Feeds

Google Chrome OS: Too secure to need security?

Confident anti-virus-less chocolateers may be repeating Apple's mistakes

Boost IT visibility and business value

A leading security researcher has warned that Google risks repeating Apple's mistakes on security with its new Chrome OS.

Google Chrome OS is a Linux-based operating system designed to work exclusively with web applications. Chrome netbooks running the new OS will be available from Google's partners Samsung and Acer from June. In a launch announcement, Google boasted of an end to patching and anti-virus updates woes.

Chromebooks have many layers of security built in so there is no anti-virus software to buy and maintain. Even more importantly, you won't spend hours fighting your computer to set it up and keep it up to date.

Rik Ferguson, a security consultant at Trend Micro, criticised this line as marketing rhetoric. Google risks repeating the security mistakes of Apple, he warns.

Security features of Chrome OS include process sandboxing (so any app is unable to interfere with other apps on a system), automatic updating and a reversion to the last known good state if any problems are detected. This latter feature is possible because user files are stored in the cloud (and encrypted), with only system files held locally.

In addition, every application in Chrome OS will run inside the browser, with only (sandboxes) browser plug-ins running locally.

However this sterile environment is unlikely to last long, not least because Google has created a a Software Development Kit that allows the creation of Chrome "native apps", according to Ferguson, who reckons this open the door towards the creation of malware.

Sandboxing technology ought to prevent any bad apps that are created getting out of their play pen. But Ferguson warns that sandboxing technology is no panacea for security woes.

"Exploits that break out of sandboxing have already been demonstrated for Internet Explorer, for Java, for Google Android and of course for the Chrome browser (to name but a few), while the Google sandbox is effective, it is not impenetrable and to rely on it for 100 per cent security would be short-sighted," he said.

Rebooting laptops and storing data in the cloud is just "moving the goalposts" for scammers, Ferguson further argues. Instead of stealing data on a compromised device, the motivation will shift towards swiping authentication keys. "If I can infect you for one session and steal your keys, well then I'll get what I can while I'm in there and then continue accessing your stuff in the cloud; after all I've got your keys now, I don't need your PC anymore," Ferguson writes.

Ferguson praises Google for its engineering work but questions its apparent suggestion that switching OSes is a "silver bullet" capable of killing off the modern myriad of security woes. He draws a comparison between Google's claim that Chrome needs no anti-virus and similar claims in the past by Apple.

The essential guide to IT transformation

More from The Register

next story
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
Microsoft: Azure isn't ready for biz-critical apps … yet
Microsoft will move its own IT to the cloud to avoid $200m server bill
Oracle reveals 32-core, 10 BEEELLION-transistor SPARC M7
New chip scales to 1024 cores, 8192 threads 64 TB RAM, at speeds over 3.6GHz
Docker kicks KVM's butt in IBM tests
Big Blue finds containers are speedy, but may not have much room to improve
US regulators OK sale of IBM's x86 server biz to Lenovo
Now all that remains is for gov't offices to ban the boxes
Gartner's Special Report: Should you believe the hype?
Enough hot air to carry a balloon to the Moon
Flash could be CHEAPER than SAS DISK? Come off it, NetApp
Stats analysis reckons we'll hit that point in just three years
Dell The Man shrieks: 'We've got a Bitcoin order, we've got a Bitcoin order'
$50k of PowerEdge servers? That'll be 85 coins in digi-dosh
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.