I'd just like to point out that Google significantly raised the state of the art with respect to browser security, specifically because they made it central to their effort. They had a more secure browser within a year than the other vendors had created since the birth of the web.
This is a minor setback and I have no doubt that they've learned not only just how to fix this set of bugs, but the bug classes they represent.
Netscape won (at the time) partly on "features", so browser competitors have to release features, balanced with their other priorities. Can't go back, can only go forward as responsibly as possible. Chrome has done this admirably.
I suggest looking at these tests through a half-full glass. There's a huge benefit in discovering multi-bug exploits, for Chrome, Google, other browser vendors and all users. When an attacker is looking to break into a computer, Chrome is not their most obvious starting point. In fact, IIRC Kevin Mitnick said this:
"KH: What’s the most secure OS? Is there one that you can recommend?
KM: I don’t know of any secure OS. In the past eight years, I’ve had 100% success at penetration testing on all of them. Wait, ChromeOS, ChromeOS is the most secure because of its very limited attack vector–there’s just nothing to exploit."
This is a minor setback and I have no doubt that they've learned not only just how to fix this set of bugs, but the bug classes they represent.
Netscape won (at the time) partly on "features", so browser competitors have to release features, balanced with their other priorities. Can't go back, can only go forward as responsibly as possible. Chrome has done this admirably.
I suggest looking at these tests through a half-full glass. There's a huge benefit in discovering multi-bug exploits, for Chrome, Google, other browser vendors and all users. When an attacker is looking to break into a computer, Chrome is not their most obvious starting point. In fact, IIRC Kevin Mitnick said this:
"KH: What’s the most secure OS? Is there one that you can recommend?
KM: I don’t know of any secure OS. In the past eight years, I’ve had 100% success at penetration testing on all of them. Wait, ChromeOS, ChromeOS is the most secure because of its very limited attack vector–there’s just nothing to exploit."
http://www.zdnet.com/blog/security/ghost-in-the-wires-the-ke...
That's progress, surely.