Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
ASRock Z590 Extreme review
Gigabyte Radeon RX 6700 XT Gaming OC review
Corsair K70 RGB TKL keyboard review
Corsair RM650x (2021) power supply review
be quiet! Silent Loop 2 280mm review
Corsair K55 RGB PRO XT keyboard review
Guru3D Rig of the Month - March 2021
Intel Core i9-11900K processor review
Intel Core i5-11600K processor review
ASUS ROG Maximus XIII HERO review

New Downloads
GeForce 466.11 WHQL driver download
Guru3D RTSS Rivatuner Statistics Server Download 7.3.2 Beta 2
MSI Afterburner 4.6.4 Beta 2 Download
HWiNFO Download v7.02
Intel HD graphics Driver Download Version: DCH 27.20.100.9316
Corsair Utility Engine Download (iCUE) Download v4.9.350
Quake II RTX Download 1.5.0
GeForce 465.89 WHQL driver download
AIDA64 Download Version 6.33
AMD Radeon Adrenalin Edition 21.3.2 driver download


New Forum Topics
NVIDIA Indicates GPU shortages to last for the bigger part of the year GeForce 466.11 WHQL driver download & discussion Intel Core i5-11600K processor review GeForce 466.11 WHQL driver download Windows 10 20H2 (Build 19042.508) NVIDIA Announces Grace CPU for Giant AI and High Performance Computing Workloads 3090 Owner's thread Doom Eternal bad performance Resizeable BAR support issues AMD Radeon Adrenalin Edition 21.3.2 driver download & discussion




Guru3D.com » News » Chrome version 67 Add on Site Isolation as standard for protection against Spectre

Chrome version 67 Add on Site Isolation as standard for protection against Spectre

by Hilbert Hagedoorn on: 07/15/2018 08:14 AM | source: Google | 41 comment(s)
Chrome version 67 Add on Site Isolation as standard for protection against Spectre

Ever since the Intel processor vulnerabilities got exposed, Google has been working hard to to protect the Chrome browser against security vulnerabilities. The company now achieved a final solution, by implementing a function called Site Isolation.

-- Google -- Speculative execution side-channel attacks like Spectre are a newly discovered security risk for web browsers. A website could use such attacks to steal data or login information from other websites that are open in the browser. To better mitigate these attacks, we're excited to announce that Chrome 67 has enabled a security feature called Site Isolation on Windows, Mac, Linux, and Chrome OS. Site Isolation has been optionally available as an experimental enterprise policy since Chrome 63, but many known issues have been resolved since then, making it practical to enable by default for all desktop Chrome users.

This launch is one phase of our overall Site Isolation project. Stay tuned for additional security updates that will mitigate attacks beyond Spectre (e.g., attacks from fully compromised renderer processes).

What is Spectre?

In January, Google Project Zero disclosed a set of speculative execution side-channel attacks that became publicly known as Spectre and Meltdown. An additional variant of Spectre was disclosed in May. These attacks use the speculative execution features of most CPUs to access parts of memory that should be off-limits to a piece of code, and then use timing attacks to discover the values stored in that memory. Effectively, this means that untrustworthy code may be able to read any memory in its process's address space.

This is particularly relevant for web browsers, since browsers run potentially malicious JavaScript code from multiple websites, often in the same process. In theory, a website could use such an attack to steal information from other websites, violating the Same Origin Policy. All major browsers have already deployed some mitigations for Spectre, including reducing timer granularity and changing their JavaScript compilers to make the attacks less likely to succeed. However, we believe the most effective mitigation is offered by approaches like Site Isolation, which try to avoid having data worth stealing in the same process, even if a Spectre attack occurs.


What is Site Isolation?

Site Isolation is a large change to Chrome's architecture that limits each renderer process to documents from a single site. As a result, Chrome can rely on the operating system to prevent attacks between processes, and thus, between sites. Note that Chrome uses a specific definition of "site" that includes just the scheme and registered domain. Thus, https://google.co.uk would be a site, and subdomains like https://maps.google.co.uk would stay in the same process.

Chrome has always had a multi-process architecture where different tabs could use different renderer processes. A given tab could even switch processes when navigating to a new site in some cases. However, it was still possible for an attacker's page to share a process with a victim's page. For example, cross-site iframes and cross-site pop-ups typically stayed in the same process as the page that created them. This would allow a successful Spectre attack to read data (e.g., cookies, passwords, etc.) belonging to other frames or pop-ups in its process.

When Site Isolation is enabled, each renderer process contains documents from at most one site. This means all navigations to cross-site documents cause a tab to switch processes. It also means all cross-site iframes are put into a different process than their parent frame, using "out-of-process iframes." Splitting a single page across multiple processes is a major change to how Chrome works, and the Chrome Security team has been pursuing this for several years, independently of Spectre. The first uses of out-of-process iframes shipped last year to improve the Chrome extension security model.

In Chrome 67, Site Isolation has been enabled for 99% of users on Windows, Mac, Linux, and Chrome OS. (Given the large scope of this change, we are keeping a 1% holdback for now to monitor and improve performance.) This means that even if a Spectre attack were to occur in a malicious web page, data from other websites would generally not be loaded into the same process, and so there would be much less data available to the attacker. This significantly reduces the threat posed by Spectre.



Chrome version 67 Add on Site Isolation as standard for protection against Spectre




« Cougar Launches the Cougar Turret · Chrome version 67 Add on Site Isolation as standard for protection against Spectre · Microsoft advocates regulation for facial recognition »

9 pages « < 6 7 8 9


Robbo9999
Senior Member



Posts: 1528
Joined: 2012-10-07

#5565758 Posted on: 07/17/2018 08:02 PM
Not sure about you, but I would lightheartedly kill ANY cheater, biaser, malicious "IT expert" out there. Without a moment's hesitation. Cheating in PC games? I SWEAR with my whole being, I would be able (and I am capable of it) to break every bone in every finger, toe, every rib etc. of such guy . Afterwards, I'd take a glass of good, cold German beer and a huge piece of cheesecake.

Ha, kinda extreme! I have to admit I don't like cheaters in online gaming, and they do make me mad, but I wouldn't kill them or maim them, they're just saddos that then feel the need to cheat.

Aura89
Senior Member



Posts: 8156
Joined: 2008-07-31

#5565797 Posted on: 07/17/2018 09:58 PM
Not sure about you, but I would lightheartedly kill ANY cheater, biaser, malicious "IT expert" out there. Without a moment's hesitation. Cheating in PC games? I SWEAR with my whole being, I would be able (and I am capable of it) to break every bone in every finger, toe, every rib etc. of such guy . Afterwards, I'd take a glass of good, cold German beer and a huge piece of cheesecake.


So you're a sociopath?

Thank you, alerting the officials now.

vbetts
Moderator



Posts: 15115
Joined: 2006-07-04

#5565802 Posted on: 07/17/2018 10:15 PM
So...

We're gonna just overlook this at least once...And we're gonna go on without wanting to kill anyone.

DLD
Senior Member



Posts: 886
Joined: 2002-09-14

#5566506 Posted on: 07/20/2018 12:59 AM
I am most certainly NOT a "sociopath". Only, unlike you, I do not accept a kind of behavior based on a scheme "I will do whatever I can to provoke your anger, to make you suffer, to spit on you, to make your life miserable etc. and you'll be forced to remain passive in the name of DEMOCRACY, TOLERANCE, CHRISTIANITY...".
To turn the other cheek (after one have been slapped by some scumbag)? Oh, no - I am definitely not such a guy. No - I will rather turn the scumbag (over). Say hello to the "officials", dear aura89, and convey my sincere apologies for not being a good, humble Samaritan, but a communist instead...

By the way: why did you thank me (you've written "thank you")? What's the reason for thanking me (it's kind of confusing, since you had expressed your disagreement with me - which is OK - I don't expect everyone to share my attitudes)?

Fox2232
Senior Member



Posts: 11719
Joined: 2012-07-20

#5566551 Posted on: 07/20/2018 07:08 AM
So you're a sociopath?

Thank you, alerting the officials now.
That was not depiction of sociopathic behavior. (Violence can happen to be necessary evil/rationally justified. But not enjoyable as sociopaths have empathy.)
That's clearly psychopathic. (Disregard for human life/borderline self-enjoyment from suffering of others.)

But I do not blame you, 1/2 of world stopped calling many things their names to prevent insult.
Now, notice that I called it depiction. Because those 2 are not defined by their words, but actions.

(I think something is in the air, because we are derailing so many threads.)

9 pages « < 6 7 8 9


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2021