Wednesday January 7, 2009 1:45 AM AEST
Latest Comments
"Discontinuing the issuance of MD5 certs is a good first step, but the real problem is that the ..."
by Scott | Jan 6, 2009 3:13 PM
 
"ineed nokia 6120c-1"
by Dipak Ahikari | Jan 6, 2009 2:04 PM
 
"My facebook profile has been hacked through one of these sites and they have changed my password ..."
by Ryan geen | Jan 3, 2009 3:51 PM
 
"http://impresser.com.au/category/security/ We need more websites like this. Security is an ..."
by Andrew Galdes | Dec 27, 2008 3:46 PM
 
"Um... what product were you really using???? documentation is supplied in printed form (aka a ..."
by Glen | Dec 23, 2008 12:11 PM
Web

Close tabs for safe browsing in Chrome

  • Email a Friend
  • Print Page
Close tabs for safe browsing in Chrome
By Negar Salek
Sep 9, 2008 3:02 PM | 1 Comment
Tags: Google | Chrome | sandbox |
Sandboxing processes in tabbed browsers – as seen in Chrome - is great for security, as long as users understand how to use the technology, a security expert has warned.

Randy Abrams, director of Technical Education at ESET, said Google is on the right track with Chrome's isolation of tabs featuring their own sandbox. However he warned that people need to understand how it actually works.

“If people don’t understand that a sandbox is really best used as a one shot environment - empty out that sandbox, before you go to something important - sandboxing benefits are mitigated,” warned Abrams.

According to Abrams, the average user is going to use the same tab for many things which defeats the purpose of a sandbox.

“If the user goes to a compromised webpage and malicious software is downloaded, then in that same tab they go to their bank it doesn’t matter that you’re in the sandbox. “You’re playing in the same sandbox and your money is not going to be safe there,” said Abrams.

Google launched a beta version of its inaugural web browser, Chrome, last week where it introduced sandboxing for individual tabs and their corresponding processes.

According to Google, the goal of sandboxing is to prevent malware from installing, while also isolating tabs from any adverse affects in other open tabs.

“We’ve taken the existing process boundary and made it into a jail. That means no watching you type your credit cards and no telling Windows to run an executable at start up," Google wrote in an explanatory guide book.

It’s really good that there are some new security things coming out in browsers, but as we’ve seen cars evolve over the years, they have much better safety [but] it doesn’t prevent fatal accidents," said Abrams.



 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
This seems all well and good for someone who is actually paying attention and is going to follow the rules, however most people are still struggling to use their email let alone remember that they can only use one tab for each site they want to go to. A real security innovation would create a secure sandbox without the user having to learn yet another new thing because that's simply not going to happen.
SC Magazine - comments icon Posted by uglymogySep 9, 2008 4:23 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers