Linked by Thom Holwerda on Tue 24th Nov 2009 17:28 UTC, submitted by waid0004
Google Google has put up a very interesting document explaining the security features underlying its Chrome OS. The document also details the underlying guiding principles of Chrome OS' security features.
Thread beginning with comment 396229
To read all comments associated with this story, please click here.
What about Caja ?
by wannabe geek on Tue 24th Nov 2009 21:57 UTC
wannabe geek
Member since:
2006-09-27

Does Google Caja (javascript capabilities) fit anywhere in this scheme? I'd really like to see a capability-based security model.

Google Caja : http://code.google.com/p/google-caja/

On the other hand, as someone who opens Synaptic and other privileged GUI apps in a dedicated X session for the sake of security, I like the fact they took this possiblility into account: "Full-screen mode in some plugins could allow an attacker to mock out the entire user experience of a Chromium OS device. We are investigating a variety of mitigation strategies in this space."

Edit: link

Edited 2009-11-24 21:58 UTC

Reply Score: 2