DISQUS

Matasano Chargen: Browser Wars 2.0: Will security be the battleground?

  • dre · 3 years ago
    the battleground is OS integration, popularity, and FUD if you look at those numbers again. Microsoft is fine with security being a priority feature for IE7 as long as they come out on top.

    unfortunately, that's just what the crime syndicates' web application attack teams are preparing for. global domination through IE6/7 cross-exploits and gaping holes in websites that browsers don't catch, regardless of their antiphishing features.

    this stuff is so far under the radar. it's so easy to launch an attack from a cloned mobile phone running bluetooth with a sniper rifle in NYC to a laptop in LA that's running wifi that breaks into a corporate LAN and dns spoofs google and CNN.com to insert any given executable/rootkit.

    maybe it's not as easy - but certainly possible to access ebay.com from romania using a custom but highly advanced onion routing network and posting a few lines of persistent injected javascript code that can collect every user/pass/info for every active ebay/paypal account in a manner of hours.

    expensive firewalls, WAF's, IPSes, IDS's, scanning tools, billions of dollars worth of programmers, and 25 years of industry standards don't solve the basic attack platforms that are being used against us today. what makes you think IE7 or Firefox 2.0 will have any impact?
  • Chris_B · 3 years ago
    Recently I was doing some bog standard XSS testing against a few sites with various browsers. I noticed that Opera (on OSX) tossed out a warning page when attempting to click on a xss link or manually enter a xss test URL. Makes me wonder if there is any justifyable reason that other browsers dont implement this behavior.
  • dre · 3 years ago
    Chris_B: is this the same warning that RSnake and others were talking about in the sla.ckers forum and on the ha.ckers blog? I thought it was unintentional on opera's part?