Or maybe it was never really secure and it was just good marketing?
Or maybe it was never really secure and it was just good marketing?
I think it’s also partly Google’s very open culture on CVEs that means they are discovered and reported on promptly. It’s difficult to tell how much it’s just increases awareness that browsers are full of holes and whether the holes are increasing in size/frequency tbh.
I would say there were three trends that happened at the same time that really made a difference:
- People now actually update their web browser, and yes, started to ignore the browser vendor that wasn't shipping them (IE). Driveby download exploits started to disappear.
- Flash and Java went from enabled by default to prompt-first. Flash was later abandoned, and IcedTea-Web / Java Web Start had its core functionality gutted in later Java versions.
- No support for ActiveX at all, unless you wanted to go for IE Frame (Chrome and IE tabs under a Chrome interface) or Chrome Frame (IE and Chrome tabs under an IE interface), which quickly faded into corporate Intranet obscurity
All three saved us from a much worse future.
However, Chrome is an operating system unto itself. It's more than 40 million lines of code comprising of complex intertwined systems. It's a miracle there are so few CVEs
So the code is running in a process that runs as the same user running the browser. That's no longer much of a sandbox and you're now relying on the OS to protect your data, right?
https://chromium.googlesource.com/chromium/src/+/HEAD/docs/d...
> If successful, on Ubuntu 22.04, it should call launch xcalc when calc.html is opened in Chrome.
Then how does this work? It doesn't look like the provided build flags disable any sandbox that the distributed build doesn't.
Who in their right mind thinks it makes sense to have a desktop screen sharing system... built into a browser?