Microsoft Issues Warning About WebGL, a Feature of Firefox and Chrome

The Microsoft Security Research & Defense team this week issued a serious warning about WebGL, a web browser technology that is supported by both Mozilla Firefox and Google Chrome. And they’re not screwing around.

Our analysis has led us to conclude that Microsoft products supporting WebGL would have difficulty passing Microsoft’s Security Development Lifecycle requirements. Some key concerns include:

Browser support for WebGL directly exposes hardware functionality to the web in a way that we consider to be overly permissive

Browser support for WebGL security servicing responsibility relies too heavily on third parties to secure the web experience

Problematic system DoS scenarios

We believe that WebGL will likely become an ongoing source of hard-to-fix vulnerabilities. In its current form, WebGL is not a technology Microsoft can endorse from a security perspective.

Yikes. Well, there you go.

Discuss this Article 1

etharis
on Jun 20, 2011
When Steve Gibson of Gibson Research agrees with Microsoft on the dangers of WebGL, it makes you think.

Please or Register to post comments.

IT/Dev Connections

Las Vegas
September 30th - October 4th

Paul ThurottYou'll have the opportunity to experience:
• 120 Technical
Sessions
• Networking with Peers
• Expert Speakers


Come See Paul Thurrott & Mary Jo Foley in Person!

Register Now

Office 365 InfoCenter

Get the latest insight and info from Paul

Read Now!

What I Use