{"id":309,"date":"2009-03-21T08:15:20","date_gmt":"2009-03-21T16:15:20","guid":{"rendered":"http:\/\/jaredrobinson.com\/blog\/?p=309"},"modified":"2009-03-21T08:15:20","modified_gmt":"2009-03-21T16:15:20","slug":"web-browser-security-cracked-in-minutes","status":"publish","type":"post","link":"https:\/\/jaredrobinson.com\/blog\/web-browser-security-cracked-in-minutes\/","title":{"rendered":"Web Browser Security: Cracked in minutes"},"content":{"rendered":"<p>There was a hacking contest at the [CanSecWest 2009 security conference](http:\/\/cansecwest.com\/) this past week, and it proved that web browsers still aren&#8217;t secure. Here&#8217;s [the report](http:\/\/www.heise.de\/english\/newsticker\/news\/134843):<\/p>\n<p>> Charlie Miller, in a repeat performance of last year, used a prepared exploit to crack the Safari web browser on a MacBook running the latest version of Mac OS X in a matter of seconds.<\/p>\n<p>> Following Miller, a 25 year old computer science student at the University of Oldenburg in Germany, who went by the name of &#8216;Nils&#8217;, used an exploit on Microsoft&#8217;s Internet Explorer 8 circumventing the latest Data Execution Prevention (DEP) and Address Space Layout Randomisation (ASLR)&#8230; he then demonstrated an exploit for Safari and Mozilla&#8217;s Firefox.<\/p>\n<p>What does this mean for me and you? That if a well organized group or well funded organization wants to, they can and will hack your machine.<\/p>\n<p>I think there&#8217;s an extremely high likelihood that these hackers exploited a hole in JavaScript or Flash, not in the web browser&#8217;s rendering of HTML itself. Running untrusted code from random sites never has been, and never will be, without security risk. That&#8217;s why I use the [NoScript](http:\/\/noscript.net\/getit) Firefox extension. Unfortunately, it makes many sites confusing by reducing the &#8220;richness&#8221; of the web browsing experience, and can even break online shopping.<\/p>\n<p>Is there a moral of the story here? Life is risky. Surfing the web is risky. By avoiding all risk, there is no opportunity, no life.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There was a hacking contest at the [CanSecWest 2009 security conference](http:\/\/cansecwest.com\/) this past week, and it proved that web browsers still aren&#8217;t secure. Here&#8217;s [the report](http:\/\/www.heise.de\/english\/newsticker\/news\/134843): > Charlie Miller, in a repeat performance of last year, used a prepared exploit to crack the Safari web browser on a MacBook running the latest version of Mac &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/jaredrobinson.com\/blog\/web-browser-security-cracked-in-minutes\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Web Browser Security: Cracked in minutes&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-309","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts\/309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/comments?post=309"}],"version-history":[{"count":2,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts\/309\/revisions"}],"predecessor-version":[{"id":311,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/posts\/309\/revisions\/311"}],"wp:attachment":[{"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/media?parent=309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/categories?post=309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jaredrobinson.com\/blog\/wp-json\/wp\/v2\/tags?post=309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}