Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Development
    • IT Management

    Google Chrome Puts Security in a Sandbox

    Written by

    Brian Prince
    Published December 11, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The Google Chrome browser is no longer a beta, and has been outfitted with a coat of security armor Google hopes will both protect users and help Chrome compete with rival browsers.

      The toughest piece of that armor involves sandboxing. In Chrome, HTML rendering and JavaScript execution are isolated in their own class of processes. Running each tab in Chrome in a sandbox allows Web applications to be launched in their own browser windows without the ability to write or read files from sensitive areas. Plug-ins are run in separate processes that communicate with the renderer.

      “I think Google was very proactive in terms of what we’ve been doing around trying to help prevent users from being infected with malware,” said Ian Fette, security product manager for Google. “On the Web browser, we’re trying to do everything we can to make sure that users are not becoming affected with malware, and a big part of that is the sandboxing technology.”

      Calling it a second level of defense, he said the technology is designed to prevent malware from persisting even if there is a flaw in the code that would lead to the Web browser being compromised.

      “It’s designed to prevent malware from getting installed on the system, from being able to start again when you close the browser and restart the computer; it’s designed to help prevent malware from being able to read files on your file system … it’s really a defense-in-depth mechanism,” Fette explained.

      As noted on the Google security blog, however, there are some limitations. Since it depends on Windows, there is the possibility of a flaw in the operating system security model itself. Another issue is that some legacy file systems used on certain computers and USB keys, such as FAT32, don’t support security descriptors. Files on those devices can’t be protected by the sandbox, according to the blog.

      In addition, if a third-party vendor configures files, registry keys and other objects in a way that bypasses the access check-the mechanism by which the system determines whether the security descriptor of an object grants the rights requested to an access token-it can give everyone using the machine full access.

      In addition to the sandboxing, Google has outfitted Chrome with a number of security features similar to those of Internet Explorer, such as Incognito mode. Like IE 8’s InPrivate Browsing, Incognito mode allows users to hide their Web surfing histories, and no cookies are stored beyond the lifetime of a browser window.

      “Incognito mode is designed to reduce the amount of data that gets stored on your computer; it’s not designed to provide, for instance, anonymous browsing,” Fette said. “When you go into Incognito mode you are essentially saying, ‘Everything I do in this browser window, please don’t record that on my computer once [I] close off that window.'”

      Chrome also takes a blacklisting approach using Google’s SafeBrowsing API to protect users against known malicious sites.

      “I think the biggest advantage that we have is that Chrome is the first browser built from scratch after bad guys started exploiting other browsers,” opined Google Engineering Director Linus Upson. “We’ve had the luxury of looking at the security problems other browser vendors have had, and designing around those from the very beginning.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×