Latest in Gear

Image credit:

Google Chrome prevents sites from launching Spectre-like attacks

Site isolation is the law of the land as of Chrome 67.
Jon Fingas, @jonfingas
July 12, 2018
Share
Tweet
Share

Sponsored Links

AOL

If you're using Chrome, you now have fewer reasons to worry about Spectre-style security threats. Google has revealed that Chrome 67 for desktop and the matching Chrome OS release enable a previously experimental Site Isolation feature that reduces the chances of intruders using speculative execution side-channel attacks like Spectre. The technique limits the web renderer process to content from a single site, preventing an attacker's page from sharing malicious code through an innocent page (say, though cross-site pop-ups or remotely stored scripts). In theory, sinister types can't swipe passwords or other sensitive data while you're visiting otherwise innocuous sites.

The feature "generally" shouldn't break legitimate site behavior. It will, however, put extra strain on your system. Google believes there's a 10 to 13 percent memory overhead compared to earlier versions since it'll need to run processes for each site.

The company promises "additional security checks" in the future, including safeguards when an attack has already been compromised. Mobile users will have protections, too, with Chrome 68 for Android will adding an experimental Site Isolation flag. These initiatives don't guarantee that you'll be immune to Spectre and its kind, but they should cut off some of the more obvious avenues for stealing your info.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
Tweet
Share

Popular on Engadget

Engadget's 2020 Back-to-School Guide

Engadget's 2020 Back-to-School Guide

View
'Xbox Series S' console revealed by controller packaging

'Xbox Series S' console revealed by controller packaging

View
Space Force official logo and motto unveiled

Space Force official logo and motto unveiled

View
Watch AI-controlled virtual fighters take on an Air Force pilot on August 18th

Watch AI-controlled virtual fighters take on an Air Force pilot on August 18th

View
Hyundai is turning Ioniq into its own EV sub-brand

Hyundai is turning Ioniq into its own EV sub-brand

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr