Showing posts with label Browser. Show all posts
Showing posts with label Browser. Show all posts

Friday, 9 April 2010

Early IE9 Platform Preview results show promise

We've argued that Microsoft needs to engage more with Web developers to give a better understanding of what the company is doing with its Web browser, allow them to provide feedback throughout the development process, and more broadly get them engaged with the development process. With Internet Explorer 9's Platform Preview, Microsoft has indeed taken steps to do exactly this. Though Microsoft still isn't releasing the nightly builds that other browsers offer, the Platform Preview definitely represents progress; it provides early access to IE9's core rendering and JavaScript engines, and will be updated approximately every eight weeks.

The eight-week cycle was chosen because Redmond felt this provided the best trade-off between getting regular updates into developers' hands, ensuring that the preview releases are reasonably robust, and getting useful feedback that integrates well with Microsoft's own development processes. Each version will undergo reasonably extensive testing during the eight-week period, giving ample opportunity for bugs to be filed. For its part, the IE team has committed to investigating every single bug filed, and resolving all that it can.

Indications are that the Platform Preview has thus far been quite successful. Sources close to the matter state that some 700,000 copies of the preview have been downloaded, and that interest has been global in spite of the preview being a US English-only release. The top three bug report areas are SVG, compatibility, and then CSS, which certainly indicates that developers are taking an interest in testing the browser's new features and ensuring they work correctly. Of the hundreds of bugs filed thus far, the same source says that around 60 percent of them have been addressed by the development team.

These download numbers are substantial, and it could be make a good case in favor of this slower release strategy. The Mozilla group's weekly Status Meetings include information about the number of users of different prerelease versions of Firefox. During the lead-up to the release of Firefox 3.5, several hundred thousand people used the major betas, but the nightly releases were much less used, with perhaps 10,000-15,000 users. The Platform Preview is not anything near as usable as the Firefox betas, so 700,000 downloads is a strong showing.

Ars talked with IE General Manager Dean Hachamovitch briefly about the Preview. He said that IE9 testers seemed particularly interested in the browser's performance and graphical capabilities, as these areas of the IE 9 Test Drive site had received most traffic. This is also reflected in some third-party reactions. NVIDIA recently used the IE9 Platform Preview to promote the graphical capabilities of its new Ion2 platform—capabilities that IE9 can, of course, exploit due to its extensive hardware acceleration (the same hardware acceleration that leaves Windows XP users out in the cold).

Stability vs. automation

Microsoft's approach to browser development shows a strong commitment to the ideal of a stable, versioned platform, something that developers could reliably target for consistent results. This attitude is carried through to the Platform Preview. Unlike, say, Chrome's dev channel which automatically updates about once a week, ensuring that developers always have access to an up-to-date version, the IE9 Platform Preview will require manual updating. Though this has the obvious downside that developers might forget or not notice that a new version has been released, and hence may result in testing of obsolete versions, it maintains the important (to Microsoft) notion of predictability. With Chrome, a page might work one day and be broken the next by an automatic update, a behavior that can be confusing at best. Microsoft doesn't want IE developers to face a similar experience; instead, they will have to take deliberate action to update.

On the other hand, automatic updates are, in a sense, part-and-parcel of the Web experience. Websites can change their appearance overnight, and while this can be confusing to some, it's an unavoidable fact of Internet life. The case can certainly be made that browsers should follow websites' lead and update themselves; this gives users a browser that (by and large) keeps on getting better—faster, more capable, and with new features. Though occasional regressions will happen (wherein a new version breaks something that used to work) a robust development process should make these rare.

These advantages were acknowledged by Hachamovitch, especially for the more savvy, technically aware user (that is, users who are unlikely to be fazed by new features and improvements appearing within their browser automatically). But the company still prefers to take the more conservative approach to avoid problems of users being surprised by changes.

Hachamovitch was noncommittal about what the second Platform Preview release would contain when released next month. At MIX10 we saw demonstrations of HTML5 video in a build of IE9. The version released last month, however, didn't include video support. HTML5 video is surely one of the most eagerly anticipated IE9 features. It will ship in a Preview release eventually, but we do not know when.

The Platform Preview program is still in its early stages, and this is the first time that Microsoft has developed its browser in this way; there may yet be refinements to the program as both the company and third parties learn the best way to work together, and there's no news yet of what will happen once IE9 moves into beta.

Thus far, at least, it looks like the scheme has been successful at getting third-party developers involved with IE9's development, which has to be good news for both sides.

Tuesday, 6 April 2010

HTML5 and WebGL bring Quake to the browser

The developers behind the GWT Java framework have implemented a port of Quake 2 that runs natively in modern Web browsers. It takes advantage of recent innovations in emerging standards-based Web technologies such as WebGL and WebSockets.

GWT is designed to enable Web application development with Java. Developers can benefit from Java's static typing and more rigidly structured architecture. It generates the requisite JavaScript code that is needed for the application's client-side components. GWT powers several high-profile Google Web applications, including Google Wave. The GWT developers implemented browser-based Quake by using a Java port of the Quake 2 engine on top of GWT.

GWT and the Java-based Quake engine both had to be extended and modified extensively in order for the pairing to work, but the effort paid off. It serves as a compelling example of how emerging standards are becoming increasingly capable of delivering all of the necessary functionality for interactive 3D network gaming.

As some readers might remember, Google released a Quake demo for Native Client (NaCl) when the plug-in was first announced in 2008. The state of open Web technologies has clearly advanced since that time. It's no longer necessary to rely on plugins to deliver this kind of functionality.

Thursday, 25 March 2010

IE8, Safari 4, Firefox 3, iPhone fall on day 1 of Pwn2Own

The first day of the annual Pwn2Own contest in which security researchers can win cash and hardware if they successfully compromise machines using zero-day exploits is finished. Internet Explorer 8 on Windows 7, Firefox 3 on Windows 7, Safari 4 on Mac OS X 10.6, and iPhone OS 3 were all compromised during the competition. Google's Chrome was the only browser left standing—and in fact, was completely untested. None of the researchers at the competition even tried to attack Chrome.

So far, little is known about the successful exploits. Until vendors have been informed of the flaws and those flaws have been patched, details will not be made public.

The iPhone was not successfully hacked in 2009's competition, but was predicted to fall this year, and those predictions have come true. A zero-day Safari flaw was used to gain access to text messages stored on the device by Vincenzo Iozzo from German security firm Zynamics and Ralf-Philipp Weinmann, a post-doctoral researcher at the University of Luxembourg. Notable in the exploit was that it bypassed both iPhone's Data Execution Protection as well as its requirements that all code be signed.

A little more is known about the IE8 exploit, including an (abridged) video of the browser being taken down. The successful researcher, Peter Vreugdenhil, has published a rough outline of the techniques used to bypass IE8's DEP and ASLR protections.

The Safari hack came from Charlie Miller; this makes three years in a row now that Miller has pwned—and hence owned—a Mac at pwn2own. Thus far, nothing further about either this exploit or the Firefox one appears to have been published.

Neither the iPhone exploit nor the IE8 exploit managed to escape the OS-supplied sandboxes that protect these platforms. Without escaping the sandboxes, the impact that flaws can have is reduced, preventing, for example, writing to hard disk (and hence, preventing installation of malware). Nonetheless, read-only access is still valuable for data theft.

It is this sandboxing that might explain why Google's Chrome was untouched; no researcher even attempted to attack it. It is certainly not the case that Chrome has no security flaws—a couple of days before the Pwn2Own draw was made to decide who got to attack which machine and in what order, Google published an update to Chrome that fixed a range of security flaws, some of which were deemed to be high-risk. Google's sandboxing shouldn't be impenetrable, but it is sufficient to make the standard harmless exploit payload—starting up Windows calculator—harder to do.

Tuesday, 23 March 2010

Browser ballot already hurting Internet Explorer market share

The first few weeks of the browser ballot, Microsoft's solution to put an end to the EU antirust case, has already resulted in Redmond's browser losing market share to its rivals, according to web stats firm StatCounter.

In France, IE usage has dropped by 2.5 percent, Italy by 1.3 percent, and the UK by 1 percent. Browser developers Opera and Mozilla have reported strong growth within Europe, with Opera claiming that downloads have doubled since the ballot was introduced, and a Mozilla spokesperson claiming, "We have seen significant growth in the number of new Firefox users as a result of the Ballot Choice screen :As the ballot is rolled out across the rest of Europe, Mozilla expects further gains to be made.

The ballot isn't universally popular. Although 12 browsers are offered, only the top five are immediately accessible. The remaining seven are only visible after scrolling horizontally. As the seven minority browsers expected, their presence in the ballot has done little to boost their market share. A spokesman for the Flock browser said, "To date, new downloads of Flock originating from the browser choice screen have only contributed marginally to growth in overall downloads. This is also the case for the other browsers not on the main screen."

The remaining browsers have petitioned the EU to try to get the ballot changed. For its part, Microsoft still maintains that the browser ballot is compliant with the EU's demands. With some 200 million European users due to be shown the choice screen, and the benefits of being included becoming increasingly clear, time is clearly of the essence for the seven smaller browsers.

Saturday, 20 March 2010

Mozilla Labs builds add-on to bring address book to Firefox

Firefox's flexible XUL framework and sophisticated add-on system offer a rich platform for enhancing browser functionality. Mozilla Labs takes advantage of this capability as it experiments with new concepts for augmenting Web interaction. Some of the latest experiments to emerge from Mozilla Labs aim to make contacts and identity a core part of the browser.

Mozilla has announced the availability of an experimental new add-on for Firefox that is designed to import information about the user's contacts from a variety of Web services and other sources. The add-on makes contact details easily accessible to the user and can also selectively supply it to remote Web applications. The initial implementation can import data from Gmail, Twitter, and the local system address book on OS X. It can optionally use the Gravatar service to find contact avatars.

After the add-on has imported and indexed the user's contact data, it becomes available to the user through an integrated contact management tool that functions like an address book. There are a number of ways that the contact information could potentially be useful in the browser itself. One of Mozilla's first experiments is an autocompletion feature that allows users to select a contact when they are typing an e-mail address into a Web form.

A number of more compelling usage scenarios involve making the user's contact information available to remote Web services. Consider, for example, the popular social networking website Foursquare, which requests access to your Gmail account so that it can connect you with your friends. Instead of giving it access to your Gmail account and all of your contacts, you could use the contacts add-on to selectively provide limited details about specific groups of contacts.

The add-on is designed in a manner which ensures that contact information is only made accessible to Web services with the user's explicit permission. In many ways, it could potentially be more secure and respectful of privacy than the existing mechanisms that are already widely used today by many social networks to automatically establish friend relationships for new users.

To make the browser's contact database accessible to Web applications, the add-on uses the W3C Contacts API specification. It's an emerging standard developed by Nokia that defines JavaScript methods for interacting with contact data. The functionality described by the standard is intended to allow Web applications to seamlessly integrate with the user's browser-integrated address book.

The API is still in the editing stage, but appears to be relatively comprehensive. It supports adding, removing, and updating items in the browser's contact database and also provides methods for searching and iterating over contacts.

The add-on also supports Plaxo's Portable Contacts standard, which is associated with the OpenSocial initiative. Mozilla says that its new contacts add-on is using the Portable Contacts format to store data internally.

Mozilla is enthusiastic about opportunities for making the new contacts add-on integrate with Raindrop, the experimental communication platform that is being developed by Mozilla Messaging. There is also a chance that we could eventually see contact synchronization support integrated in Weave. As the browser increasingly becomes the central hub of Internet communication, native support for managing and accessing contacts could be a valuable enhancement.

Wednesday, 3 March 2010

Microsoft rivals push to send browser ballot on world tour

The lobbying group European Committee for Interoperable Systems (ECIS) today called on antitrust regulators worldwide to follow the European Commission and pressure Redmond into offering a browser ballot, similar to what the company began serving yesterday to European customers via Windows Update, everywhere. The ballot is offered to consumers on Windows XP, Windows Vista, and Windows 7.

ECIS members include Adobe Systems, Corel, IBM, Nokia, Opera, Oracle, RealNetworks, Red Hat, and Sun Microsystems. It was Norwegian browser maker Opera that first filed a complaint with the European Union in December 2007, accusing Microsoft of violating EU antitrust law by bundling IE with Windows. And the company isn't satisfied yet. "Opera is a member of ECIS, which supported the complaint to the European Commission because it promoted the ECIS core values of competition, interoperability and consumer choice," reads a statement in an ECIS press release today. "Microsoft agreed to change its business practices in the face of formal charges from the Commission. Consumers deserve the same unbiased browser choice on all the world's more than 1 billion personal computers." Of course, Opera doesn't rule the ECIS alone, but given that the lobbying group is mainly composed of Microsoft rivals, we doubt any of them would object to Opera's proposition.

Meanwhile, Microsoft has dismissed the ECIS' call to arms. "The issues in the Internet Explorer case have already been the subject of extensive legal action in several other countries around the world, including the United States, which have each developed their own legal solutions which are different than the browser choice screen pursued by the European Commission after years of litigation," a Microsoft spokesperson told Ars.

Microsoft is not obligated to take the ballot screen outside the boundaries of the EU, but the push from ECIS could spur other consumer groups, competition agencies, and antitrust regulators to band together against the software giant. It worked in Europe, but will it work in the rest of the world?


Friday, 26 February 2010

Two new browser plugins, partying like it's 1999

In a world that is slowly and surely moving away from depending on plugins to provide advanced features, the decision to release new browser plugins for Internet Explorer is surely a little surprising. Even the popular, widely used Flash is coming under fire, with many advocating a switch to native HTML 5 capabilities in favor of using the proprietary plugin.

Two new plugins are looking to turn the tide. First up we have Vision Engine 8 from 3D game engine developer Trinigy. The company's engine runs on a variety of platforms, and with the new plugin, the Web browser does too. The engine boasts Direct3D 11 support, Havok physics, and sophisticated multithreading support. This plugin allows complex 3D games to be played in the browser.

Browser-based games are big business, especially Flash-based games. The hugely popular FarmVille and Farm Town games on Facebook use Flash and have between them many tens of millions of users; and there are many more like them. The graphics of these games are limited in their complexity, and slowdowns when scenes get complex are commonplace. Many of the tower defense-style games, for example, can get extremely sluggish when there are lots of bullets flying around the screen. Proper 3D gaming engines should allow more flexible in-browser gaming without the same performance issues.

The thing is, it's not clear who would install a special plugin just to play 3D games in their Web browser. Quake Live provides Quake III through a browser plugin (albeit a single-purpose plugin that can only play Quake Live) and has failed to gain any significant traction. Existing browser games are successful because they fit into social networking and other sites that people already use, and because they stick with Flash—a plugin that virtually everyone has already, even on corporate desktops and other restricted environments. As such, the plugin seems to be a solution in desperate search for a problem. Sure, it means that you can play 3D games in your browser, but do you really want to?

Xiph.org's plugin
The next plugin at least has a clearly-defined purpose. The latest version of the Xiph.org codec pack for Windows includes an experimental IE plugin that brings limited support for the HTML 5 <> tag to Internet Explorer. The video tag is one of the more keenly anticipated parts of the HTML 5 specification, as it will enable sites such as YouTube to deliver videos using pure HTML, instead of having to depend on the Flash plugin, and a beta version of YouTube that uses the tag is already available.

One of the sticking points for adoption of the video tag is that Internet Explorer does not presently support it. The Xiph.org plugin strives to change that.

Presently, the plugin is only a Technology Preview, and its support is very limited indeed. The biggest long-term hurdle is that the plugin supports Theora video, not H.264. Although Theora is the format chosen by Firefox for its video tags, H.264 is the format being used by YouTube and similar sites that are trialling HTML 5. As Xiph.org only produces codecs for patent-free open source formats (Vorbis, Speex, and FLAC audio compression, Theora video compression), this limitation is not surprising, but it does mean that the plugin is unlikely to ever be particularly useful.

The plugin is currently only branded a "Technology Preview," too; it presently lacks virtually any features above and beyond playing video, including basics like offering playback controls. It also requires pages using video tags to be written in a specific way to ensure that IE even tries to load the plugin.

If the plugin ever reached a stage where it was stable and fully featured, it might yet achieve some significance. A long-standing issue with the HTML 5 video tag is that the HTML 5 specification itself does not specify which codecs should be supported. The result has been two camps (well, three if one includes Internet Explorer, which supports nothing at all); WebKit-based browsers (most significantly Safari and Chrome) support H.264. Mozilla-based browsers (most importantly Firefox) support Theora. Firefox leads WebKit in market share, so Theora should become more widely supported more quickly, but H.264 has more corporate backing (notably from Google and Apple).

A complete version of this plugin could swing things substantially in Theora's favor; as well as the 24 percent of web users using Firefox, the 60 percent using Internet Explorer would also be able to use Theora videos. Such a large target would make Theora support much harder for H.264's corporate backers to ignore.

That said, the days of the browser plugin are surely behind us. Flash gets a pass due to legacy and being the only widely deployed solution that can do the kind of thing it does (supporting rich interactivity, animation, audio and video, webcams and microphones), with Silverlight and perhaps Java the nearest also-rans, but anything else demanding a browser plugin? Fugeddaboutit. The trend is clearly towards extending HTML to provide these capabilities, not proprietary browser extension mechanisms, which makes producing a new plugin today quite an extraordinary thing to do.

Wednesday, 24 February 2010

Browser history hijack + social networks = lost anonymity

Simply joining a few groups at social networking sites may reveal enough information for hackers to personally identify you, according to some recent computer science research. In a paper that will be presented at a security conference later this year, an international team of academics describes how they were able to build membership sets using information that social networking sites make available to the public, and then leverage an existing attack on browsing history to check for personal identity. That information, they argue, can then be combined with other data to create further security risks, such as a personalized phishing attack.

The vulnerability of social networking groups is the product of a few decisions that require a balancing between security and usability. The first takes the form of providing unique identifying information for groups. Many social networking sites simply track groups (like "science writers" or "Ars Technica fans" by IDs in the form of integers. These IDs make their way into a browser's history because they're often incorporated into a URL via HTTP GET, which sends information to servers via variables incorporated into the URL.

It's possible to keep that information out of the URL by using HTTP POST instead, which transfers the data separately. But POST makes it impossible to bookmark a group's page, since that information is no longer part of the URL that's stored in a bookmark. So, from a user interface perspective, it's much better to use HTTP GET.

If the group ID is in the URL, then it also shows up in the browser history, and previous work has shown that the browser history is vulnerable to being scanned by malicious websites. Again, this is the product of good user interface, as sites are able to display links that have already been visited in distinct colors as an aid to navigation. To do that, they have to be able to know where a user has been, and there are a number of ways to do this using standard Web technology. "To date, the problem has not been solved as it is often viewed as a usability feature/design issue rather than a browser bug," the authors write.

So, it's possible to identify URLs that correspond to social networking groups, and then test a user's browser history for whether they've visited them. The last step in tracing back to individual users involved obtaining a list of social networking group members. It turns out that many sites make group membership lists public, and others will allow registered users to see the membership lists for groups. LinkedIn, the authors note, displays group membership information for individual users on their public profile page. On the German social site Xing, they were even able to get access to some private group membership information simply by sending requests from a dummy account—about 10 percent of the groups seemed to accept any membership requests that came in.

This required them to generate custom crawlers for each social networking site but, barring major site redesigns, those crawlers should be able to update membership lists indefinitely.

The authors built a complete membership list for every group they could access in Xing, and then analyzed what the intersection of various membership lists could tell them about an individual's identity. For Xing, it turns out that 42 percent of the group membership intersects provided an exact identity. In other words, by knowing what groups an individual belongs to, nearly half the time you could determine precisely who that individual is.

The amount of computational effort involved isn't especially significant, either. "In total, we successfully crawled more than 43.2 million group members from 31,853 groups in a period of 23 days using only two machines," the authors noted. They also performed a pilot analysis with Facebook, and showed that it was vulnerable as well, although its massive membership size made tackling it fully beyond the scope of this work.

With the group membership database built, all that's left is to test for the presence of member pages in a browser's cache. The authors produced a JavaScript that would do that, and tested it with browsers on several platforms. Performance generally paralleled published JavaScript results, with Safari and Chrome leading the pack, and IE well behind (in this case, that's a security feature). But the important thing is the raw numbers: using Safari, they could test 90,000 URLs in under 20 seconds using a 2.8GHz Core 2 Duo laptop.

Depending on the social network, knowing an individual's identity can open up a can of worms, as far as personal information goes. A person's bank account details is unlikely to appear there, but (as noted at top), having a more complete profile of an individual makes them susceptible to spear phishing attacks, or could leave them more vulnerable to abuse by personal information obtained from other sources.

A lot of this information may be available by other means, but the addition of social networking sites to the list of vulnerabilities simply makes it harder for individuals to take appropriate steps to protect themselves. And, since this attack relies on features that are generally considered essential to good interface design, preventing this risk may be nearly impossible.

Friday, 19 February 2010

Firm uses typing cadence to finger unauthorized users

Though most users feel anonymous when browsing the Web, their browsers constantly turn over unique information such as a list of installed plugins, screen resolution, and the user agent string. Taken together, such bits of information can uniquely identify many users even without cookies.

But this is now old tech; behavioral analytics firms have already moved on. Cookies, browser signatures, and IP addresses can all help identify particular machines and particular browsers—but how can you tell which human actually sits behind the terminal at a given moment? One way is by measuring the "cadence" of their typing.

Scout Analytics has done just that in order to help its 40 paid content clients detect and stop those "sharing" their accounts without permission. Imagine that you sell access to an expensive database, so expensive that users are routinely tempted to share their "named accounts" with others in the office rather than pay for additional licenses. You would probably want to "encourage" these users to pay up or stop sharing the account, but it's difficult to know which logins are legitimate and which are not.

Cookies, browsers, and biometrics

That's where a company like Scout comes in. I spoke with Matt Shanahan, VP of Strategy for the company, about a research project that Scout just concluded that tried to figure out exactly when more than one person was using a single named account.

At first, Scout of course tried using cookies to track this information, but this produced terrible data; it suggested that six or seven different devices were being used to access each account, a number that seemed far too high to be plausible. So Scout then added browser data, of the kind highlighted by the EFF's recent Panopticlick project, to prevent problems like cleared cookies. When applied to a data set of 20 million actual logins to paid content sites, this refined technique identified nearly 600,000 unique devices being used for access.

This produced a more accurate count of "cookied browsers," but not of "actual users." An expensive subscription service might well be accessed by multiple people using the same central office computer, for instance, all using the same login, same browser, and same cookie.

So Scout used some Javascript timing features to watch how users type when they enter their login credentials for various services. Shanahan says that his algorithms need a minimum of 5 attempts at entering a phrase of at least 12 characters in order to generate a typing "cadence." By watching repeated logins, Scout could soon categorize these cadences into a digital pattern, then assign each pattern a serial number.

"As you're typing, you have a cadence and rhythm," Shanahan says, a rhythm that includes how long one holds down various keys and how long it takes to move between keys. Applying the technology to its data set of 20 million logins, Scout pulled out 175,000 unique patterns—thereby identifying 175,000 distinct users, even when they used the same login credentials on the same machine.

But only 130,000 users had subscribed to the services in question, meaning that 45,000 of the 175,000 people using the services were freeriding. Even if cookie tracking were 100 percent accurate, it would be off by a factor of 2-4x when it comes to tracking individual users of a service.

These typing patterns aren't quite unique—Shanahan estimates that 1 in 20,000 people share the same pattern—but when you combine that with IP addresses and browser information, it's good enough for its intended purpose.

What companies do with this information is up to them. Shanahan says some use the soft sell, calling up clients who are allowing multiple users on a single account and reminding them of the terms of service. The goal isn't to browbeat customers, but to convince them to pay up for the additional licenses they appear to need. Other companies might choose the "irritate them into submission" approach, perhaps by resetting the account password whenever multiple unique users access an account. Scout estimates that such information can boost subscription revenues by 10-15 percent.

"The amount that can be known from the network is pretty amazing," Shanahan notes, and he concedes that few users even know that their machines enable tracking of this kind. But he does point out that the patterns created by Scout's software don't identify people; each cadence pattern identifies someone unique, but the software has no idea who the person is.

That may be cold comfort to groups like the EFF, which have long been wary of online tracking schemes. While Panopticlick showed just how easy it was to uniquely track browsers, analytics companies like Scout can already pick out a browser's unique users.

With a bit more work, a court order, and the cooperation of an ISP, the day might not be far off when the old "Hey, that must have been someone else using my computer!" defense comes to an end. On the flip side, such technology could provide evidence that it really was someone else at your machine.

The RIAA no doubt wishes it had access to this technology back when it was still suing file-swappers and meeting this very objection in court.