Showing posts with label chrome. Show all posts
Showing posts with label chrome. Show all posts

Monday, February 7, 2011

Chrome 9: Faster 3-D Graphics, Instant Search and an App Store



Google has updated the stable channel of its Chrome web browser. This release is technically labeled Chrome 9, though Google ceased focusing on version numbers some time ago, opting for a rolling, every-six-weeks update schedule.
If you’d like to take the latest version of Chrome for a spin, head over to the Chrome downloads page. If you’re already using Chrome, the update will arrive automatically.
If you’ve tested the beta release of Chrome 9, there won’t be anything new to see in this update. But for those that prefer to stick with the stable channel, Chrome 9 brings several features from the beta channel to prime time — notably, support for 3-D WebGL hardware acceleration. This release also adds support for the new Chrome Web Store, and Chrome Instant, a tool that loads web pages as soon as you start typing in the URL bar.
WebGL, which was originally developed by Mozilla, acts as a bridge between the browser and the desktop hardware acceleration tool OpenGL. The WebGL project gives web developers a way to connect the HTML 5 Canvas tool, which can be used to display complex graphics in the browser without plug-ins like Flash, to the operating system’s native, hardware accelerated graphics engine — in this case, OpenGL. The result is much improved performance for 3-D apps on the web. Google notes a couple of demos you can try out, the Google Body experiment in particular does a nice job of showcasing the power of WebGL.
This release is also notable for being the first stable version of Chrome to include access to the new Chrome Web App Store (U.S. users only). To check it out, just click the new link on the New Tab page.
Chrome Instant mimics Google’s instant search feature when you type a search in the URL bar. If you type a web address, Chrome Instant will start loading the page as you type, which makes getting to your favorite sites a bit faster. The only catch is that Chrome Instant is disabled by default. To turn it on, head to the “basic” tab on Chrome’s preferences page and check the “Enable Instant” option under Search.

Saturday, February 5, 2011

Pwn2Own 2011: Google offering $20,000 for Chrome sandbox exploit

By Ryan Naraine

Google is offering a $20,000 cash prize for any hacker who can successfully compromise a Windows 7 machine via a vulnerability — and sandbox escape — in its Chrome web browser.
The prize is part of this year’s CanSecWest Pwn2Own contest, which will pit some of the world’s best security researchers and exploit writers against popular web browsers and mobile devices.   During last year’s contest, Google Chrome was the only browser left standing but with the enhanced cash prize — and publicity that goes along with a successful Chrome netbook hack — there is a strong likelihood that someone will take aim at Chrome this year.
According to TippingPoint ZDI, the contest sponsor, a successful Chrome hack “must include a sandbox escape,” which means that a privilege escalation vulnerability may have to be combined with another security hole to cause full system compromise.

[ Pwn2Own 2010: iPhone hacked, SMS database hijacked ]

Kernel bugs and plugins other than the built-in PDF support are all out of scope for Chrome, TippingPoint ZDI said.

follow Ryan Naraine on twitterAs is customary, the CanSecWest conference organizers are offering cash prizes for researchers who use zero-day (unpublished) browser flaws to remotely launch code against a 64-bit Windows 7 or Mac OS X machines.
This year the web browser targets will be the latest release candidate (at the time of the contest) of the following products:
  • Microsoft Internet Explorer
  • Apple Safari
  • Mozilla Firefox
  • Google Chrome
TippingPoint ZDI says Each browser will be installed on a 64-bit system running the latest version of either OS X or Windows 7.

Hacker exploits IE8 on Windows 7 to win Pwn2Own ]

On the mobile device side, the 2011 Pwn2Own contest organizers have increased the attack surface to allow attacks against the cell phone basebands.
The targets this year are:
  • Dell Venue Pro running Windows 7
  • iPhone 4 running iOS
  • Blackberry Torch 9800 running Blackberry 6 OS
  • Nexus S running Android
TippingPoint ZDI says a successful attack against these devices must require little to no user interaction and must compromise useful data from the phone. Any attack that can incur cost upon the owner of the device (such as silently calling long-distance numbers, eavesdropping on conversations, and so forth) is within scope.
UPDATE:
In response to some criticisms from security researchers on Twitter, the conference organizers have modified the Google Chrome portion of the contest to offer different prizes for security holes in Google-written code and other non-Google code.
Here’s the change:
On day 1, Google will offer $20,000 USD and the CR-48 if a contestant can pop the browser and escape the sandbox using vulnerabilities purely present in Google-written code. If competitors are unsuccessful, on day 2 and 3 the ZDI will offer $10,000 USD for a sandbox escape in non-Google code and Google will offer $10,000 USD for the Chrome bug. Either way, plugins other than the built-in PDF support are out of scope.