Zero-Days in Desktop Web Browsers
radsix.com
radsix.com
The only way to stop it is to not use a browser that thinks it's an OS. That means not being able to use websites that use new OS features like web components, webgl, etc. It means not using these features as web dev unless you're forced into it by getting paid. Browsers that treat the web as a document instead of an application will have far, far fewer remote exploits.
When you use those features only when you're a web dev, not only you're actually using them anyway (which defeats the purpose by driving demand), but you also increase supply by creating new websites of the kind.
Also, if you not use the websites "that think they're an OS", you're ending up not being able to function in today's world to an increasing extent. e-governments are all about web applications, often with "bare metal functionality" such as legacy Java, ActiveX or Flash applets. They should be long gone, but given that somebody pumped millions into them, it will take them years to go away.
Hell, even regular JS is bare metal today with all the complexity of JIT. I'm getting the impression that suggesting to go away from this realm is naive and a better solution would be to look at it from the perspective of "OK, it happened. How can we make it more secure?".
After all, becoming an OS isn't an excuse to doing less. In fact, browsers now have more responsibility to keep their security philosophy up to date.
I actually like and use webrtc, but only for actual RTC, otherwise it's a shitshow and disabled.
Some things are indeed useful, but I don't see how you go OK, it happend, time to make it secure - with an ever expanding scope and attack surface. Note - "more secure" is not enough, we need secure.
I got the impression from your post that you're willing to join the crowd that's never willing to turn on JS etc. If it's just about reading the newspaper, you can pick a less invasive data data source. But, say, for e-government, you really don't have a choice and given that all those things are already standard and can be used for good purposes, I guess we really have no option other than isolating those features the best we can.
If your bottom line is "features should only be available when there's a legitimate use case for them", perfect. The problem is when there's a major website and you don't know why it's working, but you turned off entire JS stack and it can't even tell you that.
What are "all those things" that "are already standard"? And why should a rando government or other site requiring an API mean it should be available to all websites everywhere?
Note, I didn't even mention javascript nor disabling it altogether, and I don't wish to imply we shouldn't secure any and all APIs/features.
I'm saying (1) we will never secure all APIs/features; (2) they are ever growing so it would be futile even if we could secure the present ones; (3) even if all the APIs are "secure", they will be misused against users, so they should not be available by default like they currently are; (4) yes, I do think static/simple sites should be usable without JS.
I used to think of Stallman's browsing habits as silly, but there may come a time where I will visit the web-at-large only from other people's or dedicated-use devices.
While I see your point it seems to me that ship has sailed many years ago, perhaps from the point where Chrome’s OS like kernel/module based architecture was accepted as something to strive for, and browser were deemed secure and fast enough to be pitched as an alternative to native applications.
The answer is some, with degraded functionality and layout if you don't support yesterday's CSS and JS
For my part, I attempt to support every browser in existence, and laegely succeed.
Bonus: Was responsible for IE3 tag being added to StackOverflow.
HTML is a language that is too ambiguous to parse, and that's not a good thing for browsers. HTML should be adapted to mobile so it can work faster, use less memory, etc. Something with vector graphics should be a better norm.
Wouldn't that be XHTML? Which was killed by HTML 5?
I'd actually agree.
> Something with vector graphics..
And I'm wary of the idea, because it would probably end up as wasm on webgl, with websock and input via webusb, while banning HTTP, HTML and CSS, yet somehow still require javascript.
Perhaps you like browsing pure html documents to view websites. Everyone else prefers current gen browsers despite the rare risk.
See https://chromium.googlesource.com/chromium/src/+/master/docs... for details.
Interesting quote: "(Some of us on Security Team aspire to get more of Chromium in safer languages, but that's a long-term, heavy lift.)"
It's a big job, and it's going to take a while, but better, safer programming is possible.
Turns out "Rewrite it in Rust" is actually really hard when you have millions of lines of code. Even Google probably can't rewrite Chrome from scratch.
Maybe if we just try harder, communism will work. You gotta draw the line somewhere.
That sounds like job security for those employed in "computer security".
I use a text-only browser. Nine times out of ten, that's all I need to get the content I want.
I do not use Windows but "Nessie" looks interesting. Someone posted about this browser a few months ago and commenters crticised it for not being open source. It appears the source is now available:
https://www.radsix.com/download.php?appname=nessie_source.zi...
Sometimes they're appropriate (e.g. ability to drag-and-drop or CTRL+V paste a photo to an image sharing site), but as a user my personal inclination tends toward traditional interfaces (which as a happy bonus can be more responsive) and I've encountered an overwhelming number of sites that abuse capabilities for no good reason (e.g. those which immediately prompt for your location).
A little taste and restraint would be very welcome on the modern web.
If I understand this correct this is looking at CVEs where exploitation has happened as announced by the vendor. It's bad statistics, because you cannot assume all vendors tread these things equally (one vendor may be very open about known exploitations while another may try to hide stuff as much as possible). Creating such statistics also creates an incentive for vendors to be more secretive if such things happen, so it's not just bad statistics, it's also bad for security.
I suspect sample sizes are too small to really make strong claims about which browsers are least/most exploited.
Because in that case I disagree: a 0-day is an important event, every single one counts. It's like nuclear bombs: statistically, it indeed makes no sense to say "amount of employed nukes per capita" or so, but it still makes sense to say "The US employed the most nuclear bombs" and "Japan has seen the most nuclear attacks on it's citizens".
Or am I missing your point entirely?
I would also point out that the website is only tracking vulnerabilities in the last 2 years. I bet IE's number would go way up if you included IE6 (not that that would mean anything). I suppose you could also say that "Japan has seen the (tied for) least nuclear attacks on its citizens in the last 2 years", but i'm not sure what the point would be.
And I'm pretty sure chrome actually is the most "dangerous" browser wrt 0days. If they're going to exploit them, it's surely going to be the one with the largest market share.
But yes, the quantity of bugs doesn't necessarily translate to the actual security of the browser.
Has a zero day in a web browser directly resulted in anyone’s death?
Proving that A is worse than B does not prove that A is good or that B is bad. Or, if you are more mathematical: a > b does not prove that b < 0 or a > 0, where 0 is neutral.
And as I point out above: this was not meant as comparison but as analogy. If my analogy affected anyone, I sincerely apologise.
Patients have died in ransomware attacks. Not half a million patients or even a quarter million but still, a browser zero day can be a threat to human life.
There was 150,000 + 200,000 reported deaths. Those are also rounded figures. So 350,000.
I don’t know how many people are in hospitals with life threatening conditions but I suspect it is more than a quarter million, or even half.
Based on personal experience in deskside hospital IT browser vulnerabilities are a significant vector. We spent a lot of time re-imaging machines.
There have been ransomware attacks at hospitals including deaths. A coordinated attack using this vector could easily cause as many deaths as nuclear weapons have.
https://en.m.wikipedia.org/wiki/Atomic_bombings_of_Hiroshima...
https://www.washingtonpost.com/national-security/hospitals-b...
Let's take your analogy a step further. Does it follow that the US is the most likely to be the next user of nuclear weapons? Does it follow that Japan is most likely to be the next target? (I'm sure someone is thinking that at least one of those outcomes is quite likely, but note that I wrote "does it follow...", not "how likely is it..." because the issue is what one can deduce from the evidence presented in the above post.)
https://zerodium.com/program.html
Chrome bugs are currently selling for $500k and Firefox/Edge bugs are selling for $100k. It's kind of shocking that we got to this point, but for comparison, a full Chrome exploit sells for the same amount as a full exploit for IIS or Apache. Firefox and Edge sell for the same price as a full exploit in Wordpress.
This is a great way to measure "attacker utility". That is, it's not only a measure of how rare some of these bugs are, but how useful they are to attackers.
Chrome bugs have been significantly more expensive than IE bugs since long before Chrome overtook IE in popularity. For a while, Firefox bugs and Chrome bugs we neck and neck, because even though it was easier to find exploitable bugs in Firefox, the Intelligence Community was buying up Firefox bugs like mad in order to exploit Tor users, since Firefox is the underlying tech behind the Tor browser.
> edge 5.83%, IE 2.15%
It's not unexpected that people don't spend lots of time on IE 0days. I mean, Links was the least exploited one with 0 cases.
(I will use C/Assembler if I'm coding something for an C64, Amiga or a 4k/64k demoscene intro but I'm not gonna put up a server written like that on the internet for people to exploit)
But there is a positive side to it, where would the anti-virus, hardware memory tagging and security consultancy companies be without languages like C, there is a market to keep alive out there.
Selling laptops with 128 cores and 1TB RAM?
Type safe systems programming exists since 1961.
- Many of the vendor advisory links are pointing to the wrong place (most of the Firefox ones and at least 2 of the IE ones to start).
- The starred note on Hardened IE says "4 out of the last 5" when it means "3 out of the last 4".
(Never mind that comparing counts of CVEs is a ridiculous way to compare security of products. CVE counts seem more indicative of the amount of research targeting the product than of the number of bugs in the product.)
And considering Safari is not by a longshot the most popular browser, what does this say about Apple?
Als Safari signals you are a high value target, so a Safari zero-day is generally worse for Safari users than say a Chrome zero day.
I'm sorry, I can't take this site seriously.