Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well either Google and Mozilla are knowingly shipping insecure code or Microsoft is, to some degree, wrong. Given the history of the organisations in question I'm going to assume Microsoft wrong or not telling the whole story until we hear a response from Moz or Google.


Microsoft has the perspective of the entire OS from top to bottom. Google and Firefox have the perspective of their respective applications.

Given the concerns Microsoft is voicing (and they aren't the first to voice them) are well below the application itself, I tend to trust Microsoft more on this one.


What about Apple? They're clearly working on WebGL support for Safari. They have at least equal insight into the whole stack, considering the ship the GPU drivers with the OS.

Then there's XNA in Silverlight. If they believe in the security of that, why not build WebGL on top of it? Probably because they're in direct competition with one another, and Microsoft wants Silverlight to win.


Apple has announced that, for now, WebGL on iOS will only be available to WebKit when it's displaying advertisements through iAd (where Apple controls which ads are distributed), and not to web pages generally.

http://www.theregister.co.uk/2011/06/16/webgl_in_ios_5/


I would think that security in this regard is far easier for Apple than it is for Microsoft. By virtue of their closed hardware, Apple has a very limited set of graphics cards for OS X to support. I'd imagine that this makes graphics drivers a lot easier to police and keep secure.


Let's face it, AMD, nVidia and Intel have >99% of the PC GPU market, and 100% of the Mac market. The drivers only change from one chip generation to the next, and the Mac has had chips from all recent generations from all 3 manufacturers. The total number of drivers is therefore identical. I really don't think there's much in it. See also: Silverlight's XNA.


Silverlight's integration with the host browser, DOM and Javascript is pretty good.

I'm pretty sure you could build a WebGL API on top of Silverlight by yourself. It would suck, but it is possible.

That's why I always thought Silverlight is pretty cool as a technology, as compared to Flash. Among other things, a Silverlight plugin could also allow you to serve OGG Theora videos to users.


This is an argument from ignorance and, knowing engineers at both Google and Microsoft, I have no reason to believe that the Google engineers are any more competent than Microsoft. I do know that the Google security team is smaller than Microsoft's.


Hence the 'not telling the whole story' part. Would Microsoft play politics with something like this? Not saying that's the case, only that one would have to be silly to think they wouldn't.


This is a false dichotomy. Mozilla and Google could both be unknowingly introducing the possibility of bugs and errors. The depth of their testing could be inadequate -- bugs could occur only on certain combinations of hardware and driver (and even, versions of drivers).


I believe Google and Mozilla (doesn't Safari support WebGL?) are shipping code that interfaces with insecure GPU drivers.

We cannot, however, discount the incentive Microsoft has in preventing the formation of another standard it can't control. I would consider any info coming from Redmond on this issue to be somewhat exaggerated.

And Windows-specific.


Speaking as someone doing security research on WebGL but no real dog in this fight (aside from developing on WebGL on the side, making me potentially biased in its favor), nothing MS has said is Windows-specific or remotely exaggerated. In fact, they explicitly didn't talk about many potential attack vectors against WebGL, which makes me think they really don't care much about this either way.


I asked Paul Irish, Chome Developer relations: @paul_irish re http://bit.ly/kOZ7Lp - MSFT wrong? Security risk in Chrome/FF with WebGL?

http://twitter.com/#!/paul_irish/status/81492337108328448 @AlexGraul i think chrome's record in pwn2own is a good indicator of our commitment to security while delivering great features. :)


Note he didn't actually answer the question.


I'm not at all an expert to handle details about the security of WebGL. I have no idea on that front.

I do know Chrome and FF just fixed a timing attack vector where you could apparently intuit the content of a crossdomain image by interpreting what hues were based on it via the application of shaders. Which means hypothetically you could read text. Like a crazy-person's OCR.


Or like virtual Van Eck phreaking.

http://en.wikipedia.org/wiki/Van_Eck_phreaking




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: