Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Chrome's based on the OP browser, SFI/CFI, and segments for POLA that came out of my side of the field. They weakened those security models to get extra performance because the good stuff had up to 50% hit on your favorite architectures. The result was plenty of breaks in their model despite its clever design. I did cite them as an example of mainstream trying to leverage proven techniques and they did get best paper in 2009 for the attempt. Just got unacceptably weakened.

Meanwhile, there's DARPAbrowser, OP2, Gazelle, Tahoma, Illinois Browser OS, my scheme of running it in a microkernel partition behind guard functions, old scheme of dedicated box with KVM for switching, compiler transformations, diversification, and so on. These are all either browsing schemes more secure than Chrome or ways to better prevent/contain damage of arbitrary apps than popular methods. I've been posting these on forums for some time now. Strong, INFOSEC research certainly builds & evaluates browser architectures. Only around 6 groups making attempts & no help from the mainstream, as usual. They will do occasional knockoffs with less security (i.e. Chrome). IBOS has a nice table [1] showing what containment Chrome achieved vs their which leveraged Orange Book B3 methods. You'd have lost the bet.

[1] https://www.usenix.org/legacy/events/osdi10/tech/full_papers...



Do any of these secure browsers have JavaScript?


They're all prototypes illustrating better security architectures. Such work often doesn't have all functionality included. Nonetheless, these support JavaScript: OP1 & OP2 web browsers; Microsoft's Gazelle; Tahoma; IBOS; my two kludge solutions I mentioned. So, all of them except the DARPAbrowser which was just a demo for Combex's methods. Papers below on on their architectures, security analysis, and performance evaluation if you're interested.

Far from "use it now," I'm advocating that they illustrate the difference between strong security design and mainstream while providing something to build on. My claim is building on stuff like this would reduce impact of hackers vs popular browsers. Many trusted components can also be built to medium or high assurance because they're simpler.

DARPAbrowser demo http://www.combex.com/tech/darpaBrowser.html

Designing and Implementing the OP and OP2 Web Browsers http://web.engr.illinois.edu/~kingst/Research_files/grier11....

Multi-principal OS Construction of Gazelle Web Browser http://research.microsoft.com/pubs/79655/gazelle.pdf

Tahoma - A Safety-oriented Platform for Web Applications http://homes.cs.washington.edu/~gribble/papers/gribble-Tahom...

Trust and Protection in the Illinois Browser Operating System https://www.usenix.org/legacy/events/osdi10/tech/full_papers...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: