+ Reply to Thread
Page 1 of 3 123 LastLast
Results 1 to 15 of 32

Thread: Which Browsers Are The Most Secure?

  1. #1
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581

    Which Browsers Are The Most Secure?

    Do a test here.

    It's a "suite of security tests that measure whether the browser supports JavaScript APIs that allow safe interactions between sites, and whether it follows industry best practices for blocking harmful interactions between sites".
    Security - What are the Security Tests? - Browserscope

    You can then compare your results with those of the main browsers.



    Spoiler The safest:


    You can see the good results FF gets. Chrome 8 seems the safest of all, but it's only in assuming that you can be safe in the middle of Google's tentacles. Anyway as usual FF can easily get better: It seems FF 4 beta6 with noscript "scripts globally allowed" enabled has a higher score than Chrome 8.




    Spoiler The unsafest:


    You can contemplate here the weak score 10.63 Opera's browser gets. IE8 itself seems even better. Poor Opera users are really living in an insecure world....





    NB: Some trolls-like sentences are included in this thread. Will you able to find them ?
    Last edited by Renk; 14.11.10 at 20:14.
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    saebrtooth (15.11.10) , slikrapid (14.11.10) , BrianBosworth (14.11.10) , SealLion (14.11.10) , SBcheater (14.11.10)

  3. #2
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,439
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39439
    My score:
    Spoiler Click >>>:
    1. PASS postMessage API
    2. PASS JSON.parse API
    3. FAIL toStaticHTML API
    4. PASS httpOnly cookie API
    5. PASS X-Frame-Options
    6. FAIL X-Content-Type-Options
    7. FAIL Block reflected XSS
    8. PASS Block location spoofing
    9. PASS Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. FAIL Strict Transport Security
    14. PASS Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. FAIL Cross Origin Resource Sharing
    17. PASS Block visited link sniffing


    Can't comment on the troll-like sentences.

    Is there any browser that passes all the checks?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  4. #3
    1. PASS postMessage API
    2. PASS JSON.parse API
    3. FAIL toStaticHTML API
    4. PASS httpOnly cookie API
    5. PASS X-Frame-Options
    6. FAIL X-Content-Type-Options
    7. FAIL Block reflected XSS
    8. PASS Block location spoofing
    9. PASS Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. FAIL Strict Transport Security
    14. PASS Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. PASS Cross Origin Resource Sharing
    17. FAIL Block visited link sniffing
    Reply With QuoteReply With Quote
    Thanks

  5. #4
    Retired Seal
    SealLion's Avatar
    Join Date
    03.05.08
    Location
    The Arctic--Believe it!!
    Posts
    2,079
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2079
    Here is my result of the test
    1. PASS postMessage API
    2. PASS JSON.parse API
    3. FAIL toStaticHTML API
    4. PASS httpOnly cookie API
    5. PASS X-Frame-Options
    6. FAIL X-Content-Type-Options
    7. FAIL Block reflected XSS
    8. PASS Block location spoofing
    9. PASS Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. FAIL Strict Transport Security
    14. PASS Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. PASS Cross Origin Resource Sharing
    17. FAIL Block visited link sniffing


    ---------- Post added at 12:34 ---------- Previous post was at 12:33 ----------

    Pretty much the same as TheDeathless results.
    "God, from the mount Sinai
    whose grey top shall tremble,
    He descending, will Himself,
    in thunder, lightning, and loud trumpet’s sound,
    ordain them laws".


    John Milton (1608-1674) in Paradise Lost


    Ripley's SealLion's Believe it or Not! ~ NASCAR car crashes and Windows have just one thing in common.
    Oh, oh. Better use LINUX.
    Reply With QuoteReply With Quote
    Thanks

  6. #5


    Join Date
    22.06.08
    Location
    astral planes
    P2P Client
    sbi finest
    Posts
    3,125
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss3125
    1. PASS postMessage API
    2. PASS JSON.parse API
    3. PASS toStaticHTML API
    4. PASS httpOnly cookie API
    5. PASS X-Frame-Options
    6. PASS X-Content-Type-Options
    7. PASS Block reflected XSS
    8. PASS Block location spoofing
    9. PASS Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. PASS Strict Transport Security
    14. PASS Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. PASS Cross Origin Resource Sharing
    17. FAIL Block visited link sniffing
    13/17, as expected for firefox
    Reply With QuoteReply With Quote
    Thanks

  7. #6
    I'm using FireFox on Ubuntu 10.10 with all updates.
    Reply With QuoteReply With Quote
    Thanks

  8. #7


    Join Date
    22.06.08
    Location
    astral planes
    P2P Client
    sbi finest
    Posts
    3,125
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss3125
    firefox version 3.6 (9/17) vs. 3.6.12 (13/17), let me guess: you haven't restarted it recently
    Reply With QuoteReply With Quote
    Thanks

  9. #8
    My version is 3.6.12 how is possible our result are different ?
    Reply With QuoteReply With Quote
    Thanks

  10. #9


    Join Date
    22.06.08
    Location
    astral planes
    P2P Client
    sbi finest
    Posts
    3,125
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss3125
    i also use Adblock Plus & NoScript add-ons, maybe thats the reason why
    Reply With QuoteReply With Quote
    Thanks

  11. Who Said Thanks:

    SealLion (14.11.10)

  12. #10
    Also I use adblock plus. No I will try NoScript (Is also made in italy ) and post my result.

    ---------- Post added at 21:15 ---------- Previous post was at 21:12 ----------

    1. PASS postMessage API
    2. PASS JSON.parse API
    3. PASS toStaticHTML API
    4. PASS httpOnly cookie API
    5. PASS X-Frame-Options
    6. PASS X-Content-Type-Options
    7. PASS Block reflected XSS
    8. PASS Block location spoofing
    9. PASS Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. PASS Strict Transport Security
    14. PASS Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. PASS Cross Origin Resource Sharing
    17. FAIL Block visited link sniffing

    13/17
    Last edited by piratemeister; 14.11.10 at 21:16.
    Reply With QuoteReply With Quote
    Thanks

  13. #11
    Retired Seal
    SealLion's Avatar
    Join Date
    03.05.08
    Location
    The Arctic--Believe it!!
    Posts
    2,079
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2079
    I guess mine's a little bit better now. Thanks slik for the comment suggesting that No Script might be the detail involved.

    1. PASS postMessage API
    2. PASS JSON.parse API
    3. PASS toStaticHTML API
    4. PASS httpOnly cookie API
    5. PASS X-Frame-Options
    6. PASS X-Content-Type-Options
    7. PASS Block reflected XSS
    8. PASS Block location spoofing
    9. PASS Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. PASS Strict Transport Security
    14. PASS Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. PASS Cross Origin Resource Sharing
    17. FAIL Block visited link sniffing
    I guess I now have the same results as yourselves. :)
    "God, from the mount Sinai
    whose grey top shall tremble,
    He descending, will Himself,
    in thunder, lightning, and loud trumpet’s sound,
    ordain them laws".


    John Milton (1608-1674) in Paradise Lost


    Ripley's SealLion's Believe it or Not! ~ NASCAR car crashes and Windows have just one thing in common.
    Oh, oh. Better use LINUX.
    Reply With QuoteReply With Quote
    Thanks

  14. #12
    Advanced User
    Join Date
    30.07.09
    P2P Client
    Azureus™
    Posts
    847
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssss847
    1. PASS postMessage API
    2. PASS JSON.parse API
    3. PASS toStaticHTML API
    4. PASS httpOnly cookie API
    5. PASS X-Frame-Options
    6. PASS X-Content-Type-Options
    7. PASS Block reflected XSS
    8. PASS Block location spoofing
    9. PASS Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. PASS Strict Transport Security
    14. PASS Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. PASS Cross Origin Resource Sharing
    17. PASS Block visited link sniffing
    14/17
    _____

    ---------- Post added at 00:21 ---------- Previous post was at 00:20 ----------

    ff, latest stable.
    Reply With QuoteReply With Quote
    Thanks

  15. #13
    Retired Seal
    SealLion's Avatar
    Join Date
    03.05.08
    Location
    The Arctic--Believe it!!
    Posts
    2,079
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2079
    17. PASS Block visited link sniffing
    tokio, how did you manage to get this as a pass and we got ours as a fail??
    Last edited by SealLion; 15.11.10 at 02:48.
    "God, from the mount Sinai
    whose grey top shall tremble,
    He descending, will Himself,
    in thunder, lightning, and loud trumpet’s sound,
    ordain them laws".


    John Milton (1608-1674) in Paradise Lost


    Ripley's SealLion's Believe it or Not! ~ NASCAR car crashes and Windows have just one thing in common.
    Oh, oh. Better use LINUX.
    Reply With QuoteReply With Quote
    Thanks

  16. #14
    Moderator
    Instab's Avatar
    Join Date
    17.09.09
    Posts
    6,661
    Activity Longevity
    4/20 17/20
    Today Posts
    0/5 sssss6661
    Code:
       1. PASS postMessage API
       2. PASS JSON.parse API
       3. PASS toStaticHTML API
       4. FAIL httpOnly cookie API
       5. PASS X-Frame-Options
       6. PASS X-Content-Type-Options
       7. PASS Block reflected XSS
       8. PASS Block location spoofing
       9. PASS Block JSON hijacking
      10. PASS Block XSS in CSS
      11. FAIL Sandbox attribute
      12. FAIL Origin header
      13. PASS Strict Transport Security
      14. PASS Block cross-origin CSS attacks
      15. FAIL Content Security Policy
      16. PASS Cross Origin Resource Sharing
      17. PASS Block visited link sniffing
    also the test requires js which i have disabled by default normally
    Your account has been disabled.
    Reply With QuoteReply With Quote
    Thanks

  17. Who Said Thanks:

    SealLion (15.11.10)

  18. #15
    Member illusive's Avatar
    Join Date
    24.10.10
    P2P Client
    What ?! That's Private!
    Posts
    512
    Activity Longevity
    2/20 16/20
    Today Posts
    3/5 ssssss512
    1. FAIL postMessage API
    2. FAIL JSON.parse API
    3. FAIL toStaticHTML API
    4. FAIL httpOnly cookie API
    5. FAIL X-Frame-Options
    6. FAIL X-Content-Type-Options
    7. FAIL Block reflected XSS
    8. PASS Block location spoofing
    9. FAIL Block JSON hijacking
    10. PASS Block XSS in CSS
    11. FAIL Sandbox attribute
    12. FAIL Origin header
    13. FAIL Strict Transport Security
    14. FAIL Block cross-origin CSS attacks
    15. FAIL Content Security Policy
    16. FAIL Cross Origin Resource Sharing
    17. FAIL Block visited link sniffing
    I'm using FireFox 1.5.0.4
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread
Page 1 of 3 123 LastLast

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •