Pwn2Own 2016: Chrome, Edge, and Safari hacked, $460k awarded
venturebeat.com
venturebeat.com
http://www.eweek.com/security/pwn2own-hacking-contest-return...
mentions:
"We wanted to focus on the browsers that have made serious security improvements in the last year," Gorenc said.
This claim is oft repeated, but the only reasons people seem to say it is that multiprocess + sandbox is not in release Firefox (it's in Nightly/Aurora/Beta).
That doesn't necessarily make it true. There's been some blogs since about how the JS <-> C++ sandbox has actually been significantly strengthened, but people just ignore truths that don't fit their preconceptions.
IE/Edge and Chrome also have sandboxes, and they still get cracked every Pwn2Own.
Normal people don't install development versions.
A sandbox isn't full proof, but it is way better than not having anything.
Microsoft Windows: 6
Apple OS X: 5
Adobe Flash: 4
Apple Safari: 3
Microsoft Edge: 2
Google Chrome: 1 (duplicate of an independently reported vulnerability)
Chrome is looking better each passing pwn2own. Even with the bloat and not having all the add-ins I like on FF (Self Destructing Cookies(there's Vanilla Cookie Manager it mostly works but not quite as it doesn't have access to local storage, and given how bad Chrome Download manager is - DownthemAll) it looks like it still is a good idea to compromise a bit of privacy and convenience for the sake of security.Wouldn't using Chromium instead of Chrome get around most of the privacy issues?
This also happens if you try to transfer your Chrome data from one PC to another, say when you buy a new laptop.
At least all the above happened the last time I checked it out, which is why we started recommending Firefox Portable over Chrome Portable for portable use or use on your synced could folder.
This is apparently by design to prevent third party apps from modifying your homepage, default search engine, or adding advertising to your web pages via extension.
Chrome is great, but only if you log in to your Google account and sync everything back to Google.
It was originally a misspelling of 'own' I think.
Probably accidental at first and then subsequently used mockingly to engender cavalier sloppyness as if the recipient was not worthy of the respect or fleeting seconds required to fix simple mistakes before sending the message. This etomology is now lost on most users of "pwn". People who were not around before "pwn" was ever used pronounce it differently. Generally "poned"
Tencent Security Team Sniper (KeenLab and PC Manager): 3/3
360Vulcan Team: 1.5/2
JungHoon Lee (lokihardt): 2/3
Tencent Security Team Shield (PC Manager and KeenLab): 1/2
Tencent Xuanwu Lab: 0/1
Impressive.It's unfortunate that Microsoft's security blog ( https://blogs.technet.microsoft.com/srd/ ) rarely posts EMET success stories. Is it not that effective?
Removing logic errors might be possible with formal methods, but even those can contain false premises.
Actually I understand what you are saying. Showing the list that way is kind of unfair.
Also, Firefox installs generally still come with Flash which is easier to exploit than the browser itself, and reaches a broader audience.
Officially, they claimed its because "Firefox security has not advanced in the last year" but that is just utter BS.
(A few months older than one year, but close enough. Also, of course I'm not going to claim that sandboxing is unimportant.)