How Google set a trap for Pwn2Own exploit team
zdnet.com
zdnet.com
This is hardly an impossible feat.
Don't use it.
> So, if we stopped including Flash, the vast majority of our users would be more vulnerable than they already are.
Prompt to use a specific Flash when the user requests it.
If Chrome didn't bundle a modified version, and prompted the user to select a Flash version, the only one they could offer would be the system one.
Unless you're saying that the Chrome team should go to all the effort to build a custom version of flash, but only deliver it to Chrome browsers when the user specifically requests it? That strategy seems DOA from a cost/benefit analysis perspective.
Edit: Never find what I'm looking for in chrome settings... It's in Options -> Under the hood -> Content settings... (or just chrome://settings/content ) and then you can enable click-to-play under plugins.
Thanks!
I disable plugins in Chrome and either whitelist sites or run them as-needed.
Flash is on life support, and I don't see a way back for it.
Flash is certainly has less of a monopoly on "interactive web content" than it once did, but it still fills an extremely important and currently unreplacable role on the web. To be ringing its death toll just yet is premature.
We're making progress in that direction, but it's going to be years before there's a significant dent made.
They aren't fooling anyone. It's Google's problem.
Isn't the nacl+pepper flash rewrite effectively the result of doing a bit of all three?
Link? I haven't heard anything about this.
1) Google contributes tons of security fixes to Flash. 2) Google announced they will rework Linux Flash to use PPAPI and make it Chrome only. Adobe seems to have abandoned Linux Flash entirely. Logical conclusion is what Google will do this themselves - and they'll need the source code for that. 3) Android shipped with Flash and Google pushed it as a major feature over iOS. This also points to strong collaboration. Android had Flash very early - much earlier than Adobe could have done it themselves.
I admit I was also trolling here to see if one of the Google security guys (who already posted in other threads regarding this) would bite and deny it - in which case I have an indication to the contrary :-)
Google's Chrome team has full access to Adobe's Flash code. The Chrome team maintains their own Flash builds and releases. That's how they can do things like Pepper, even if Adobe doesn't care about Pepper for other platforms. There have been news stories about Chrome updating their Flash a day or two before Adobe, thus revealing security holes in other browsers' Flash.
Google's Android team, for mysterious lawyery reasons, does not access to any Flash code. Adobe had an army of 10-20 engineers and QA working exclusively on Flash for Android. (This is yet another example that Android's device fragmentation is an expensive problem and requires lots of manpower.)
BTW I have to agree if vulnerable flash is included in default installation of chrome that is essentially the same thing as pwning chrome.
Apparently it was not effective in the end, but we may never know, since VUPEN doesn't plan to disclose how they escaped the Chrome sandbox.
Who knows, Unity3D will substitute it for games, HTML5 Video /Sound for playing videos. While that happens, we will soon realize that Unity3D is another plugin-in-browser solution and might be (and I am just speculating here) vulnerable to issues similar to flash; while content providers will stop pushing video content because of lack of DRM like technology with HTML5 Videos. Please note that I am NOT supporting/rejecting any of the mentioned technologies; this is just a reply to a straw man argument.
But the lack of applets is pretty apparent to me. I come across Flash almost hourly while my last few encounters with Java Applets were academic demos 2 years back.
http://src.chromium.org/viewvc/chrome?view=rev&revision=...
The change causes a specific exception when a style of attack known as a JIT spraying attack is detected. The exception generates a minidump which is uploaded to Google's crash servers.
Further info:
The claims of it backfiring in the other comments only make me more uneasy about all this. I hope they gave a good thought about a 'user first and cute tricks later' mentality. Don't put 200 million+ users into the crossfire. Or maybe all this is not a big deal at all.
Then he takes your stuff anyway.
On second thought, this is like a software vendor including a knowingly-insecure program with their product and then discounting exploits because they used that included program.