Linked by kragil on Wed 23rd Jan 2013 20:26 UTC
Thread beginning with comment 550130
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
RE: Let the exploits begin!
by kragil on Wed 23rd Jan 2013 21:02
in reply to "Let the exploits begin!"
The security behind it was already tested a few times and so far seems to be fairly solid. The native code has to conform to very strict rules, but sure there might be holes(but probably less than Java ;-) )
BUT Chrome X86 ships with it for some time and so far the security nightmare that the "ActiveX!" screeming masses have predicted hasn't happened yet.
RE[2]: Let the exploits begin!
by moondevil on Wed 23rd Jan 2013 22:29
in reply to "RE: Let the exploits begin!"
RE: Let the exploits begin!
by bentoo on Thu 24th Jan 2013 18:02
in reply to "Let the exploits begin!"
How long until black hats start having fun with native client?
They already have. Recall it was a couple of native client bugs that were used to exploit Chrome at Pwnium last year. No doubt it will be part of the attack surface again at this years pwn2own.
http://nakedsecurity.sophos.com/2012/05/24/anatomy-of-an-exploit-si...
RE[2]: Let the exploits begin!
by moondevil on Fri 25th Jan 2013 08:03
in reply to "RE: Let the exploits begin!"





Member since:
2005-07-08
How long until black hats start having fun with native client?