News: 1628227808

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft wonders if disabling just-in-time compilation of JavaScript improves browser security

(2021/08/06)


Microsoft is conducting an experiment it hopes will improve browser security – by making its Edge offering worse at running JavaScript

As explained in a [1]post by Johnathan Norman, the vulnerability research lead for Microsoft Edge, JavaScript is the juiciest target when trying to crack a browser – because engines like Google's [2]V8 and the just-in-time compilation (JIT) techniques they employ use "a remarkably complex process that very few people understand" and have "a small margin for error" in the way they handles code.

We live with that because the likes of V8 mean JavaScript zips along very nicely when used with JIT, making all sorts of in-browser fun possible.

[3]

But it also means all sorts of in-browser evil is possible. Norman cites data suggesting 45 per cent of CVEs issued for V8 were related to its JIT engine.

[4]

[5]

Norman argues that these days JIT doesn't make a massive difference to browser performance. He also points out that the presence of V8's JIT prevents the use of alternative mitigations.

Microsoft is therefore going to try to build what it calls "Super Duper Security Mode" for Edge, by disabling JIT and eventually adding other security mitigations – namely Controlflow-Enforcement Technology (CET) and Arbitrary Code Guard and Control Flow Guard.

[6]

Click to enlarge

"Super Duper Security Mode" is already available. Type edge://flags/#edge-enable-super-duper-secure-mode into Edge and the browser provides a long list of its security controls so you can see what you'll be missing if you decide to join Microsoft's experiment.

"This is of course just an experiment; things are subject to change, and we have quite a few technical challenges to overcome," Norman wrote. "Also, our tongue-in-cheek name will likely need to change to something more professional when we launch as a feature. For now, we are going to continue having fun with it."

[7]Google hits undo on Chrome browser alert change that broke websites, web apps

[8]Developing for Windows 11: Like developing for Windows 10, but with rounded corners?

[9]Internet Explorer downgraded to 'Walking Dead' status as Microsoft sets date for demise

A more "professional" (read: less goofy) name could be a good thing. Or maybe not.

Despite being baked into over a billion machines running Windows 10 – which includes rather insistent nagware encouraging use of the browser – Edge has just 3.41 per cent market share according to [10]statcounter Global Stats . A fun name like "Super Duper Security Mode" might make more of a difference to users than hard-to-appreciate changes to security plumbing. ®

Get our [11]Tech Resources



[1] https://microsoftedge.github.io/edgevr/posts/Super-Duper-Secure-Mode/

[2] https://v8.dev/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQ0IX4qNa1iZ0UmOwEjwIwAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQ0IX4qNa1iZ0UmOwEjwIwAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQ0IX4qNa1iZ0UmOwEjwIwAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://regmedia.co.uk/2021/08/06/shutterstock_edge_security.jpg

[7] https://www.theregister.com/2021/08/05/google_chrome_iframe/

[8] https://www.theregister.com/2021/06/28/developing_for_windows_11/

[9] https://www.theregister.com/2021/05/20/internet_explorer_death_day_set/

[10] https://gs.statcounter.com/browser-market-share

[11] https://whitepapers.theregister.com/



I have an easier fix...

Anonymous Coward

I configured my browser to never run JavaScript in the first place. There, security door closed, barred, & welded shut. Job done.

Re: I have an easier fix...

Anonymous Coward

That's similar to how I protect myself from car crashes. I never travel in an automobile. Likewise I know I'll never get food poisoning because I've stopped eating!

Bur seriously, if you don't run JavaScript in your browser you're not using 95% of the web. That's your choice, but your post implied that you still had a use for your browser. I guess you spend a lot of time on the wayback machine....

Re: I have an easier fix...

Geez Money

I'm not sure how you came to this but most sites work fine or with minimal degradation without JavaScript. There are poorly written sites which fail to and some web apps genuinely need it, but for the most part not any you'd miss. HTML5 continues to narrow that gap too.

Re: I have an easier fix...

bellcore

You can use addons like uMatrix/NoScript to block it by default and whitelist only specific subdomains.

Re: I have an easier fix...

garretmh

Ah yes, abstinence. “The only safe browsing is no browsing”

Squeaky Lobster

Anonymous Coward

Might be a while before the silly name gets changed. After all it was many years before the "Squeaky Lobster" Exchange server registry value became the much more boring "Show Advanced Counters".

https://techcommunity.microsoft.com/t5/exchange-team-blog/from-crush-to-product-documentation-the-story-of-squeaky-lobster/ba-p/604691

Making Edge worse at running JavaScript

Pascal Monett

Hey Microsoft, I've got a hint for you : integrate NoScript.

Job done.

Many missing the point

SsiethAnabuki

I came here expecting the usual "NoScript/I disabled javascript" posts and was not disappointed. Along, of course, with the "If yoiu disable JavaScript the whole internet will break" (again, not disappointed)

And, of course, they're missing the point. Microsoft isn't attempting to mitigate every flaw in JavaScript. They, along with the majority of the world, have accepted that considerably more than 99% of users aren't going to do that because they want to use the full functionality of the web or are completely unaware/unbothered by the additional security risk of JavaScript.

Instead Microsoft are basically targetting the folks who might hit the "secure" button if one is provided and seems to provide an acceptable level of functionality to them. I don't doubt that their marketing people are also getting all sweaty-handed about the notion of using the slogan "The most secure browsing experience" if they have the slightest excuse to use it.

Maybe they shouldn't wonder so loudly...

sreynolds

Sometimes its best to talk things out with a trusted friend before posting on a blog.

Cunning like a fox

bellcore

You can already do this in Firefox. Just go to about:config and disable javascript.options.baselinejit

A good scapegoat is hard to find.
A guilty conscience is the mother of invention.
-- Carolyn Wells