Microsoft tightens Edge security for less visited websites
- Reference: 1659978908
- News link: https://www.theregister.co.uk/2022/08/08/microsoft_edge_security_browsing/
- Source link:
The new feature is part of a number of [1]security updates in version 104.0.1293.47 announced this month that are designed to reduce the risk for the five Edge users users as they move around the internet.
Edge is designed to give users a full browsing experience using technologies like JavaScript, according to Microsoft. "On the other hand, that power can translate to more exposure when you visit a malicious site," the vendor [2]wrote as it outlined the feature. "With enhanced security mode, Microsoft Edge helps reduce the risk of an attack by automatically applying more conservative security settings on unfamiliar sites and adapts over time as you continue to browse."
[3]
The enhanced security mode reduces memory-related vulnerabilities by disabling just-in-time (JIT) JavaScript compilation and applying more OS protections for the browser, including Hardware-enforced Stack Protection and Arbitrary Code Guard.
[4]
[5]
"When combined, these changes help provide 'defense in depth' because they make it more difficult than ever before for a malicious site to use an unpatched vulnerability to write to executable memory and attack an end user," the company wrote.
Microsoft a year ago ran an experiment that included [6]disabling JavaScript JIT compilation to open the way for more security protections. Johnathan Norman, principal security engineering manager at Microsoft, wrote in a [7]blog post at the time that "JavaScript engine bugs are a mainstay for attackers for a variety of reasons; they provide powerful exploit primitives, there is a steady stream of bugs, and exploitation of these bugs often follows a straightforward template."
[8]
JITs were put into browsers starting 2008 to speed up particular JavaScript tasks by taking loosely typed JavaScript and compiling it to machine code just before it's needed and is useful in making JavaScript perform better. However, such performance and complexity can result in more security bugs and more patches; turning off JIT can help improve security, Norman wrote.
[9]Chromium's WebRTC zero-day fix arrives in Microsoft Edge
[10]Canonical adds instance tweaking to Multipass, Confidential VMs to Azure
[11]Google fiddles with cross-platform Flutter and Dart to boost performance, tooling
[12]Ubuntu on a phone, anyone? UBports reaches 18th stable update, but it's still based on 16.04
[13]OK, Google: Unshackled from Windows, Edge team is free to follow where Chromium leads
With the enhanced security feature, the Basic security level will be the default when the "Enhance your security on the web" browsing mode – which is optional – is enabled in settings. The Basic setting ensures the user experience on the most popular sites on the web remain intact while adding security mitigations for those sites visited less frequently.
Shifting to the Balanced level will include the new features for such times, while ensuring most of the other sites work as expected. If a user chooses the Strict security level, security features will be added for all sites on the web – those frequently and infrequently visited – and could mean that parts of some sites won't work.
"However, you can still manually add sites to the exception site list and enterprise admin configuration will still apply, if present," Microsoft wrote. "Strict mode isn't appropriate for most end users because it may require some level of configuration for the user to complete their normal tasks."
In addition, enterprise administrators can use Group Policy settings to include "allow" and "deny" lists to enhance the security for their users when visiting certain sites while disabling the mode for others.
[14]
Another security feature will enable users to import data from Google Chrome during Edge's First Run Experience – an annoying feature that occurs when users open Edge for the first time and shows a welcome page with information, tips, and recommended actions for improving their experience with the browser – without having Chrome installed.
With the new feature, users can log into their Google account during the First run Experience. The feature can be turned off by disabling First Run Experience with the HideFirstRunExperience policy or by setting AutoImportAtFirstRun to "DisabledAutoImport," Microsoft [15]wrote in its Edge policies pages. ®
Get our [16]Tech Resources
[1] https://docs.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel#version-1040129347-august-5
[2] https://docs.microsoft.com/en-us/deployedge/microsoft-edge-security-browse-safer
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YvGHhwbTBDhx9Fn4djRXwwAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvGHhwbTBDhx9Fn4djRXwwAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvGHhwbTBDhx9Fn4djRXwwAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/06/edge_super_duper_security_mode/
[7] https://microsoftedge.github.io/edgevr/posts/Super-Duper-Secure-Mode/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvGHhwbTBDhx9Fn4djRXwwAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/07/07/edge_cves/
[10] https://www.theregister.com/2022/08/01/canonical_multipass_azure/
[11] https://www.theregister.com/2021/09/08/google_flutter_dart/
[12] https://www.theregister.com/2021/07/20/ubports_ubuntu_touch_ota_18/
[13] https://www.theregister.com/2021/03/16/edge_cadance/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvGHhwbTBDhx9Fn4djRXwwAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://techcommunity.microsoft.com/t5/enterprise/how-to-hide-the-first-run-experience-in-the-new-microsoft-edge/td-p/1145307
[16] https://whitepapers.theregister.com/
Re: Please stop saying
According to StatCounter, it's the third most popular browser behind Chrome and Safari - ahead of Firefox, Samsung and Opera.
And please nobody say "people need to use it once to download a proper browser", because that's obvious, hackneyed, silly and untrue. I repeat, Edge gets more day-to-day usage than Firefox . It deserves some respect.
That's a nice little website you have there,
shame if we made it annoying to access via our software. Maybe if you use our new $$$ a month verification product you too can be a popular site and not an annoying site.
Disabling JIT?
Unless they do something similar to NoScript most of the scripting attack vectors are still there.
I am aware that NoScript is probably a bit too much hassle for non technical users as half the web sites display something along the lines of "please enable scripting, this site depends on it" and another quarter simply displays a blank page.
I still wonder why no browser allows to block scripts by default but allow them for specific sites in a session in a simple way like NoScript for advanced users.
Please stop saying
That there are only five Edge users. There are probably as many as ten, possibly even a dozen.