Google, Adobe sandbox Flash for Chrome to protect users
While only Windows XP, Vista and Windows 7 versions of Chrome include the new Flash sandbox, Adobe and Google plan to add the security feature to Mac OS X and Linux editions. The companies did not set a timetable for the expansion to those two platforms, however.
"We think of this as a working prototype," said Arkin. "It will progress to maturity with Chrome."
"There are still bugs we're working through, so it will be in the dev channel for a while yet," added Uhley.
Google said the Flash sandbox should show up in the "stable" build of Chrome -- the production version of the browser -- in early-to-mid 2011.
While Adobe said that the quality of this first sandbox is credible, it plans to continue working on the technology until it's rock solid. Arkin compared the Flash sandbox now in Chrome to the quality of the code in Reader X when Adobe issued several private betas to testers before launching the PDF program to the public last month.
"We're confident that when it makes it into the [Chrome] stable channel, it will be solid," said Arkin.
Adobe wants to apply what it learns with Google and Chrome to other browsers, particularly Mozilla's Firefox and Apple's Safari.
"We wanted to do a working prototype [of the sandbox] to make sure we could do it," said Uhley. "But we want to have these same discussions with Mozilla and Apple and see if this will work for them."
Uhley said Adobe couldn't craft a Flash Player sandbox for other browsers without their help. "We can't to it all ourselves," he said. "It requires changes on the browser side as well as in Flash."
Some of the work, including the critical broker process, will be available as open-source in the Chromium project, which feeds into Chrome, said Uhley.
On Google's part, it's planning to add APIs to Chrome that will allow other plug-in makers to run inside a sandbox. "We are always interested in improving plug-in security, and thus we are committed to our ongoing next-generation plugin API work, which provides a standard way for plug-ins to run inside the sandbox," Google said.
Google and Adobe have collaborated on Flash before. Last April Chrome began packaging Flash Player with the browser, which automatically updates Adobe's software when the latter issues security updates.
The Windows Chrome dev build with the Flash sandbox was released yesterday. Users can switch to the dev channel by visiting Chrome's Web site.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is email@example.com.
- Workarounds to purge search bar from Firefox's new tab page are available
- Mozilla ships Firefox 31, adds search to new tab page
- Microsoft's IE steps back from the brink of irrelevance
- Firefox falters, falls to record low in overall browser share
- Firefox risks user backlash by adding search box to new tab page
- Google unseats Microsoft as the U.S. browser powerhouse
- Safari, Chrome push to mask URLs
- Chrome on Windows champs at the 64-bit
- Google pulls trigger, cripples some Chrome add-ons
- Microsoft shoots to shorten Internet Explorer's long tail
Read more about Security in Computerworld's Security Topic Center.
- Troubleshooting Common Issues in VoIP Learn more about Voice over Internet Protocol (VoIP), including common VoIP metrics used, best practices in VoIP management and tips and tricks for...
- 2013 Network Management Software (NMS) Buyers Guide This white paper contains an independent comparison study of six different network management solutions and provides guidance on how you can choose the...
- Rightsizing Your Network Performance Management Solution: 4 Case Studies This white paper discusses challenges encountered as organizations search for the most cost-effective network performance management solution.
- Global Growing Pains: Tapping into B2B Integration Services to Overcome Global Expansion Challenges A recent survey by IDG Research explored both the challenges and pain points companies face when growing globally, as well as the capabilities...
- E-Signature RFP Checklist Webcast If your organization is looking to adopt e-signatures, you may be overwhelmed by the number of providers that offer seemingly similar solutions. How...
- Cloud and Collaboration: Driving Your Business Value Mission Critical Cloud from Peer 1 Hosting is enterprise-grade. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!