Qhov kev tso tawm tom ntej ntawm Chrome 86 thiab kev tso tawm ruaj khov ntawm Chromium tau raug tso tawm.

Cov kev hloov loj hauv Chrome 86:

  • tiv thaiv kev xa tawm tsis zoo ntawm cov ntaub ntawv nkag rau ntawm nplooj ntawv thauj khoom hla HTTPS tab sis xa cov ntaub ntawv hla HTTP.
  • Kev thaiv cov downloads tsis zoo (http) ntawm cov ntaub ntawv ua tiav yog ua tiav los ntawm kev thaiv cov ntaub ntawv tsis zoo ntawm cov ntaub ntawv (zip, iso, thiab lwm yam) thiab tso tawm cov lus ceeb toom rau kev rub tawm tsis zoo ntawm cov ntaub ntawv (docx, pdf, thiab lwm yam). Cov ntaub ntawv thaiv thiab ceeb toom rau cov duab, ntawv nyeem, thiab cov ntaub ntawv xov xwm yuav tsum nyob hauv qhov kev tso tawm tom ntej. Kev thaiv yog siv vim tias rub tawm cov ntaub ntawv tsis muaj encryption tuaj yeem siv los ua qhov phem los ntawm kev hloov cov ntsiab lus thaum MITM tawm tsam.
  • Cov ntawv qhia zaub mov lub neej ntawd qhia txog "Ib txwm qhia tag nrho URL" kev xaiv, uas yav tas los yuav tsum tau hloov cov chaw ntawm nplooj ntawv hais txog: chij los pab. Tag nrho URL tuaj yeem pom los ntawm ob-nias ntawm qhov chaw nyob bar. Cia peb nco ntsoov koj tias pib nrog Chrome 76, los ntawm lub neej ntawd qhov chaw nyob pib qhia yam tsis muaj tus txheej txheem thiab www subdomain. Hauv Chrome 79, qhov teeb tsa kom rov qab tus cwj pwm qub raug tshem tawm, tab sis tom qab cov neeg siv tsis txaus siab, tus chij sim tshiab tau ntxiv rau hauv Chrome 83 uas ntxiv ib qho kev xaiv rau cov ntawv qhia zaub mov kom lov tes taw zais thiab qhia tag nrho URL hauv txhua yam.
    Rau ib feem me me ntawm cov neeg siv, ib qho kev sim tau tsim los tso saib tsuas yog sau npe hauv qhov chaw nyob bar los ntawm lub neej ntawd, tsis muaj cov ntsiab lus thiab cov lus nug. Piv txwv li, es tsis txhob "https://example.com/secure-google-sign-in/" "example.com" yuav pom. Lub hom phiaj xav tau yuav tsum coj mus rau txhua tus neeg siv hauv ib qho ntawm cov kev tshaj tawm tom ntej. Txhawm rau lov tes taw tus cwj pwm no, koj tuaj yeem siv "Ib txwm qhia tag nrho URL" kev xaiv, thiab saib tag nrho URL, koj tuaj yeem nyem rau ntawm qhov chaw nyob bar. Lub hom phiaj ntawm qhov kev hloov pauv yog lub siab xav los tiv thaiv cov neeg siv los ntawm phishing uas tswj hwm qhov tsis sib xws hauv URL - cov neeg tawm tsam siv kom zoo dua ntawm cov neeg siv kev tsis txaus siab los tsim qhov zoo li qhib lwm lub vev xaib thiab ua txhaum kev dag ntxias (yog tias qhov hloov pauv no pom tseeb rau tus neeg siv kev txawj ntse. , ces cov neeg inexperienced yooj yim poob rau tej yam yooj yim manipulation).
  • Txoj kev pib tshem tawm FTP kev txhawb nqa tau rov ua dua tshiab. Hauv Chrome 86, FTP yog neeg xiam oob qhab los ntawm lub neej ntawd li ntawm 1% ntawm cov neeg siv, thiab hauv Chrome 87 qhov kev cuam tshuam ntawm kev xiam oob qhab yuav nce mus rau 50%, tab sis kev txhawb nqa tuaj yeem rov qab los siv "--enable-ftp" lossis "-- enable-features=FtpProtocol" chij. Hauv Chrome 88, kev txhawb nqa FTP yuav raug kaw tag nrho.
  • Nyob rau hauv version rau Android, zoo ib yam li cov version rau desktop systems, tus password manager siv ib tug check ntawm saved logins thiab passwords tiv thaiv ib tug database ntawm compromised accounts, tso saib ceeb toom yog pom muaj teeb meem los yog sim siv tsis tseem ceeb passwords. Daim tshev yog nqa tawm tawm tsam cov ntaub ntawv npog ntau dua 4 billion tus account uas tau tshwm sim hauv cov neeg siv cov ntaub ntawv xau. Txhawm rau tswj hwm tus kheej, tus hash prefix raug txheeb xyuas ntawm tus neeg siv sab, thiab cov passwords lawv tus kheej thiab lawv tag nrho cov hash tsis raug xa mus rau sab nraud.
  • Lub pob "Safety check" thiab hom kev tiv thaiv zoo dua tiv thaiv qhov chaw txaus ntshai (Enhanced Safe Browsing) kuj tau raug xa mus rau Android version. Lub pob "Safety check" qhia txog cov ntsiab lus ntawm cov teeb meem kev nyab xeeb, xws li kev siv cov passwords cuam tshuam, cov xwm txheej ntawm kev tshuaj xyuas qhov chaw tsis zoo (Safe Browsing), muaj qhov hloov tshiab uninstalled, thiab kev txheeb xyuas cov add-ons siab phem. Kev tiv thaiv qib siab ua kom muaj kev kuaj xyuas ntxiv los tiv thaiv phishing, kev ua phem thiab lwm yam kev hem thawj hauv Web, thiab tseem suav nrog kev tiv thaiv ntxiv rau koj tus lej Google thiab Google cov kev pabcuam (Gmail, Drive, thiab lwm yam). Yog hais tias nyob rau hauv ib txwm Safe Browsing hom checks yog ua nyob rau hauv lub zos siv ib tug database ib ntus loaded mus rau tus neeg siv qhov system, ces nyob rau hauv Enhanced Safe Browsing cov ntaub ntawv hais txog nplooj ntawv thiab downloads nyob rau hauv lub sij hawm ntawm lub sij hawm raug xa mus rau kev txheeb xyuas ntawm Google sab, uas tso cai rau koj los teb sai sai. kev hem thawj tam sim tom qab lawv raug txheeb xyuas, tsis tas tos kom txog thaum lub npe dub hauv zos hloov kho.
  • Ntxiv kev txhawb nqa rau cov ntaub ntawv qhia ".well-known/hloov-password", uas cov tswv ntawm lub vev xaib tuaj yeem qhia qhov chaw nyob ntawm daim ntawv web rau hloov tus password. Yog tias tus neeg siv cov ntawv pov thawj raug cuam tshuam, Chrome yuav tam sim no qhia tus neeg siv nrog daim ntawv hloov pauv tus password raws li cov ntaub ntawv hauv cov ntaub ntawv no.
  • Cov lus ceeb toom "Safety Tip" tshiab tau raug coj los siv, tso tawm thaum qhib qhov chaw uas nws lub npe zoo ib yam li lwm qhov chaw thiab kev tshawb fawb qhia tias muaj qhov ua rau muaj qhov tsis zoo (piv txwv li, goog0le.com qhib tsis yog google.com).

    * Kev them nyiaj yug rau Back-forward cache tau ua tiav, muab kev taw qhia tam sim thaum siv cov nyees khawm "Rov qab" thiab "Forward" lossis thaum taug kev los ntawm cov nplooj ntawv yav dhau los saib ntawm qhov chaw tam sim no. Lub cache tau qhib siv lub chrome://flags/#back-forward-cache setting.

  • Optimizing CPU cov peev txheej siv rau lub qhov rais sab nraud. Chrome xyuas seb lub qhov rais browser puas sib tshooj los ntawm lwm qhov rais thiab tiv thaiv kev kos duab pixels hauv thaj chaw sib tshooj. Qhov kev ua kom zoo no tau qhib rau qee feem me me ntawm cov neeg siv hauv Chrome 84 thiab 85 thiab tam sim no tau qhib txhua qhov chaw. Piv nrog rau kev tshaj tawm yav dhau los, kev tsis sib haum xeeb nrog cov tshuab virtualization uas ua rau cov nplooj ntawv dawb tshwm tuaj kuj raug daws.
  • Ntxiv peev txheej trimming rau tom qab tabs. Cov tabs no tsis tuaj yeem haus ntau dua 1% ntawm CPU cov peev txheej thiab tuaj yeem qhib tsis pub ntau tshaj ib zaug hauv ib feeb. Tom qab tsib feeb ntawm kev nyob hauv keeb kwm yav dhau, tabs tau khov, tshwj tsis yog cov tab uas tab tom ua si cov ntsiab lus multimedia lossis kaw.
  • Kev ua haujlwm tau rov pib dua ntawm kev sib koom ua ke Tus Neeg Siv-Agent HTTP header. Hauv qhov tshiab version, kev txhawb nqa rau Tus Neeg Siv-Agent Client Hints mechanism, tsim los ua ib qho kev hloov rau Tus Neeg Siv-Agent, tau qhib rau txhua tus neeg siv. Cov txheej txheem tshiab no suav nrog kev xaiv rov qab cov ntaub ntawv hais txog qhov browser tshwj xeeb thiab qhov tsis ua haujlwm (version, platform, thiab lwm yam) tsuas yog tom qab kev thov los ntawm server thiab muab sijhawm rau cov neeg siv los xaiv cov ntaub ntawv zoo li no rau cov tswv ntawm lub xaib. Thaum siv User-Agent Client Hints, tus cim tsis raug xa mus los ntawm lub neej ntawd yam tsis muaj kev thov meej, uas ua rau tsis muaj kev txheeb xyuas tsis tau (los ntawm lub neej ntawd, tsuas yog lub npe browser qhia).
    Qhov taw qhia ntawm qhov muaj qhov hloov tshiab thiab qhov yuav tsum tau rov pib dua browser rau nruab nws tau hloov pauv. Hloov cov xub xim, "Hloov kho" tam sim no tshwm nyob rau hauv tus account avatar teb.
  • Kev ua haujlwm tau ua tiav los hloov lub browser kom siv cov ntsiab lus suav nrog. Hauv cov npe txoj cai, cov lus "dawb dawb" thiab "blacklist" tau hloov nrog "daim ntawv tso cai" thiab "blocklist" (twb tau ntxiv cov cai yuav ua haujlwm ntxiv, tab sis lawv yuav qhia cov lus ceeb toom txog kev raug tshem tawm). Hauv cov lej thiab cov npe cov ntaub ntawv, cov ntaub ntawv xa mus rau "blacklist" tau hloov nrog "blocklist". Cov neeg siv pom cov ntawv xa mus rau "blacklist" thiab "whitelist" tau hloov pauv thaum pib ntawm 2019.
    Ntxiv qhov kev sim muaj peev xwm los hloov cov passwords khaws tseg, qhib siv lub "chrome://flags/#edit-passwords-in-settings" chij.
  • Native File System API tau raug xa mus rau qeb ntawm API ruaj khov thiab muaj nyob hauv pej xeem, tso cai rau koj los tsim cov ntawv thov web uas cuam tshuam nrog cov ntaub ntawv hauv cov ntaub ntawv hauv zos. Piv txwv li, API tshiab tuaj yeem xav tau hauv qhov browser-raws li kev tsim kho ib puag ncig, ntawv nyeem, duab thiab video editors. Txhawm rau kom ncaj qha sau thiab nyeem cov ntaub ntawv lossis siv cov lus sib tham qhib thiab txuag cov ntaub ntawv, nrog rau kev taug qab cov ntsiab lus ntawm cov npe, daim ntawv thov nug tus neeg siv kom paub meej tshwj xeeb.
  • Ntxiv CSS selector ":focus-pom", uas siv tib yam heuristics uas browser siv thaum txiav txim siab seb puas yuav qhia qhov kev hloov pauv qhov taw qhia (thaum txav mus rau lub pob kom pom tseeb siv cov keyboard shortcuts, qhov taw qhia tshwm, tab sis thaum nias nrog tus nas. , tsis yog). Yav dhau los muaj CSS selector ":focus" ib txwm ua kom pom tseeb. Tsis tas li ntawd, qhov "Quick Focus Highlight" kev xaiv tau raug ntxiv rau cov chaw, thaum qhib, qhov taw qhia ua kom pom tseeb ntxiv yuav raug pom nyob ib sab ntawm cov ntsiab lus tseem ceeb, uas tseem pom tau txawm tias cov ntsiab lus tseem ceeb rau kev pom qhov pom kev tsom xam yog xiam oob qhab ntawm nplooj ntawv ntawm CSS. .
  • Ob peb API tshiab tau ntxiv rau Origin Trials hom (kev sim cov yam ntxwv uas yuav tsum tau ua kom cais tawm). Keeb Kwm Kev Txiav Txim hais txog kev muaj peev xwm ua haujlwm nrog API teev tseg los ntawm cov ntawv thov rub tawm los ntawm localhost lossis 127.0.0.1, lossis tom qab sau npe thiab tau txais lub cim tshwj xeeb uas siv tau rau lub sijhawm txwv rau ib qhov chaw tshwj xeeb.
  • WebHID API rau qib qis nkag mus rau HID cov cuab yeej (Tib neeg cov khoom siv sib cuam tshuam, cov keyboards, nas, gamepads, touchpads), uas tso cai rau koj los siv cov laj thawj ntawm kev ua haujlwm nrog HID ntaus ntawv hauv JavaScript los teeb tsa kev ua haujlwm nrog cov cuab yeej HID tsawg yam tsis muaj qhov tshwm sim. cov tsav tsheb tshwj xeeb hauv qhov system. Ua ntej tshaj plaws, API tshiab yog tsom rau kev txhawb nqa gamepads.
  • Screen Information API, txuas ntxiv qhov Window Placement API los txhawb kev teeb tsa ntau lub vijtsam. Tsis zoo li window.screen, API tshiab tso cai rau koj los tswj qhov kev tso kawm ntawm lub qhov rais nyob rau hauv tag nrho cov chaw tshuaj ntsuam ntawm ntau lub tshuab, tsis tas yuav txwv rau lub vijtsam tam sim no.
  • Meta tag roj teeb-txuag, uas lub vev xaib tuaj yeem qhia rau tus browser txog qhov xav tau los qhib hom kom txo qis kev siv hluav taws xob thiab txhim kho CPU load.
  • COOP Kev Qhia API los tshaj tawm cov kev ua txhaum cai ntawm Cross-Origin-Embedder-Policy (COEP) thiab Cross-Origin-Opener-Policy (COOP) hom kev cais tawm, yam tsis siv cov kev txwv tiag tiag.
  • Daim Ntawv Pov Thawj Kev Tswj Xyuas API muaj ib hom ntawv pov thawj tshiab, PaymentCredential, uas muab kev pom zoo ntxiv ntawm kev them nyiaj ua haujlwm. Ib tog neeg vam khom, xws li lub txhab nyiaj, muaj peev xwm tsim tau tus yuam sij rau pej xeem, PublicKeyCredential, uas tuaj yeem thov los ntawm cov tub lag luam kom paub meej txog kev them nyiaj ruaj ntseg ntxiv.
  • Lub PointerEvents API rau kev txiav txim siab qhov qaij ntawm lub stylus * tau ntxiv kev txhawb nqa rau lub kaum sab xis (lub kaum sab xis ntawm lub stylus thiab lub vijtsam) thiab azimuth (lub kaum sab xis ntawm X axis thiab qhov projection ntawm lub stylus ntawm lub vijtsam), es tsis txhob TiltX thiab TiltY cov ces kaum (lub kaum sab xis ntawm lub dav hlau los ntawm lub stylus thiab ib qho ntawm cov axes thiab lub dav hlau los ntawm Y thiab Z axes). Kuj tseem ntxiv kev hloov pauv hloov pauv ntawm qhov siab / azimuth thiab TiltX / TiltY.
  • Hloov cov encoding ntawm qhov chaw nyob rau hauv URLs thaum xam nws nyob rau hauv raws tu qauv handlers - tus navigator.registerProtocolHandler() txoj kev tam sim no hloov chaw nrog "% 20" es tsis txhob ntawm "+", uas unifies tus cwj pwm nrog rau lwm yam browsers xws li Firefox.
  • Ib qho pseudo-element ":: marker" tau ntxiv rau CSS, tso cai rau koj los kho cov xim, qhov loj me, cov duab thiab hom lej thiab cov dots rau cov npe hauv cov blocks Thiab .
  • Ntxiv kev txhawb nqa rau Document-Policy HTTP header, uas tso cai rau koj los teeb tsa cov cai rau kev nkag mus rau cov ntaub ntawv, zoo ib yam li sandbox cais tawm tswv yim rau iframes, tab sis ntau dua. Piv txwv li, los ntawm Document-Policy koj tuaj yeem txwv tsis pub siv cov duab tsis zoo, lov tes taw JavaScript APIs qeeb, teeb tsa cov cai rau kev thauj khoom iframes, cov duab thiab cov ntawv, txwv tag nrho cov ntaub ntawv loj thiab kev khiav tsheb, txwv tsis pub txoj hauv kev uas ua rau nplooj ntawv redrawing, thiab lov tes taw Scroll-To-Text muaj nuj nqi.
  • Rau lub ntsiab ntxiv kev txhawb nqa rau 'inline-grid', 'grid', 'inline-flex' thiab 'flex' tsis tau teeb tsa ntawm 'display' CSS cov cuab yeej.
  • Ntxiv ParentNode.replaceChildren() txoj kev los hloov tag nrho cov me nyuam ntawm niam txiv node nrog lwm DOM node. Yav dhau los, koj tuaj yeem siv qhov sib xyaw ntawm node.removeChild() thiab node.append() lossis node.innerHTML thiab node.append() los hloov cov nodes.
  • Qhov ntau ntawm URL schemes uas tuaj yeem hla dhau siv registerProtocolHandler() tau nthuav dav. Cov npe ntawm cov phiaj xwm suav nrog cov kev cai tswj hwm kev tswj hwm cabal, dat, puas, dweb, ethereum, hyper, ipfs, ipns thiab ssb, uas tso cai rau koj los txhais cov kev txuas rau cov ntsiab lus tsis hais lub xaib lossis lub rooj vag muab kev nkag mus rau cov peev txheej.
  • Ntxiv kev txhawb nqa rau cov ntawv nyeem / html rau Asynchronous Clipboard API rau kev theej thiab pasting HTML ntawm cov ntawv teev cia (cov kev tsim HTML txaus ntshai raug ntxuav thaum sau thiab nyeem ntawv rau cov ntawv teev cia). Qhov kev hloov pauv, piv txwv li, tso cai rau koj los teeb tsa cov ntawv ntxig thiab luam tawm cov ntawv sau nrog cov duab thiab txuas hauv web editors.
  • WebRTC tau ntxiv lub peev xwm los txuas nws tus kheej cov ntaub ntawv tuav, hu rau ntawm qhov encoding lossis decoding theem ntawm WebRTC MediaStreamTrack. Piv txwv li, lub peev xwm no tuaj yeem siv los ntxiv kev txhawb nqa rau qhov kawg-rau-kawg encryption ntawm cov ntaub ntawv xa mus los ntawm cov servers nruab nrab.
    Hauv V8 JavaScript cav, qhov kev siv ntawm Number.prototype.toString tau nrawm los ntawm 75%. Ntxiv .name cov cuab yeej rau cov chav kawm asynchronous nrog tus nqi khoob. Txoj kev Atomics.wake tau raug tshem tawm, uas ib zaug tau hloov npe rau Atomics.notify kom ua raws li ECMA-262 specification. Cov cai rau fuzzing xeem cuab yeej JS-Fuzzer yog qhib.
  • Lub Liftoff baseline compiler rau WebAssembly tso tawm nyob rau hauv qhov kev tso tawm kawg suav nrog lub peev xwm siv SIMD vector cov lus qhia kom ceev cov kev suav. Kev txiav txim los ntawm cov kev ntsuam xyuas, kev ua kom zoo ua rau nws tuaj yeem ua kom tau qee qhov kev xeem los ntawm 2.8 npaug. Lwm qhov kev ua kom zoo dua ua rau nws nrawm dua los hu rau JavaScript ua haujlwm los ntawm WebAssembly.
  • Cov cuab yeej rau cov neeg tsim tawm hauv lub vev xaib tau nthuav dav: Media vaj huam sib luag tau ntxiv cov ntaub ntawv hais txog cov players siv los ua yeeb yaj kiab ntawm nplooj ntawv, suav nrog cov ntaub ntawv tshwm sim, cov cav, cov cuab yeej muaj nuj nqis thiab cov txheej txheem kev txiav txim siab (piv txwv li, koj tuaj yeem txiav txim siab qhov laj thawj ntawm thav duab. poob thiab teeb meem cuam tshuam los ntawm JavaScript).
  • Nyob rau hauv cov ntawv qhia zaub mov ntawm lub Elements vaj huam sib luag, lub peev xwm los tsim cov screenshots ntawm cov khoom xaiv tau raug ntxiv (piv txwv li, koj tuaj yeem tsim ib lub screenshot ntawm cov ntsiab lus lossis lub rooj).
  • Hauv lub vev xaib console, cov teeb meem ceeb toom vaj huam sib luag tau hloov nrog cov lus tsis tu ncua, thiab teeb meem nrog cov khoom qab zib thib peb tau muab zais los ntawm lub neej ntawd hauv Issues tab thiab tau qhib nrog lub thawv tshwj xeeb.
  • Hauv Rendering tab, "Disable local fonts" khawm tau ntxiv, uas tso cai rau koj simulate qhov tsis muaj fonts hauv zos, thiab hauv Sensors tab koj tam sim no simulate cov neeg siv tsis ua haujlwm (rau cov ntawv thov siv Idle Detection API).
  • Daim ntawv thov vaj huam sib luag muab cov ncauj lus kom ntxaws txog txhua lub iframe, qhib qhov rais, thiab pop-up, suav nrog cov ntaub ntawv hais txog kev sib cais ntawm Cross-Origin siv COEP thiab COOP.

Kev ua raws li QUIC raws tu qauv tau pib hloov los ntawm cov qauv tsim hauv IETF specification, tsis yog Google version ntawm QUIC.
Ntxiv nrog rau kev tsim kho tshiab thiab kho kab laum, tus tshiab version tshem tawm 35 qhov tsis zoo. Ntau qhov tsis zoo tau raug txheeb xyuas raws li qhov tshwm sim ntawm kev ntsuas tsis siv neeg siv qhov chaw nyob Sanitizer, MemorySanitizer, Tswj Flow Integrity, LibFuzzer thiab AFL cov cuab yeej. Ib qho tsis zoo (CVE-2020-15967, nkag mus rau lub cim xeeb pub dawb hauv code rau kev cuam tshuam nrog Google Payments) yog qhov tseem ceeb, piv txwv li. tso cai rau koj hla txhua theem ntawm kev tiv thaiv browser thiab ua tiav cov cai ntawm lub kaw lus sab nraud sandbox ib puag ncig. Raws li ib feem ntawm qhov kev pab cuam them nyiaj ntsuab rau kev tshawb pom qhov tsis zoo rau qhov kev tso tawm tam sim no, Google tau them 27 khoom plig muaj nqis $ 71500 (ib qho $ 15000 khoom plig, peb $ 7500 khoom plig, tsib $ 5000 khoom plig, ob $ 3000 khoom plig, ib qho khoom plig $ 200, thiab ob qho khoom plig $ 500). Qhov loj ntawm 13 khoom plig tseem tsis tau txiav txim siab.

Sau los ntawm Opennet.ru

Tau qhov twg los: linux.org.ru ua

Ntxiv ib saib