Menu
Custom Web browser from Comodo poses security threat, researcher says

Custom Web browser from Comodo poses security threat, researcher says

The browser has the 'same origin policy' disabled

A customized version of Google's Chrome browser developed by security vendor Comodo has a jaw-dropping flaw, according to a researcher.

Tavis Ormandy, an information security engineer with Google, analyzed Comodo's "Chromodo," a browser based on the Chromium open-source code.

Chromodo is marketed as a browser with enhanced security and privacy controls. But Ormandy found it contains a flaw that violates one of the most basic rules for Web security.

Code that runs on one website shouldn't be allowed to execute on another since it would pose a great security risk. It's known as the same origin policy.

For some reason, the same origin policy was disabled in Chromodo, Ormandy wrote in an advisory.

"Chromodo is described as 'highest levels of speed, security and privacy,' but actually disables all web security," he wrote.

Ormandy typically gives companies 90 days to patch a flaw before going public, and he started writing about Chromodo on Jan. 21.

On Tuesday he updated the advisory, saying that it appeared Comodo tried to patch Chromodo against an exploit he developed. But the patch isn't effective and he planned on filing a fresh bug report.

Comodo officials reached Tuesday didn't have an immediate comment. The company is one of the largest sellers of SSL/TLS certificates, which encrypt data traffic, and other security products.

On Tuesday, Ormandy wrote on Twitter: "Selling antivirus doesn't qualify you to fork chromium, you're going to screw it up."

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments