Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 12:26:01 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668810
Posts
71126
Topics
145740
Members
Latest Member:
sushil kumar
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Dragon - CD
Help - CD
Is the Flash plugin sandboxed like in Chrome
« previous
next »
Pages:
[
1
]
Author
Topic: Is the Flash plugin sandboxed like in Chrome (Read 4612 times)
Metalfyre
Comodo Family Member
Offline
Posts: 67
Is the Flash plugin sandboxed like in Chrome
«
on:
May 09, 2012, 12:07:25 PM »
I start this new topic becuz a moderator asked me to (even though it was somewhat on topic in the closed thread, but that aside)
Quote from: Metalfyre
When using Chrome the flashplayer is being sandboxed. So in other words, it cannot be exploited.
Quote from: HeffeD
It was exploited just a couple of months ago. Pwn2Own 2012: Google Chrome browser sandbox first to fall | ZDNet
If you want to continue a flash/sandbox discussion, please start your own thread.
Yes, it was exploited ONCE, while hackers admit that they rather not touch Chrome becuz of it's enhanced security. And it's the sandboxed feature that actually enhances it. You fail to mention that there have been attempts during these hacker conventions before where the hackers failed BECAUSE of the sandboxed technology.
Pointing out that sandboxing technology might be flawed, doesn't really suit you as a moderator for a security company that makes a firewall with a sandbox as well.
What would have suited you before closing the topic was a simple yes or no to my initial question, which was: "Does CD sandbox the flash plugin like Chrome does?"
The response I gave (as mentioned here above as a quotation) was in direct answer to the person who started that topic becuz he didn't understand what I meant with sandboxing.
And my answer was the correct one in terms of it's definition. But as we all know, even sandboxing technology can be exploited, but it at least gives another layer of protection as opposed to using no sandbox at all.
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #1 on:
May 09, 2012, 05:17:21 PM »
Sorry for the misunderstanding, but that topic is not closed...
The reason I suggested creating a new topic was because the original post was regarding an issue updating Flash. Asking a question regarding the sandbox in a thread about an updating issue is off-topic.
I didn't answer as to whether or not Dragon sandboxes Flash like Chrome does, because I don't know the answer to that.
And I wasn't saying the techology was flawed. Merely that it
had
been exploited quite recently.
I'm sorry if you feel that me asking you to create a new topic doesn't suit me as a moderator. Off-topic posting is against the
Forum Policy
, and I wouldn't be doing my job as a moderator if I didn't say something. If you don't agree with this, you do have a recourse.
How to appeal against Moderators decisions
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Metalfyre
Comodo Family Member
Offline
Posts: 67
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #2 on:
May 10, 2012, 12:45:56 AM »
If you do not know, then just say that.
I just assume that a simple question like that was answerable since CD is based off of Chrome source. If CD states that it is exactly like Chrome with the exception of some privacy instrusive behaviour, then it seems that in fact it should also be able to use it's sandboxed technology.
It is somewhat related to the updating Flash issue, as Chrome automatically updates Flash in it's browser becuz it's integrated so it can use the sandbox technology. So it wasn't that "off-topic" as you stated. Even the OP didn't see the problem.
So is there anybody that knows enough about Comodo products that can answer my initial question?
Logged
JoWa
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 2953
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #3 on:
May 10, 2012, 02:07:06 AM »
No, it is not sandboxed in Dragon as it is in Google Chrome. The reason is that Google Chrome on Windows uses a special version of Flash Player (gcswf32.dll). If you use this version of Flash Player with Dragon, it will be sandboxed, just as it is when used with Google Chrome.
I think we can expect changes when the
PPAPI-version
of Flash Player is released later this year.
Notice the Job-tab in the images.
FlashPlayer-Dragon-Chrome.png
(45.81 KB, 893x519 - viewed 16 times.)
FlashPlayer-Dragon.png
(26.61 KB, 447x519 - viewed 13 times.)
Logged
Ubuntu 13.04, 64-bit | Chrome 28β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Metalfyre
Comodo Family Member
Offline
Posts: 67
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #4 on:
May 10, 2012, 06:20:46 AM »
Thank you very much JoWa for your very clear explanation. This was a very helpful answer. Much appreciated.
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #5 on:
May 10, 2012, 03:02:54 PM »
Quote from: Metalfyre on May 10, 2012, 12:45:56 AM
I just assume that a simple question like that was answerable since CD is based off of Chrome source. If CD states that it is exactly like Chrome with the exception of some privacy instrusive behaviour, then it seems that in fact it should also be able to use it's sandboxed technology.
It's not such a simple question...
Dragon is not based on Chrome, it is based on Chromium. Chromium is not Chrome. Chrome has features that Chromium does not, such as a built-in .pdf reader, Flash Player, and Google's automatic updater.
Since Dragon is based on Chromium, (as are all of the Chrome clones) it has all of Chromium's features, but not Chrome's.
I have never used Chrome, so I haven't kept up on all of the differences between Chromium and Chrome. Sorry about that.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Metalfyre
Comodo Family Member
Offline
Posts: 67
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #6 on:
May 10, 2012, 03:44:15 PM »
HeffeD, actually it turned out to be a really simple answer, as you can notice by JoWa's reply. It's just that one has to have that knowledge. You didn't, and that's okay, but just mention it when you do not know an answer. No biggie ^^
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #7 on:
May 10, 2012, 04:22:47 PM »
Since I didn't attempt to answer the question, I would have thought it obvious that I didn't know the answer.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Metalfyre
Comodo Family Member
Offline
Posts: 67
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #8 on:
May 15, 2012, 11:24:05 AM »
Quote from: HeffeD on May 10, 2012, 04:22:47 PM
Since I didn't attempt to answer the question, I would have thought it obvious that I didn't know the answer.
lol, I am not a mindreader HeffeD
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #9 on:
May 15, 2012, 12:28:40 PM »
You don't need to be. You asked why I didn't answer the question, and I said I didn't know the answer. Why is this a problem?
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Metalfyre
Comodo Family Member
Offline
Posts: 67
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #10 on:
May 15, 2012, 12:43:34 PM »
Who said that it's a problem? If you make assumptions then that is open for misinterpretation. You should know this. It's never safe to just assume anything as that's where the most misunderstandings come from.
Just like you seem to assume there is a problem.
You however stated in this topic ->
https://forums.comodo.com/help-cd/sandboxing-t83679.0.html
an answer that you could as well have given me as well, or pointed me to the topic in which you state and I quote:
"I'm no expert on the differences between Chrome and Chromium's sandboxes, so perhaps someone else has more information.
Chrome does sandbox the Flash plugin, and since Chromium doesn't come bundled with Flash like Chrome, I'm assuming it does not sandbox Flash.
So there may be a slight advantage there in terms of Flash exploits, but like I said, I don't know all of the differences. (if any)
Even though you express you don't know for sure, it would at least have been an answer, which is better than to assume that by not giving an answer at all the other party can safely say that you don't know at all.
If you don't give a direct answer, or stay quiet, it is open to any interpretation to the other party.
Now, that being said, you at least have to concur with that. If you don't, well that's okay too ofcourse cuz nobody actually likes to agree upon anything that contradicts that what has been stated the first time. That's only logical.
I have my answer, all I am saying is, as a moderator (or even just as a human being) it's not all that wise to assume anything, as assumptions are often at the base of misunderstandings. And that is something you cannot disagree upon, as it's just plain fact. That's all.. no problem. I never actually thought that you would think I see it as a problem. My replies at least did not indicate any of the sorts.
«
Last Edit: May 15, 2012, 12:45:35 PM by Metalfyre
»
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #11 on:
May 15, 2012, 12:49:07 PM »
I am sorry for the misunderstanding.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
JoWa
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 2953
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #12 on:
May 18, 2012, 02:33:15 PM »
Quote from: JoWa on May 10, 2012, 02:07:06 AM
I think we can expect changes when the
PPAPI-version
of Flash Player is released later this year.
Actually
Chrome Canary
has “PepperFlash” (PPAPI) and it can be used with the stable version of Chrome, but I can’t get it to work with Dragon.
Chrome 20 Dev for Linux also has PepperFlash, but not Chrome 20 Dev for Windows.
PepperFlash-Chrome19-W7.png
(23.92 KB, 628x483 - viewed 4 times.)
PepperFlash-process-Security.png
(22.68 KB, 447x519 - viewed 0 times.)
PepperFlash-process-Job.png
(20.46 KB, 447x519 - viewed 0 times.)
PepperFlash-Chrome20-Ubuntu.png
(12.17 KB, 395x242 - viewed 0 times.)
Logged
Ubuntu 13.04, 64-bit | Chrome 28β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4068
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #13 on:
May 18, 2012, 05:36:02 PM »
Pepperflash made a brief appearance in Dragon 17.3/4 -
Re: Comodo Dragon ver 17.4 is now available for download
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
JoWa
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 2953
Re: Is the Flash plugin sandboxed like in Chrome
«
Reply #14 on:
May 22, 2012, 03:01:13 AM »
Google Chrome 21 (Dev)
for Windows has PepperFlash.
Chrome21Dev-PepperFlash.png
(15.47 KB, 640x355 - viewed 5 times.)
Logged
Ubuntu 13.04, 64-bit | Chrome 28β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.096 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com