Showing posts with label Chrome. Show all posts
Showing posts with label Chrome. Show all posts

Friday, April 2, 2010

Quake II Ported to HTML5 Browser


A lot of attention lately has been put on the capabilities of HTML5 sites, since the iPad doesn’t support Flash. It turns out to not matter much because most companies have had no trouble to switching to HTML5 supported online video platforms. But what about other things that Flash does well, like games? Turns out that HTML5 might be a more powerful game engine than most people think.

To show off the possibilities of HTML5, some engineers on the Google Web Toolkit team created an HTML5 port of the classic first-person shooter game Quake II. You can check it out in the video below. It is based on an open-sourced Java port of Quake called Jake2.

A post on the Google Code blog explains exactly how they managed to port the game over:

We started with the existing Jake2 Java port of the Quake II engine, then used the Google Web Toolkit (along with WebGL, WebSockets, and a lot of refactoring) to cross-compile it into Javascript. You can see the results in the video above — we were honestly a bit surprised when we saw it pushing over 30 frames per second on our laptops (your mileage may vary)!

The HTML5 game works on “modern browsers such as Safari and Chrome.” If you have had a chance to try it out, let us know what you think.

Friday, March 26, 2010

Pwn2Own 2010: Browsers and iPhone Get Pwned!


The TippingPoint Zero Day Initiative (ZDI) held it’s annual Pwn2Own contest at the CanSecWest security conference held in Vancouver, BC on March 24th, 2010. As the contest name implies, if you successfully exploit a target you get to keep it along with a ZDI cash prize and related benefits. This was the fourth year this contest was held and the total cash prize amounted to $100,000. The competition had two main technology targets, the first one being security posture of market-leading web browsers and operating system pairings; and the second target being vulnerabilities affecting mobile phones.
Target One: Browsers

The multifaceted web browser continues to occupy a critical presence on the client-side attack surface. As Adobe, Google, and an estimated 30 other companies affected in the Aurora incident can attest to, the security posture of these products merits a yearly public evaluation by the research community at large. $40,000 of the total $100,000 cash prize pool was allotted to the web browser portion of the contest, each target being worth $10,000. The browser targets used this year were the latest versions of Apple’s Safari, Google’s Chrome, Microsoft’s Internet Explorer, Mozilla’s Firefox. After the first day of the event, all but Google Chrome had been successfully hacked.

Safari Gets PWNED!

Charlie Miller, a principal security analyst at consulting form Independent Security Evaluators, remotely located a hole in the Safari browser of a MacBook Pro and launched a remote, “full-command” shell. This shell allowed him to run a set of commands and see all the files on the target’s MacBook. “There’s a reason for researchers like me t spend time looking for flaws,” said Miller. “We get something for winning, the company gets free research, and the end-user gets a batch to a critical bug. So in some sense, everybody wins there.” Miller expects to see a patch for the bug in the next month. He see’s a reason for concern as hacks to the Mac are becoming a regular event at the CanSecWest conference annually. “It’s the fourth year they’ve run the contest, and every year someone’s broken into Safari,” he said. “You begin to wonder if there’s some sort of underlying problem in what they’re doing, that in the four years they haven’t made it any harder. One of these years, nobody’s going to be able to do it. Since that hasn’t happened yet, hopefully they’ll get their act together and make a more secure product.” Miller won $10,000 and a MacBook of his own.

Microsoft’s Internet Explorer PWNED!
Peter Vreugdenhil, an independent security researcher in the Netherlands, hacked Internet Explorer 8 on a Windows PC, passing through security features in the OS and data execution prevention code in Internet Explorer 8 to take over a Windows PC. Peter won $10,000 and the PC he pwned.

Mozilla’s Firefox PWNED!


Nils, the head of research at UK-based MWR InfoSecurity, broke into a 64-bit Windows 7 PC by launching a “quintessential” CALC.EXE launching payload,” said TippingPoint’s Portnoy. Nils won $10,000 and a Sony Vaio as his prize.

Target Two: Mobile Phones

The increased presence and capabilities of smart phones has brought with it the same security issues and attention traditionally reserved for non hand-held platforms. Vulnerabilities in parsing media, dynamic web content, email, and other client issues have been published in the past. Additionally, many of the communication protocols that mobile phones implement are the focus of burgeoning field of security research. The data stored and communicated across these devices is increasing in value to attackers.

iPhone PWNED!


Ralf Philipp Weinmann of the University of Luxembourg and Vincenzo Iozzo of German company Zynamics were able to grab key data in an iPhone, according to Portnoy. “The researchers used a vulnerability in Safari that pulled the SMS database,” he explained. Data included deleted messages, contacts, pictures, and iTunes music files. The joint hackers shared a $15,000 prize, and each took ownership of an iPhone.

What Does All This Mean?

“As a whole, most people seem to understand basic security, but there are still some gaping holes in today’s most popular hardware and software computing platforms,” Aaron Portnoy, security research team lead for TippingPoint said. “The goal of this contest is to demonstrate how vulnerable these devices really are.” The results of the contest will be reported to the manufacturers so they can create the appropriate patches, according to Portnoy. “Until then, we cannot discuss the details of the vulnerabilities [with] the public,” he said. “This is to help keep the vulnerabilities from being exploited before they can be patched.”

So what do you think of the results of the Pwn2Own contest? Do you still feel your data is safe?

One of the things to keep in mind is how the iPad is near launch and it shares the same OS as the iPhone. If the iPhone can be hacked so quickly using an exploit with Safari, how safe exactly is the iPad? Don’t forget that Zobny’s survey results showed us that many iPad customers plan on using the iPad to “work on the go.” How safe would your private business data be if that was the case? That’s what the whole purpose of the contest is for so hopefully the big companies can get their act together and secure their hardware/software better.

Monday, November 23, 2009

Chrome OS And The Microsoft Squeeze

mssquee
Now that we’ve all actually seen Chrome OS, the immediate reaction that most are jumping to is that it won’t be killing Windows anytime soon. Obviously. But that doesn’t mean it won’t hurt Microsoft, and apply long-term pressure to the dominant OS. In fact, Google’s positioning for Chrome OS reads like a page out of Apple’s playbook, only from the opposite direction.

Google is aiming Chrome OS right at the bottom of the market. That is to say, cheap computers, netbooks. Apple, of course, takes the opposite approach, targeting the high end of the market which their high-quality and high-margin machines. If Google is successful with its Chrome OS netbooks (let’s call them ChromeBooks), what we could see is the squeezing of Microsoft, an idea I first laid out a month ago. With attacks from the top and bottom, Windows will be relegated to the middle. And ultimately, if Google has its way, marginalized.

There are a number of problems with being in the middle. First and foremost, the middle is average, boring, bland, etc. There’s nothing particularly wrong with that, unless you’re a company like Microsoft with an image problem. After years of taking hits, Microsoft is trying to revamp its image with expensive ads, new stores, and a new OS, among other things. But the middle is hard to sell. It’s neither the cheapest nor the best. It’s the thing people have to settle on.

Microsoft, of course, is also in the netbook space with Windows XP and now Windows 7. But after being a sector on fire for much of the year, signs point to a slowdown in sales. While you might think that would be bad news for both Microsoft and Google, Google’s ChromeBooks are really a new category altogether. As Google said during its event, they’re working with specific hardware manufacturers to make machines set to a certain standard. This means that they’ll have larger keyboards and trackpads than most netbooks, among other things. In other words, they’ll be better, from a hardware perspective, than most netbooks.

And they potentially serve a different purpose. A couple days ago, Daring Fireball wondered if the real key for Chrome OS (and netbooks) may be to serve as your secondary computer. But there’s really no need to wonder, Google’s VP of Product Management, Sundar Pichai, said as much during the Q&A session. “This will be a secondary device. It may be a primary device in terms of time spent on it, but we expect people to have other computers too,” he said when asked about more powerful editing software not being able to run on Chrome OS.

People aren’t buying $300 computers with the expectation of running Photoshop (which costs $700) on them. They are buying them mainly to get an extremely portable machine that can surf the web. Google’s promise with Chrome OS is the fastest way to do that.

And that’s what a lot of critics are missing (but we’ve been saying since July). Google isn’t trying to compete with a standard OS, they’re trying to help users realize that for the majority of computing they do, they don’t need one in the first place. Maybe you have a desktop computer at home for those few tasks that need dedicated native applications, and maybe that runs Windows or maybe that runs OS X. But maybe the machine that you use most of the time is your cheap, fast ChromeBook.

Though they get criticized a lot for not making a netbook, Apple also competes in this highly mobile space — their “netbook” is the iPhone. While unlike Chrome OS, the iPhone can run native applications, it speaks to a similar point: Increasingly, for most of your computing, you don’t need Windows.

The point is that consumer computing is shifting to a place where speed and mobility are paramount. The reason people are so excited about products like the CrunchPad and Apple’s tablet isn’t because they can run Photoshop — they can’t — it’s because they offer an easy way to use the Internet. Same thing with the iPhone. Same thing with Android phones. And it will be the same thing with Chrome OS and the ChromeBooks.

The difference is that these ChromeBooks will be the first devices that actually look like the traditional computers we’re used to. They will look like they could be Windows machines, but they won’t be. That’s a powerful stereotype to break. And if Google breaks that at the bottom of the market, with Apple continuing to break it at the top of the market, Microsoft will begin to feel squeezed.


Thursday, November 19, 2009

Google Chrome OS

Everything You Need To Know About Chrome OS
http://gizmodo.com/5408504/
http://lifehacker.com/5408594/