|
|
|
And here comes another secure by design OS |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
And here comes another secure by design OS Par DeobfuscatedLe [2010-05-12] à 14:10:26
Présentation : It's pretty old news now, but I was catching up with my RSS feeds and ran across one more time an article talking about Chome OS, the new OS from Google. The goal is quite clear, a lightweight OS, designed to run fast, boot-up quickly and focus on web-apps. Rather logical as it will massively use online Google services like Google mail, docs and so on. Alright, so far, so good. Why not... But having a look at this introduction to Chrome OS, I can't avoid to... er, not sure whether it's laughing or crying. Let me comment some bits from this article Google Chrome OS is an open source, lightweight operating system that will initially be targeted at netbooks. Later this year we will open-source its code, and netbooks running Google Chrome OS will be available for consumers in the second half of 2010. Because we're already talking to partners about the project, and we'll soon be working with the open source community, we wanted to share our vision now so everyone understands what we are trying to achieve. Ok, developing a new OS from scratch is just an huge job and costs a lot of money. So, Google will go for open-source projects it'll run Linux and just package them to run Chrome. Why not. Nothing bad here. I'd even say that releasing the source code of other components as they plan to do is really cool. Speed, simplicity and security are the key aspects of Google Chrome OS. We're designing the OS to be fast and lightweight, to start up and get you onto the web in a few seconds. The user interface is minimal to stay out of your way, and most of the user experience takes place on the web. And as we did for the Google Chrome browser, we are going back to the basics and completely redesigning the underlying security architecture of the OS so that users don't have to deal with viruses, malware and security updates. It should just work. Ok, so, as we said before, this so-called OS will be minimal. Don't expect to do anything else than browsing the web. Mmmm, alright. But wait, did you read the last sentence Completely redesigning the security architecture . Sorry Aren't you guys reusing a Linux kernel What are you redesigning And, hold on... No need to deal with malwares nor security updates Well, I'd like to know how to be honest. Google explains that its OS is basically Chrome running on a Linux kernel and, as far as I know, both of them have been and will surely be impacted by vulnerabilities. As well, it's not because malwares targeting Linux are rare that they don't exist and can't be developed . So, what's the deal here No security update at all, or the updating process will be hidden from users If I had to choose, I'd go for the second one as I really don't want to be online with an old browser running on top of an old OS as both are likely to be vulnerable to something... But still, as many people, I'm not happy with hidden stuff... Besides, if this perfect security fails, how users will be able to track down viral infection or any other security issue on their machine as the only tool available seems to be the browser All web-based applications will automatically work and new applications can be written using your favorite web technologies. Does this include silverlight Google Chrome OS is being created for people who spend most of their time on the web, and is being designed to power computers ranging from small netbooks to full-size desktop systems. Ok, I see why this kind of minimal system is interesting when it comes to netbooks. But seriously, who will buy a desktop to run a web browser I know many people just use computers to check their emails and browse the internet but, still, having a core duo, 4GB of RAM and a 3D graphic accelerator to run Google OS is like buying a Ferrari to go to the hairdresser... Anyway, just a detail. Especially when it comes to security, innovation is good. Thinking again about what already exists is vital. Being pro-active and proposing solutions is the way to go. But I reckon that Chrome OS freaks me out. Just a few details have been published so far, marketing did its job as well to make the announcement, well, like it is, and I hope I'm wrong. But the whole idea of an OS that is designed not to be administrated sounds bad to me. This Secure by design concept is not new and never really worked so far. Sounds really like If you don't see the problem, well, there's no problem . This is not security...it's all the opposite. Yeah, I hope I'm wrong...
Les derniers articles du site "Deobfuscated" :
- Coloring junk code in IDA Pro - Security Essentials Rogue AV Anti-Debugging - More on moron packers and anti-debugging - Big brother with big vulnerabilities... - R.I.P milw0rm - l0phtcrack 6 and Nmap 5 are out - Null pointer dereference vulnerability in the Linux kernel - Hey There's a worm in that apple - Die Delphi, die - And here comes another secure by design OS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|