<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2008://1.12965-</id>
  <updated>2011-08-16T18:03:04Z</updated>
  <title>Comments for Google Releases Browser Security Handbook</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=12965" title="Google Releases Browser Security Handbook" />
    <published>2008-12-13T20:11:12Z</published>
    <updated>2008-12-14T22:57:02Z</updated>
    <title>Google Releases Browser Security Handbook</title>
    <summary>Just before announcing that Chrome was taken out of beta last week, Google released a browser security handbook for Web developers that details the key security features of the main Web browsers. Released under a Creative Commons 3.0 license, the document provides a comprehensive comparison of security features of the commonly used browsers; IE (version...</summary>
    <author>
      <name>Lidija Davis</name>
      
    </author>
    
    <category term="Google" />
    
    <category term="NYT" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="lock_dec_08.jpg" src="http://www.readwriteweb.com/lock_dec_08.jpg" width="146" height="150" />Just before announcing that <a href="http://www.readwriteweb.com/archives/google_takes_chrome_out_of_beta.php">Chrome was taken out of beta</a> last week, Google released a <a href="http://code.google.com/p/browsersec/wiki/Main">browser security handbook</a> for Web developers that details the key security features of the main Web browsers.</p>

<p>Released under a <a href="http://creativecommons.org/licenses/by/3.0/">Creative Commons 3.0 license</a>, the document provides a comprehensive comparison of security features of the commonly used browsers; IE (version 6 and 7), Firefox (version 2 and 3), Safari, Opera, Chrome and the lesser known Android embedded browser.</p>]]>
      <![CDATA[<p>Wanting to give the Web world a one-stop reference to security issues in browsers, author <a href="http://lcamtuf.coredump.cx/">Michal Zalewski</a> writes "Insufficient understanding of these often poorly-documented characteristics is a major contributing factor to the prevalence of several classes of security vulnerabilities."</p>

<p>Browser security has been an ongoing problem over the years and was the first subject discussed during the <a href="http://www.readwriteweb.com/archives/firefox_chrome_and_ie_talk_add.php">browser wars panel</a> at the <a href="http://addoncon.com/">Add-on conference</a> last week.  Earlier this year, <a href="http://www.sectheory.com/">Robert Hansen</a> and <a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a> uncovered an attack known as <a href="http://ha.ckers.org/blog/20080915/clickjacking/">clickjacking</a>, which gives an attacker the ability to trick a user into clicking where the attacker wants on a site.  A good overview can be found on the Computerworld site, which has a <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9115818&source=NLT_SEC&nlid=38">clickjacking FAQ</a>:</p>

<blockquote>"In plain English, clickjacking lets hackers and scammers hide malicious stuff under the cover of the content on a legitimate site. You know what happens when a carjacker takes a car? Well, clickjacking is like that, except that the click is the car."
</blockquote>

<p>Clickjacking is one of the issues covered in the security handbook which is divided into three sections:</p>

<ol><li><a href="http://code.google.com/p/browsersec/wiki/Part1">Basic concepts behind Web browsers</a> with reviews of core standards and technologies behind current browsers and their security properties</li><li><a href="http://code.google.com/p/browsersec/wiki/Part2">Standard browser security features</a> details explicit security mechanisms and restrictions</li><li><a href="http://code.google.com/p/browsersec/wiki/Part3">Experimental and legacy security mechanisms</a> discusses security mechanisms that have either fallen into disuse or never caught on, as well as those yet to prove their worth.</li></ol>

<p>The document appears to be an ongoing project; you can find more details <a href="http://googleonlinesecurity.blogspot.com/2008/12/announcing-browser-security-handbook.html">here</a>.</p>

<p><em>Image Credit: Thanks <a href="http://flickr.com/photos/darwinbell/">Darwin Bell</a></em></p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:122522</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c122522" />
    <title>Comment from araba oyunları on 2009-01-11</title>
    <author>
        <name>araba oyunları</name>
        <uri>http://www.oyunruhu.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.oyunruhu.com">
        <![CDATA[<p> just is not that customizable or interesting to use as the versatile FireFox.<br />
</p>]]>
    </content>
    <published>2009-01-11T17:22:45Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:121495</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c121495" />
    <title>Comment from Delgado Business Software on 2009-01-02</title>
    <author>
        <name>Delgado Business Software</name>
        <uri>http://blog.delgadosoftware.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://blog.delgadosoftware.com">
        <![CDATA[<p>I'm glad more users will be informed about internet security threats. It's true that a large percentage of them could be avoided if people simply knew some of the basics.</p>]]>
    </content>
    <published>2009-01-02T22:00:52Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:121351</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c121351" />
    <title>Comment from منتدى on 2009-01-01</title>
    <author>
        <name>منتدى</name>
        <uri>http://wed-gan.com/vb</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://wed-gan.com/vb">
        <![CDATA[<p>Hope this book will be handy for web developers</p>]]>
    </content>
    <published>2009-01-01T12:40:57Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:121350</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c121350" />
    <title>Comment from منتدى on 2009-01-01</title>
    <author>
        <name>منتدى</name>
        <uri>http://wed-gan.com/vb</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://wed-gan.com/vb">
        <![CDATA[<p>Hope this book will be handy for web developers</p>]]>
    </content>
    <published>2009-01-01T12:39:18Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:119938</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c119938" />
    <title>Comment from vidanjör on 2008-12-15</title>
    <author>
        <name>vidanjör</name>
        <uri>http://www.cagdasvidanjor.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.cagdasvidanjor.com">
        <![CDATA[<p>thanks..</p>]]>
    </content>
    <published>2008-12-15T11:14:56Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:119887</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c119887" />
    <title>Comment from venkat on 2008-12-13</title>
    <author>
        <name>venkat</name>
        <uri>http://computersservicing.blogspot.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://computersservicing.blogspot.com/">
        <![CDATA[<p>Hope this book will be handy for web developers</p>]]>
    </content>
    <published>2008-12-14T03:55:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:119880</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c119880" />
    <title>Comment from Anrkist on 2008-12-13</title>
    <author>
        <name>Anrkist</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Honestly, anyone who would need this handbook probably would never use it or even know about it. The best security when it comes to computers is using the thing between your ears.</p>

<p>Don't visit shady sites and don't randomly install junk. What else do you need to know?</p>]]>
    </content>
    <published>2008-12-14T00:11:21Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12965-comment:119874</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12965" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/google_releases_browser_securi.php#c119874" />
    <title>Comment from AD Public Relations on 2008-12-13</title>
    <author>
        <name>AD Public Relations</name>
        <uri>http://galaxyspectrum.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://galaxyspectrum.com/">
        <![CDATA[<p>This is good news - but puzzling nonetheless.</p>

<p>Why would it be in their self interest to release an unbias review if they are trying to promote their own browser.</p>

<p>Are they in essence claiming that their browser excels over all the competition in security?</p>

<p>While it is a nice browser, it just is not that customizable or interesting to use as the versatile FireFox.</p>]]>
    </content>
    <published>2008-12-13T20:57:53Z</published>
  </entry>

</feed>
