Do any of these exploits require any sort of brute-force or CPU-intensive stuff which would be far easier with the massive improvements in JS performance? I wondered if new vulnerabilities might be a side-effect of the JS 'arms race' between Chrome, IE and FF.
Re: JS speed
CRIME is a side-effect. It's a side-channel attack that tries to determine the cookie by sniffing for encryption optimizations in the SSL/TLS channel. Compressing the channel to optimize transmission was part of the optimization rush, but it resulted in the side channel.
GROUJSN? Worst initialism ever.
Qualys laughs at your BEAST
Even if your banking website is vulnerable, you still get an 'A'...
- Xmas Round-up Ten top tech toys to interface with a techie’s Christmas stocking
- Xmas Round-up Ghosts of Christmas Past: Ten tech treats from yesteryear
- Google embiggens its fat vid pipe Chromecast with TEN new supported apps
- Exploits no more! Firefox 26 blocks all Java plugins by default
- Review Hey Linux newbie: If you've never had a taste, try perfect Petra ... mmm, smells like Mint 16