[VIDEO] Quarri Technologies Founder on Browser Security

Transcription

thing is that compared to three years ago there's a lot more there's a lot of innovation in browser security which means that the general recognition that browsers bring a a certain risk you know to to to Applications web applications and to the the system the end system itself right so if you look at it at a top level it looks like there's a lot of browser security but actually if you dig deep there's vendors are trying to you know very Innovative vendors are trying to solve different problems that the the browser um presents you know some are trying to prevent the the infection of a pristine you know clean device through the Web Channel others are trying to secure the the browser in the face of an already compromised dirty endpoint right so there's different you know there's there's different innovations that are occurring and different focuses you know on on Solutions all within the realm of browser security and the great thing is is that there's there's this Innovation happening right you know in in this space to try to solve these very real you know customer problems because the existing Solutions don't really address it well obviously we have to stay on top of where the you know what the attack surfaces you know are the attack surfaces are constantly moving right so we have like I should say IE yeah I10 has a bunch of additional kind of security websockets you know local database um large you know web storage um there's there's so you know the attx surface is going to alter and so clearly as a as a company focused on PR security we have to kind of keep maintaining and looking at all the different ways that that um people can try to exploit uh vulnerabilities or attack a browser sure and when we talk about websockets CU um that's particularly inter to me I know almost nobody properly secures them today um how do you is it just by isolating it or because when I think websockets I know there's no encryption it's all clear yeah there's there um actually I think there is an option to encrypt web sockets I do believe I don't think anybody uses it I've never seen it used the thing the thing is is that um I've seen some proof of Concepts there hasn't been any attack in the wild the tax yet that I'm aware of that um that leverage websockets but there's certainly been proof of Concepts that have turned like a sure like a uh an endpoint into like a network scanner yeah right via a an inbound web socket that you know that basically activates the browser um to do additional kind of Port scanning the um but we can control it with um because we can control all the networking that happens within a a protected browser so that's just kind of one instance of of you know kind of the the the various attack attack surface and you know vulnerabilities and and you know the controls that we need to kind of create and and allow users to apply so when you're talking about controlling the networking is the um uh is that inbound request routed in a different way such that it's not part of the regular uh stack on whatever my operating system is so it's a separate network interface for all intents and purposes no I mean it's it's it's delivered as HT in HTTP payload right I mean we just control we think of this as being a firewall that sits in the browser so that the rest of the browser logic Cod logic can't you know to accept this an inbound socket request web socket request we have to we ver verify that it's been allowed by policy so if we say we can say ah you know what you can only this browser can only interact yeah with with you know.com you know and and shorts.com and nowhere else then if a websocket you know either attempts to go someplace or you know to be originated and go someplace or come in from another place that isn't on one of those two wh listed locations will block it so you know that you probably know that cookies are very limited in terms of the amount of storage I think it's one it varies but it's like one one kilobyte 2 kilobytes of of data um with web storage you can you know store multi megabytes sure I use it for offline Google mail exactly I me Gil and G drive all the time exactly so a lot of it is to support offline mode uh of operations um the bottom line is that means that that data is now even if it was delivered over an SSL tunnel yeah is now decrypted and it's sitting in the clear on the disc yeah right so real time um malware can can grab it um you don't even have to be malware you just another application on the machine can you know whether it's File Explorer or something else can go in and and look at that data um so what we do is anything that's written to disk within a protected browser is encrypted um you know and it's it's the only the only thing that the only thing that has the symmetric key is the the protected browser itself so um so we use that to obviously encrypt the data as it's being written to disk and decrypt the data so when it's read from disk so you know what that what that means is that you get um all the benefits of offline you know offline use or caching or disc cookies you know the use you know because there's usability around disc cookies um that um you get that without the risk of exposure at the end point right because they're not in the clear for any other application they don't have the crypto so they would they would need to attack and try to Brute Force the actual data which is hard because it's 256bit rc4 so sure but what's your stance on whether it's you know the certificate Authority or ocsp pinning or some other kind of protocol or authenticity check to make sure that the SSL certificate is in fact good well that's a that's a really good question and it's been a huge issue right I mean it's it's you know diginotar and Komodo and I mean there there's pretty well publicized stories about how you know how much you can trust uh certificate authorities but um what we do um is because we're we're sold and deployed by a web application owner right um so we're not a endpoint security product we we were sold to a High's web app that wants to secure the other end of their their their connections right to their web server so one of the things we can take advantage of is the fact that the web the web application owner knows what SSL certificates he uses on his web servers sure right so what we allow you to do is when you get the protected browser push down into the end us machine regardless of platform iOS Android or or Windows we can also deliver a whitelisted set of CN and thumb prints of allowed certificates or Casa so what that does is it says to the browser the protected browser our protected browser basically says you can only do SSL with those certificates and so this is if the certificate store on the local machine's been poisoned yeah right the end user has been socially engineered in accepting you know a bogus certificate Authority or or or SSL certificate they would be blocked we would only because we only allow htps connections from the protected browser to those those servers presenting those those CN and thums so it's local then uh and you don't have to worry about calling out to ca over ocsp or anything like that no in fact that's what we're doing is we're leveraging the knowledge that the website owner has of his SSL infrastructure and his CS push it down in a an encrypted policy right and so then what you're saying is ignore the certificate store that could already is likely poisoned got it yeah and it defeats host you know defeat SSL man in the middle um I mean the challenge is is end user awareness I mean there's a lot of companies that think because they've got that padlock yeah and you know that their data is protected right so part of it is just an education that you know and users excuse me you or website owners people aren't stealing the data over the wire they're stealing it at the browser it's a lot easier to steal data at the browser so part of it is just an awareness thing right and um and that's that's probably our our greatest challenge is just um explaining that articulately and um you know and and get getting into budgets right because you know you got to get into a a you know a c ciso kind of budget cycle and those sorts of things but it's it's a huge issue um you know because people thought they were protected by by the padlock and they not

This transcript was generated automatically from the video's captions and may contain errors.

Published: Apr 9, 2013
Updated: Jul 16, 2021
1 minute read

Browser and security vendors alike have been rushing to reduce the risks of web applications. One such vendor is Quarri Technologies with its Protect on Q solution. The basic idea behind Protect on Q is to provide web application owners with the ability to deliver secured, protected browser to end users.

In an exclusive interview with eSecurity Planet, Mark Elliot, founder of Quarri Technologies explains what the current browser threat landscape looks like and why HTML5 requires new security mitigations.

Read the full story at eSecurity Planet:
Quarri Securing the Browser from HTML5 Risks [VIDEO]

Sean Michael Kerner is a senior editor at InternetNews.com, the news service of the IT Business Edge Network, the network for technology professionals Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.