Google steals security page from Mozilla's Firefox
Will add blocking of outdated plug-ins to Chrome at unspecified future date
Computerworld - Google will take a page from Mozilla's security playbook and block outdated plug-ins from launching in its Chrome browser, part of a new effort to keep users safer, the company said Monday.
In a post to the Chromium blog, a trio of Google security engineers announced that Chrome would refuse to run plug-ins if they were found to be out of date, and thus, potentially vulnerable to exploitation of known bugs.
Chromium is the name of the open-source development project that feeds into the Chrome browser.
Google did not spell out when the blocking of outdated plug-ins would be added to Chrome, saying only that it would happen in the "medium-term." Nor did the Google engineers specify which plug-ins would be blocked. Chrome will assist users in updating old plug-ins, they said.
Chrome will also display a warning when a site calls on an infrequently-used plug-in, said Chris Evans, Julien Tinnes and Michal Zalewski of Google's security team. "Some plug-ins are widely installed but typically not required for today's Internet experience," they said. "For most users, any attempt to instantiate such a plug-in is suspicious and Google Chrome will warn on this condition."
Evans, Tinnes and Zalewski did not elaborate on how Chrome would define "infrequently-used."
Google did not reply to requests for clarification and more information on the timeline of the impending changes to Chrome.
By making this move with Chrome, Google is following in the footsteps of Mozilla, which has already equipped its Firefox browser with the ability to block outdated plug-ins.
Mozilla added basic plug-in checking to Firefox 3.5 last September, but fleshed out the feature in Firefox 3.6, which debuted in January. The newest Firefox checks browser plug-ins, such as Adobe's Flash Player or Apple's QuickTime, to make sure they're up to date, then blocks vulnerable plug-ins from loading and shows users how to update the software.
Both Mozilla and Google have said the new features represent a response to the rapid increase in the number of attacks against vulnerable plug-ins, especially Adobe's Flash Player and Reader.
According to some estimates, attacks against browser plug-ins, particularly Adobe's popular Reader PDF viewer, are quickly climbing. In the first quarter of 2010, PDF exploits accounted for 28% of all malware-bearing attack code, antivirus vendor McAfee said in April.
In other security arenas, Chrome is already ahead of Firefox. For example, Google's browser now automatically updates Adobe's Flash Player behind the scenes. And two weeks ago, Google added an integrated PDF viewer to the "developer" build of Chrome for Windows and Mac.
Chrome accounted for 7% of all browsers used last month, according to the most recent data from Web metrics company Net Applications. Meanwhile, Firefox owned a 24% usage share in May.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, or subscribe to Gregg's RSS feed . His e-mail address is email@example.com.
- IE6: Retired but not dead yet
- Chrome users won't give up, keep pressing Google to restore old-style new tab page
- Google quashes 31 vulnerabilities, restores Metro mode 'steppers' with Chrome 34
- Firefox's UI face-lift on track for April debut
- Ex-Mozilla engineer blames Microsoft's rules for Metro Firefox's death
- Mozilla patches 20 Firefox flaws, plugs Pwn2Own holes
- Google reverses field, promises to restore Chrome's scrollbar arrows
- Update: Google ships Chrome 33, patches 28 bugs
- Mozilla's top exec defends in-Firefox ads, revenue search
- Mozilla taps in-Firefox ads as it searches for more revenue
Read more about Security in Computerworld's Security Topic Center.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts