New graphics engine imperils users of Firefox and Chrome
theregister.co.uk
theregister.co.uk
On the other hand, if it's ever going to happen, it will probably take a few embarassing public incidents to make the vendors change their priorities.
http://hackademix.net/2010/03/24/why-noscript-blocks-web-fon...
"It really worries me that the FreeType font library is now being made to accept untrusted content from the web. The library probably wasn’t written under the assumption that it would be fed much more than local fonts from trusted vendors who are already installing arbitrary executable on a computer, and it’s already had a handful of vulnerabilities found in it shortly after it first saw use in Firefox."
10 years ago we had similar issues with 2d graphics. For example, rendering huge fonts could cause the X display server to crash: http://xforce.iss.net/xforce/xfdb/9313
With WebGL, the attack surface is many times larger. I'm sure we'll see plenty of exploits leveraging vulnerabilities in the display subsystem.
Wow, this should do a nice job of confusing everyone.
Is this going to be the standard post for every Chrome fix from this point forward? The only people who we know for sure would know ain't talking. ;)
http://www.opengl.org/registry/specs/ARB/robustness.txt
Apparently it does the same thing for OpenGL that strncpy does for strcpy.Of course, it was sillier not to write "strcpy" as strcpy(dest,maxSize,src) from the beginning. And "memcpy" as memcpy(dest,maxSize,count,src). But I guess whoever wrote those weren't really expecting them to be one of the most frequently used functions in computer programming history...
If you want to be safe, use Links on OpenBSD. If you want to browse the web in style, use Chrome and Firefox.
Hm, I think the point is that some features are worse than others (larger attack surface, more bugs exposed), and WebGL is particularly bad.
whistles innocently
Now I want to write an operating system and name it "Debyan".