German gov't endorses Chrome as most secure browser


Recommended Posts

seriously that was your explanation to prove that IE8 is secure?? IE was hacked but it was hard to hack(it was hard to hack in the list of browsers that was hacked). chrome couldnt be hacked so that makes it even more secure and almost impossible to hack!!! where are you getting these logics???

Did you even bother to read what I wrote or do you just not understand english? I didn't say that, the browser hackers at pwn2own DID.

The only browser that survived Pwn2Own this year was Google Chrome. This led to numerous news reports like this one suggesting that Google's browser was somehow more secure than the others. This is far from the truth. In fact, the vulnerability that caused the iPhone's downfall was in the WebKit engine and also affected the Google Chrome browser. Chrome's sandbox was also held up as a major CanSecWest roadblock but there's already scuttlebutt circulating that at least two security researchers have found a way to break out of the Chrome sandbox. Keep in mind that the iPhone has a sandbox that didn't help much when hackers hijacked the SMS database at Pwn2Own.

Survival at the Pwn2Own contest simply means that researchers weren't motivated enough to give up their vulnerabilities/exploits in exchange for a smartphone and cash prizes. The iPhone survived in 2008, didn't it?

Despite the survival of Google Chrome and the fall of Internet Explorer 8 (running on Windows 7), all the browser hackers at the contest maintained that Microsoft's browser is by far the most difficult to exploit. For starters, IE 8 is the only browser to fully -- and properly -- implement ASLR (see explanation from Nils). Peter Vreugdenhil, the researcher behind the successful IE 8 hack, needed two different vulnerabilities and several exploitation tricks (see paper - pdf) to get it to work. However, because IE is the world's most widely deployed browser, it will continue to attract the attention of hackers and malware writers. Security doesn't equate to safety.

http://threatpost.co...0Contest?page

And, just to point out, you do realize Chrome's sandbox was made possible by reverse engineering parts of the Windows Vista / 7 kernel and then using a whole load of undocumented APIs right?

And yet again, Pwn2Own survival MEANS NOTHING. The best hackers won't show up because the prize money is pathetic, and even if they aren't going to be giving up zero day exploits like candy.

Link to comment
Share on other sites

This topic is now closed to further replies.