnerability before the patch was pushed out to customers, Microsoft claimed. "In this specific case, the stable channel of Chrome remained vulnerable for nearly a month," the blog post said. "That is more than enough time for an attacker to exploit it."
In the past Google has also disclosed vulnerabilities found in Microsoft products -- including Edge.
Do we point out Microsoft's long and illustrious history of ignoring critical security flaws now or...
Do we just point out Chrome isn't crashing computers with their security updates, thus training their users to turn off automatic updates?
I know, I know, its not the same thing exactly. But you know what they say about people in glass houses.
Was demonstrated once more by the Equifax mega breach.
gathers G.A.Y N1GGERS from all over America and abroad for one common goal - being G.A.Y N1GGERS.
Are you G.A.Y ?
Are you a N1GGER ?
Are you a G.A.Y N1GGER ?
If you answered "Yes" to any of the above questions, then G_N_A_A (G.A.Y N1GGER ASSOCIATION OF AMERICA) might be exactly what you've been looking for!
Join G_N_A_A (G.A.Y N1GGER ASSOCIATION OF AMERICA) today, and enjoy all the benefits of being a full-time G_N_A_A member.
G_N_A_A (G.A.Y N1GGER ASSOCIATION OF AMERICA) is the fastest-growing G.A.Y N1GGER community with THOUSANDS of members all over United States of America. You, too, can be a part of G_N_A_A if you join today!
Why not? It's quick and easy - only 3 simple steps!
First, you have to obtain a copy of G.A.Y N1GGERS FROM OUTER SPACE THE MOVIE and watch it.
You can watch G.A.Y N1GGERS FROM OUTER SPACE on Youtube.
Second, you need to succeed in posting a G_N_A_A "first post" on slashdot.org , a popular "news for trolls" website
Third, you need to join the official G_N_A_A irc channel #G_N_A_A on EFNet, and apply for membership.
Talk to one of the ops or any of the other members in the channel to sign up today!
If you are having trouble locating #G_N_A_A, the official G.A.Y N1GGER ASSOCIATION OF AMERICA irc channel, you might be on a wrong irc network. The correct network is EFNet, and you can connect to irc.secsup.org or irc.easynews.com as one of the EFNet servers.
If you do not have an IRC client handy, you are free to use the G_N_A_A Java IRC client by clicking here.
If you have mod points and would like to support G_N_A_A, please moderate this post up.
This post brought to you by Penisbird , a proud member of the G_N_A_A
G_____________________________________naann_______ ________G
N_____________________________nnnaa__nanaaa_______ ________A
A____________________aanana__nannaa_nna_an________ ________Y
A_____________annna_nnnnnan_aan_aa__na__aa________ ________*
G____________nnaana_nnn__nn_aa__nn__na_anaann_MERI CA______N
N___________ana__nn_an___an_aa_anaaannnanaa_______ ________I
A___________aa__ana_nn___nn_nnnnaa___ana__________ ________G
A__________nna__an__na___nn__nnn___SSOCIATION_of__ ________G
G__________ana_naa__an___nnn______________________ ________E
N__________ananan___nn___aan_IGGER________________ ________R
A__________nnna____naa____________________________ ________S
A________nnaa_____anan____________________________ ________*
G________anaannana________________________________ ________A
N________ananaannn_AY_____________________________ ________S
A________ana____nn_________IRC-EFNET-#G_N_A_A________ ________S
A_______nn_____na_________________________________ ________O
*_______aaaan_____________________________________ ________C
Gary Niger gary_niger@G_N_A_A.us G_N_A_A Corporate Headquarters 143 Rolloffle Avenue Tarzana, California 91356
Enid Al-Punjabi enid_al_punjabi@G_N_A_A.us G_N_A_A World Headquarters No.33 Kyutei Bld. 2F, Shinjuku 2-11-7, Shinjuku-ku, Tokyo, Japan ????????2??11-6
Copyright (c) 2003-2015 G.A.Y N1GGER Association of America
Ich Bindawalross (London) - G_N_A_A (NYSE:
Good has some really good programmers, and so does Microsoft. In the past they were even more impressive.
But both of them are now process driven companies, primarily focused on not overturning the boat, and the result is code that follows process. As long as process is followed, you don't have to worry about whether you did a good job or not. Just go home at the end of the day. That is the mentality of the vast majority of mediocre programmers at both companies.
"First they came for the slanderers and i said nothing."
https://www.pcworld.com/article/2846004/microsoft-fixes-severe-19-year-old-windows-bug-found-in-everything-since-windows-95.html
Yeah 1 month is slow but GO FUCK YOURSELVES for trying to make PR out of the bugs of others LEST YOU BE FUCKED YOURSELF!
Says it has poor cleanliness standards.
Local high school basketball coach criticizes NFL team for its poor tackling form on Sunday.
While I agree with them, it should be noted that Edge is not even in the same league as Chrome.
Bugs happen. What has me worried is a month long waiting time between security fix in public facing repository and release. This pretty much asks for exploitation even by not very skilled "hackers" as interested parties have lots of time to prepare viable exploit based on provided regression tests.
I don't know of any other company that has a monthly release cycle for security updates, even for zero day bugs! Google you are evil, you should be like Micros... oh.
People who live in glass houses...
...Trying to outdo each other at finding browser vulnerabilities. Outcome : both browser become more secure.
C. Sagan : A demon haunted world:
http://www.amazon.com/gp/product/0345409469/
visit randi.org
I mean.. seriously?
I don't read AC
Well this was covered recently
Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
I wrote about this:
http://robert.ocallahan.org/20...
Summary: In practice, attackers can leverage arbitrary-write bugs to produce the same-origin violations Microsoft warns about without requiring RCE, completely bypassing the CFI mitigations Microsoft is touting here.
Just the other day, I genuinely tried to use Edge because Azure is a worthless piece of shit that didn't work at all in Firefox. I gave up. I literally couldn't use it. Unusable piece of shit. And Chrome is never even getting installed -- it's pure spyware from an evil corporation. Just worthless shit. (Not promoting Firefox in any way as it's also almost as bad.)
Microsoft desperately needs money. They are left to find bugs in Chrome to get the $1,000 award
Slashdot, fix the reply notifications... You won't get away with it...
"we set out to examine Google’s Chrome web browser .. is having a strong sandboxing model sufficient to make a browser secure?" Jordan Rabet Microsoft Offensive Security Research team
That's a bit rich coming from Microsoft. Security resides in the Operating not in the Browser. Chrome wouldn't need sandboxing if the underlying Operating System did its job. That is isolate one processes memory from the other. Something the WinTEL platform seem unable to do despite numerous iterations of the x86 processor.
I love how the original "research" article tried to spin defects in the underlying Operating System into, it's somehow the fault of sandboxing in Chrome. Sandboxing, OSR, RCE, CFG, ACG, LPAC, WDAG, all designed to protect the underlying Operating System from the browser. Microsoft, the company that fights malware with self-serving adverts masquerading as technical research.
*Bill Maher enters the stage, waits for cheering to calm down*
Bill - "Good evening ladies and gentlemen, as we've just heard from the tech community, ..."
Microsoft Chastises Google over Security
*laughter errupts* ...
We suffer more in our imagination than in reality. - Seneca
That's great, but at least Chrome doesn't take down the OS when it crashes. With Microsofts history of poor security I still trust them the least. I tried using Edge for day to day activities at work but stopped after it died and I had to reboot. After it crashed the start menu stopped working and I couldn't get to the reboot menu option. Doh.
We found something that's insecure in Chrome that Edge isn't susceptible to!
Hey, that's reason to celebrate, and use the good champagne. It's not like it happens often.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
I don't know exactly at what point Microsoft stopped sucking but they definitely have at the very least sucked more less the last couple years or so. I'm guessing it's Nadella's changes.
...as easily as I do in Chrome?
No?
Then fuck off with that.
"Oh my God. This is terrible. This is the end of my Presidency. I'm fucked."; ~ Donald J. Trump
I know people defend companies that they think can do no wrong, and trash one's they personally dislike. I take a more common sense approach that a browser of any kind can be vulnerable to a exploit at any given time. This ideal that my browser is better than yours is only relative to the time and date your saying it. I do know Edge and Chrome are no slouch when it comes to focusing on security, and just about every comparison gives both browsers good marks. Its Firefox that lately has lacked good security, and yet I wouldn't caution anyone about using it.
"He who is without sin cast the first .... something or other"
READY.
PRINT ""+-0
... yeah, that's what I thought. They can't fully secure a browser on 1 platform but they're going to call out a browser that runs on no less than 5 platforms? Amateurs.
https://www.cvedetails.com/vul...
Good people do not need laws to tell them to act responsibly, while bad people will find a way around the laws-Plato
Unless you are a teenager, please don't use the slang "throwing shade". It just makes you sound like a old person, desperately trying to appear cool by talking like a teenager.
This article brings me the first laugh of this day. Ironic, Don't you think?