Google uncloaks Chrome's security goals

Google's Chrome security team has unveiled its guiding principles on how they build a safer browser.

Chrome's privacy controls.
(Screenshot by Seth Rosenblatt/CNET)

The manifesto declares seven key guidelines for Chrome security. The first one, "Don't get in the way", echoes Google's unofficial motto, "Don't be evil", and reflects what many Windows security vendors have learned the hard way about keeping people safe. If security negatively affects performance, users will look to alternatives. For a browser that has built its user base on speed, sluggish response times have the potential to wreak havoc.

"It's great to see invisibility and automatic background updates as the first principal. Good security is transparent and inescapable," said Chris Wysopal, chief technology officer at Veracode. "The less security decisions that involve the user the better. Every security decision made by the user is a chance that something with be postponed or forgotten or worse, an opportunity for social engineering."

Privacy is not mentioned in the list of principles, and that may raise the hackles of some security experts. "I think Google's approach to privacy is a little bit different than others," said Jeremiah Grossman, WhiteHat Security's chief technology officer. "They make the assumption that you trust them, but if you don't trust them then you have to separate the two. You can't protect your data that's on Google, from Google, because it's contrary to their business model."

Google does have a site dedicated to explaining privacy in Chrome, and it does have a company-wide privacy policy that applies to Chrome. However, there isn't a company policy statement on Chrome privacy like the new security manifesto.

Google told ZDNet Australia's sister site CNET that the Chrome security team works in close conjunction with Google's overall security team, as well as the Chrome team itself. "We protect users by embedding security deeply into our culture, as well as our process for designing and developing products. This relentless focus on security often benefits the web more broadly as well, either through our own action or through others who adopt similar approaches," the company said.

The need for speed has found its way into Chrome security, and the representative pointed to regular release note updates as evidence of this. "We've demonstrated that we will shine a light on security topics that are relevant to our users, even when most companies wouldn't," he said, with tough benchmarks set for response times and how long systems are left unpatched.

Of course, Google is hardly the only company to take this approach. Mozilla also regularly publishes security update release notes, and Microsoft has become so regular at publishing security updates to Internet Explorer and its other software that Patch Tuesday has become lingua franca in the computer security world.

Microsoft recently touted a decade of security achievements, and it's practically universally accepted that the company learned some tough lessons over the past 10 years.

Not surprisingly, Microsoft's current policies of a company-wide approach to security echo Google's similar stance with Chrome. Chrome's third core principle states that security is a "team responsibility", which was explained as meaning that browser security concerns go beyond the realm of just the Chrome security team to include Google's general security group and the general Chrome group. While this may sound obvious to some, cross-department communication has had an impact on the browser's development, Google said.

"Engaging the security community makes Google part of the security community. More technology companies should take this approach. They have set up a cooperative and non-adversarial posture. Microsoft pioneered this approach, but Google has taken it a step further with their bug bounties," said Wysopal.

Google has said that the quality of the bug reports has helped it to fix vulnerabilities much faster. The company has paid out more than US$200,000 for Chrome and Chromium-related security bugs found by bug hunters. The open-source progenitor of Chrome, Chromium was around for a year before Google debuted Chrome.

While likely familiar to many who keep tabs on browser security, the principles document stands as a place where Google can point to its achievements in the field, as well as its goals. Some of the Chrome features referenced in the document include the mention of anti-exploit technologies, such as JIT hardening, along with Google-sourced innovations, like the Safe Browsing API. The "Make the web safer for everyone" section notes numerous public-security standards, like public key pinning, SPDY and Native Client.

Grossman concluded that despite some concerns about Chrome, the project has been a boon for the web. "I think they're doing a lot more right than wrong when it comes to browser speed and security," he said.

Via CNET

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

I guess but in both cases, dead body!

3 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

4 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

4 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

5 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

5 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

5 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

6 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

6 hours ago by Beta on Regional review highlights NBN, mobile

michael kors outlet http://www.michael-kors-discount.com/#5923

6 hours ago by michael kors bag on Best iPhone travel apps

Hey butterflyeffecs and lex, Sorry you're not fans of this piece. But you're dead right in that it is the thoughts and experience of a se...

6 hours ago by LHopewell on Android fragmentation steers Vic Health

teen cams
http://www.aloe-vera.cz handjob

6 hours ago by MyncWenry on Fusion-io ioDrive (80GB)

We have fashional replica bags designer .Replica luxury bags sale here are perfect compromise of quality and price. The replica handbags ...

6 hours ago by Machelle on Telecom NZ CEO Paul Reynolds to leave

It's not a question of whether anyone at HSU would know how to do this, but whether they would have connections with people who could. T...

6 hours ago by meski on CT, phone clone

Fred, I can tell you what the difference between FTTN and FTTH is. FTTH means we will be developing technology and services that we sell ...

6 hours ago by andye on NBN FUD: will Abbott ever learn?

You are 100% right – Abbott is a paragon of tenacity. Now if he could only try that hard to get Malcolm Turnbull's phone number, we co...

7 hours ago by braue on NBN FUD: will Abbott ever learn?

Very interesting to hear Ben and thanks for providing some real-world examples. I suspect the NBN has actually improved things for a grea...

7 hours ago by braue on NBN FUD: will Abbott ever learn?

Hi Geoff, my opening paragraph simply suggests that the leader of the opposition party would rightfully be turning to his communications ...

7 hours ago by braue on NBN FUD: will Abbott ever learn?

Very good point Richard – perhaps one of the most interesting things about this whole debate is how extensively it feeds the collective...

7 hours ago by braue on NBN FUD: will Abbott ever learn?

Yes. I also wonder how much of this intentional subterfuge is actually playing out as part of Turnbull's master plan. Given the rough ri...

8 hours ago by braue on NBN FUD: will Abbott ever learn?

Westpac Management runs STG IT since the take over and it is they Westpac who makes the decisions.

8 hours ago by jeff_syd on St George opts to keep 200 IT workers

This story has been voted 12000 times in the last 24 hours!

9 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar