homeappliancesbrands
  • Home
  • blog
  • privacy policy
  • about us
  • English
    • English
    • Japanese
  • Home
  • /
  • blog
  • /
  • Stop JIT ~ Microsoft test...

Stop JIT ~ Microsoft tests "Mt -Great Security Mode" in "Edge"


 On August 4 (local time), Microsoft announced the new security function of "Microsoft Edge" "SUPER DUPER Secure Mode".Although it is still an experimental stage, the name is not official, but it is likely to be anxious for users who value security rather than performance.

 According to the company, there are various attacks that pierce the JavaScript engine defect, but the basics have not changed for a long time, and are being performed in the following patterns.

 The defects discovered by the security team can be proven simply by copying and paste this template, and the attacker has a system that can immediately abuse it using a framework like "PWNJS".

 But this is a nightmare for the defense side.When a defect is found, it must be dealt with quickly and encourage users to update.As a result, web browser vendors, such as Microsoft, Google, and Mozilla, make large -scale investments in the development of techniques for finding defects, and have prepared large -scale sweepstakes programs to promote hackers to report problems.Nevertheless, the current situation is that the JavaScript engine has been a security issue for Web browsers.

 The company's security team proposes a solution to stop the performance technology of the JavaScript engine called "Just in Time Compilation" (JIT).

 According to a survey of CVE (recognition number assigned to vulnerabilities) after 2019, about 45 % of the vulnerabilities found in the JavaScript engine V8 are related to the JIT engine.Furthermore, more than half of the cases that were misused before the correction in "Chrome", were abusing JIT bugs, according to Mozilla.

JITをやめてみる ~Microsoft、「Edge」で「めっちゃすげえセキュリティモード」をテスト

 JIT is becoming more complicated year by year to raise the performance of the Web browser, but has created half of the security defects that require corrections.Is it worth the speed up?

関連記事

"Google Chrome 91" has a maximum performance improved -two major improvements on the "V8" engine

 The advantage of JIT disabling is not only reducing the attack surface (that is, vulnerability).The JIT of "V8" cannot be used in the renderer process of some powerful security easing measures due to its mechanism.For example, Intel's new hardware-based Exploit easing (ControlFlow-enforcement Technology) has not been used in the renderer process.Also, because the RWX memory page is used, the "ACG" (ArbitRary Code Guard) is also disabled.If these technologies can be applied to the renderer process, security will be dramatically improved.

関連記事

"Google Chrome 90" Windows version introduces stack protection with hardware -Skinth attacks are also shut out!

 However, there are no concerns that disabling JIT will significantly reduce performance.So I tested how much the performance of the web browser changes depending on the presence or absence of JIT, but it certainly said that some tests had improved, but in most cases there was no significant change in performance.

JITの有無でWebブラウザーのパフォーマンスがどれだけ変わるのかをテストした結果

 In addition, although the power consumption was average 15 % improvement in power consumption, which increased by about 11 %, but rather increased by about 11 %.In some cases.In other tests, it seems that there are some improvements and worsening.

 So far, JIT has been promoted as a trump card to improve performance.For example, on the "Speedometer 2.0" benchmark, if JIT is disabled, the score will be reduced by 58 %.But can the user feel the invalidation of JIT in the actual use case?

改善と悪化の平均

 Either way, you won't be able to answer if you don't actually compare two versions of web browsers.In the coming months, the company plans to implement CET, ACG, and CFG (Control Flow Guard, control flow guard) in the Rendar process in the "Super Duper Secure Mode" project.If you want to actually try it, try to enable the "SUPER DUPER Secure Mode" flag in the preview version "Edge" (Beta/Dev/CANARY) in the test stage (edge: // flags/).At present, JIT (Turbofan/Sparkplug) is disabled and CET can be tested.However, please note that webassembly has not been supported yet.

「Super Duper Secure Mode」フラグ


09 / Jun / 2022 homeappliancesbrands

Category

blog

Related Articles

29.May.2025

What Makes a Wireless Power Bank Truly Portable?

Many consumers resort to wireless power banks for the sole reason that they do not need a wired connection to charge their mobile phones. All they need to do is put their smartphones on top of the wir...

29.May.2025

Why Choose Anker for Your iPhone Charging Needs?

With iPhones playing a central role in our work, communication, and entertainment, keeping them charged efficiently and safely is more important than ever. Whether you're upgrading to the latest i...

29.May.2025

What Makes USB-C to Lightning Cables So Essential?

In our digital lives, our devices are only as useful as their ability to stay charged and connected. Whether you're syncing data, powering up in a pinch, or using accessories, having the right cab...

17.Mar.2025

How to Maintain and Extend Your Robot Vacuum’s Lifespan

A robot vacuum is a valuable home assistant, saving time and effort by keeping floors clean with minimal supervision. However, like any smart device, it requires regular upkeep to perform at its best....

Hot Articles

EVsmart blog Toyota's electric car "bZ4X" that makes you feel comfortable with electric cars and quick chargers / No% display of battery level [Editorial department] Popular articles Recent posts Category

EVsmart blog Toyota's electric car "bZ4X" that makes you feel comfortable with electric cars and quick chargers / No% display of battery level [Editorial department] Popular articles Recent posts Category

23.Apr.2022
 Lenovo's 8.8 inch one-handed tab "Legion Y700" full specs released!  [Is the price in the 40,000 yen range?]

Lenovo's 8.8 inch one-handed tab "Legion Y700" full specs released! [Is the price in the 40,000 yen range?]

01.May.2022
# Remote desktop from the beginning-Connecting to your home computer from outside (IPv4)

# Remote desktop from the beginning-Connecting to your home computer from outside (IPv4)

28.Apr.2022
What is the mechanism of "universal control" that enables direct cooperation just by arranging Mac and iPad side by side?

What is the mechanism of "universal control" that enables direct cooperation just by arranging Mac and iPad side by side?

30.Mar.2022

Tags

How to turn off the security mode of Samsung tablet

Copyright © 2023 homeappliancesbrands.com. All rights reserved.