Google
-
activated Password Checkup chikamu, chakagadzirirwa kuongorora kusimba kwemapassword anoshandiswa nemushandisi. Paunenge uchiedza kupinda kune chero saiti Password Checkupanozadzisa kutarisa kupinda uye password kupikisa dhatabhesi yemaakaundi akakanganiswa ine yambiro kana matambudziko akaonekwa (kutarisa kunoitwa zvichibva pane hash prefix padivi remushandisi). Cheki inoitwa ichipokana nedhatabhesi inofukidza anopfuura mabhiriyoni mana akakanganiswa maakaundi akaonekwa mune akaburitswa mushandisi dhatabhesi. Yambiro inoratidzwawo paunenge uchiedza kushandisa mapassword mashoma se "abc4". Kudzora kusanganisirwa kwePasiwedhi Checkup, yakakosha kuseta yaitwa muchikamu che "Sync neGoogle Services". - Tekinoroji nyowani yekuona phishing munguva chaiyo inoratidzwa. Kare, ongororo yaiitwa nekuwana yakadhawunirodha Safe Browsing mazita evatema, ayo akagadziridzwa kanenge kamwe chete maminetsi makumi matatu, izvo zvakazove zvisina kukwana, semuenzaniso, mumamiriro ekugara achichinja domain nevanorwisa. Iyo nzira nyowani inokutendera kuti utarise maURL pane nhunzi uine cheki yekutanga kutarisana nevachena vanosanganisira hashes ezviuru zvemasaiti anozivikanwa akavimbika. Kana iyo saiti iri kuvhurwa isiri mune chena runyorwa, bhurawuza rinotarisa iyo URL paGoogle server, ichitumira ekutanga 30 bits yeSHA-32 hash yelink, kubva panogona kuchekwa data rako pachako. Sekureva kweGoogle, iyo nzira nyowani inogona kuvandudza kushanda kweyambiro kune itsva phishing saiti ne256%.
- Yakawedzera dziviriro yekudzivirira kubva mukufambiswa kwezvitupa zveGoogle uye chero mapassword akachengetwa mu password maneja kuburikidza nemapeji ephishing. Kana iwe ukayedza kuisa password yakachengetedzwa pane saiti iyo password isingawanzo shandiswa, mushandisi anoyambirwa nezve chiitiko chinogona kuva nengozi.
- Kubatanidza uchishandisa TLS 1.0 uye 1.1 ikozvino inoratidza kusachengeteka yekubatanidza chiratidzo. Tsigira zvizere TLS 1.0 uye 1.1
acharemara muChrome 81, yakarongerwa Kurume 17, 2020. - Yakawedzera kugona kuomesa ma tabo asingashande, zvichikubvumidza kuti uzvibudise otomatiki kubva kumatabhu ekurangarira anga ari kumashure kweanopfuura maminetsi mashanu uye usaite zviito zvakakosha. Sarudzo yekukodzera kweimwe tebhu yekuomesa nechando inoitwa zvichienderana neheuristics. Kugonesa basa kunodzorwa kuburikidza ne "chrome://flags/#proactive-tab-freeze" mureza.
-
Secured Kuvharisa zvakasanganiswa zviri pamapeji zvakavhurwa pamusoro peHTTPS kuti ive nechokwadi chekuti mapeji anovhurwa pamusoro pehttps: // ane chete zviwanikwa zvakatakurwa pane yakachengeteka nzira yekutaurirana. Kunyangwe mhando dzine njodzi dzemukati mesanganiswa, senge zvinyorwa uye iframe, dzakatovharwa nekusingaperi, mifananidzo, maodhiyo mafaera uye mavhidhiyo anogona achiri kudhawunirodha kuburikidza ne http://. Iyo yakamboshandiswa yakasanganiswa yemukati chiratidzo chekuisa kwakadaro yakawanikwa isingashande uye ichirasisa mushandisi, sezvo isingapi ongororo isina kujeka yekuchengetedzwa kwepeji. Semuyenzaniso, kuburikidza nemufananidzo spoofing, anorwisa anogona kutsiva mushandisi wekutevera Cookies, edza kushandisa kusasimba mumagadzirirwo emifananidzo, kana kuita manyepo nekutsiva ruzivo rwakapihwa mumufananidzo. Kudzima kukiyiwa kwezvikamu zvakasanganiswa, kurongeka kwakakosha kwakawedzerwa, iyo inogona kuwanikwa kuburikidza nemenu inoonekwa kana iwe uchidzvanya pane yekukiya chiratidzo. - Yakawedzera kuyedza kugona kugovera clipboard zvemukati pakati pedesktop uye nharembozha dzeChrome. Mune zviitiko zveChrome zvakabatana neakaundi imwe, iwe unogona ikozvino kuwana zviri mukati me clipboard yeimwe mudziyo, kusanganisira kugovera clipboard pakati penharembozha nedesktop system. Zviri mukati me clipboard zvakavharwa pachishandiswa end-to-end encryption, izvo zvinotadzisa kuwana zvinyorwa pamaseva eGoogle. Basa racho rinogoneswa kuburikidza nesarudzo chrome://flags#shared-clipboard-receiver, chrome://flags#shared-clipboard-ui uye chrome://flags#sync-clipboard-service.
- Mubhadha rekero pane dzimwe nguva (semuenzaniso, kana uchichengetedza password) kana kuwiriranisa kweprofile kwakadzimwa, kuwedzera kune avatar, zita reiyo Google account yazvino rinoratidzwa kuitira kuti mushandisi akwanise kuona iyo ikozvino inoshanda account.
- Yakagadzirirwa 1% yevashandisi
kutsigira "DNS pamusoro peHTTPS" (DoH, DNS pamusoro peHTTPS). Kuedza uku kunosanganisira chete vashandisi vane masisitimu ehurongwa vakatotsanangura DNS vanopa vanotsigira DoH. Semuyenzaniso, kana mushandisi aine DNS 8.8.8.8 yakataurwa muzvirongwa zvesisitimu, ipapo sevhisi yeGoogle yeDoH (βhttps://dns.google.com/dns-queryβ) ichavhurwa muChrome; kana DNS iri 1.1.1.1. XNUMX, ipapo DoH Cloudflare sevhisi ("https://cloudflare-dns.com/dns-query"), nezvimwe. Kuti udzore kana DoH yakabatidzwa, iyo "chrome://flags/#dns-over-https" inopihwa. Matatu ekushandisa modes anotsigirwa: akachengeteka, otomatiki uye akadzima. Mune "yakachengeteka" modhi, mauto anotemerwa chete zvichibva pane yaimbove cached yakachengeteka kukosha (yakagashirwa kuburikidza yakachengeteka yekubatanidza) uye zvikumbiro kuburikidza neDoH; yekudzokera kune yakajairwa DNS haishandiswe. Mune "otomatiki" modhi, kana DoH uye cache yakachengeteka zvisipo, data inogona kutorwa kubva kune isina kuchengetedzwa cache uye inowanikwa kuburikidza neyakajairwa DNS. Mu "off" mode, cache yakagovaniswa inotanga kuongororwa uye kana pasina data, chikumbiro chinotumirwa kuburikidza nehurongwa DNS. - Yakawedzerwa kuedza
kutsigira caching yezvinyorwa zvakashandurwa paunenge uchichinja mapeji uchishandisa mabhatani ekumberi nekumashure, izvo zvinogona kuderedza zvakanyanya kunonoka panguva yerudzi urwu rwekufambisa nekuda kwekukwana caching yepeji rese, izvo zvisingade kudzoreredza uye kurodha zviwanikwa. Iyo optimization inonyanya kuoneka mune vhezheni yemafoni emafoni, uko kuwedzera kwekuita panguva yekufambisa kunosvika 19%. Iyo modhi inogoneswa uchishandisa iyo "chrome://flags#back-forward-cache" sarudzo. -
Dzadzimwa kuseta "chrome://flags/#omnibox-ui-hide-steady-state-url-scheme-and-subdomains", iyo yakabvumira kudzorera kuratidzwa kweprotocol mubhari kero (ikozvino zvese zvinongedzo zvinogara zvichiratidzwa pasina https :// uye http://, uyewo pasina βwww.β). - Zvivakwa zveWindows zvinosanganisira sandboxing yeaudio yekutamba sevhisi. Kudzora kana kuzviparadzanisa nevamwe kunogoneswa, iyo AudioSandboxEnabled chivakwa chinopihwa.
- Centralised manejimendi maturusi emabhizinesi anosanganisira kugona kutsanangura mitemo inodzora kuti yakawanda sei ndangariro yebrowser muenzaniso inogona kushandisa ma tabo ekumashure asati aburitswa. Iyo ndangariro yakaburitswa mushure mekuburitsa tebhu inove iripo yekushandisa, uye zviri mukati metabhu zvinoremerwa zvakare kana uchichinjira kwairi.
- Linux inoshandisa yakavakirwa-mukati chitupa verification processor, iyo inotsiva yaimboshandiswa NSS system. Muchiitiko ichi, iyo yakavakirwa-mukati processor inoenderera nekushandisa chitoro cheNSS panguva yekusimbisa, asi inoisa zvinoomesesa zvinodikanwa kana uchigadzira zvisizvo encoded uye zvakapatsanurwa zvitupa (ese zvitupa zvinofanirwa kusimbiswa nechiremera chetifiketi).
- Mushanduro yepuratifomu yeAndroid
akawedzera kugona kugovera zvidhori zvinogadziriswa zveakaisirwa webhu zvishandiso zvinomhanya muProgressive Web Apps (PWA) modhi. Adaptive icons inogona kuenderana neiyo interface inoshandiswa nemugadziri wemudziyo, semuenzaniso, kutenderera, sikweya, kana nemakona akatsetseka. -
Added APIWebXR Chishandiso , iyo inopa mukana kune zvikamu zvekugadzira virtual uye augmented real. Iyo API inobvumidza iwe kubatanidza basa nemakirasi akasiyana emidziyo, kubva kune yakamira chaiyo chaiyo mahedhifoni seOculus Rift, HTC Vive uye Windows Mixed Reality, kune zvigadziriso zvinoenderana nenharembozha seGoogle Daydream View uye Samsung Gear VR. Zvishandiso umo iyo API nyowani inogona kushanda inosanganisira zvirongwa zvekuona vhidhiyo mu360 Β° modhi, masisitimu ekuona nzvimbo ine mativi matatu, kugadzira chaiwo mabhaisikopo ekuratidzwa kwevhidhiyo, kuita zviedzo pakugadzira 3D interface yezvitoro nemagaraji; - Mune Yekutanga Miedzo modhi (yekuedza maficha anoda kupatsanurwa
activation ) maAPI matsva akati wandei ataurwa. Origin Trial inoreva kugona kushanda neiyo API yakatsanangurwa kubva kune yakatorwa kubva kune localhost kana 127.0.0.1, kana mushure mekunyoresa uye kugamuchira yakakosha tokeni iyo inoshanda kwenguva shoma kune yakatarwa saiti.- Kune ese ma HTML zvinhu, iyo "rendersubtree" hunhu inotsanangurwa, iyo inovimbisa kuti kuratidzwa kweiyo DOM chinhu kwakagadziriswa. Kuseta hunhu ku "asingaoneki" kunodzivirira izvo zvirimo kubva mukupihwa kana kuongororwa, zvichibvumira kukwenenzverwa kupa. Kana yaiswa ku "activatable", bhurawuza inobvisa iyo isingaonekwe hunhu, inopa zvirimo uye kuita kuti zvionekwe.
- Yakawedzerwa API sarudzo
Wake lock zvichibva paPromise mechanism, iyo inopa nzira yakachengeteka yekudzora kuvharika kweauto-lock skrini uye kushandura zvishandiso kune ekuchengetedza simba modes.
- Yakaitwa kugona kushandisa hunhu
autofocus kune ese HTML uye SVG zvinhu zvinogona kuve nekuisa pfungwa. - Zvemifananidzo nemavhidhiyo
secured Verenga huwandu hunoenderana nehupamhi kana Hurefu hunhu, hunogona kushandiswa kuona saizi yemufananidzo uchishandisa CSS padanho apo mufananidzo hausati watakura (inogadzirisa dambudziko nekuvakazve peji mushure mekunge mifananidzo yatakurwa). - Yakawedzerwa CSS pfuma
font-optical-size , iyo inogadzirisa otomatiki saizi yefonti mune optical coordinates "opsz ", kana font ichivatsigira. Iyo modhi inobvumidza iwe kuti usarudze iyo yakakwana glyph chimiro chehukuru hwakatarwa, semuenzaniso, shandisa mamwe anosiyanisa glyphs emisoro. - Yakawedzerwa CSS pfuma
list-style-type , iyo inokubvumira kushandisa chero zviratidzo panzvimbo penhambo dziri mumazita, semuenzaniso, β-β, β+β, ββ β uye ββΈβ. - Kana zvisingaite kuita Worklet.addModule(), chinhu chave kudzoserwa neruzivo rwakadzama nezve chimiro chekukanganisa, izvo zvinokutendera kuti unyatso kuongorora chikonzero chekukanganisa (matambudziko netiweki yekubatanidza, syntax isiriyo, nezvimwe. .).
- Yakamira kugadzirisa zvinhu ΠΏΡΠΈ ΠΈΡ ΠΏΠ΅ΡΠ΅ΠΌΠ΅ΡΠ΅Π½ΠΈΠΈ ΠΌΠ΅ΠΆΠ΄Ρ Π΄ΠΎΠΊΡΠΌΠ΅Π½ΡΠ°ΠΌΠΈ. ΠΡΠΈ ΠΏΠ΅ΡΠ΅Π½ΠΎΡΠ΅ ΠΌΠ΅ΠΆΠ΄Ρ Π΄ΠΎΠΊΡΠΌΠ΅Π½ΡΠ°ΠΌΠΈ ΡΠ°ΠΊΠΆΠ΅ ΠΎΡΠΊΠ»ΡΡΠ΅Π½ΠΎ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΠ΅ ΡΠ²ΡΠ·Π°Π½Π½ΡΡ ΡΠΎ ΡΠΊΡΠΈΠΏΡΠΎΠΌ ΡΠΎΠ±ΡΡΠΈΠΉ Β«errorΒ» ΠΈ Β«loadΒ».
- MuJavaScript injini V8
wakaita Optimization yekubata shanduko kune inomiririra minda muzvinhu, zvichikonzera AngularJS kodhi kuuraya mu Speedometer test suite inomhanya 4% nekukurumidza. - V8 inogonesawo kugadziridzwa kweanowana anotsanangurwa mune akavakirwa-mukati maAPIs, akadai seNode.nodeType uye Node.nodeName, pasina IC handler (inline caching). Shanduko iyi yakaderedza nguva yakashandiswa paIC nguva yekumhanya neinosvika gumi nemaviri% paunenge uchimhanyisa Backbone uye jQuery bvunzo kubva kuSpeedometer suite.
- Mhedzisiro yeOSR (inonzi on-stack replacement) inochengeterwa, iyo inotsiva yakagadziridzwa kodhi panguva yekuita basa (inobvumidza iwe kuti utange kushandisa yakagadziridzwa kodhi yenguva-inomhanya mabasa pasina kumirira kuti imhanye zvakare). OSR caching inoita kuti zvikwanise kushandisa optimization mhedzisiro paunenge uchimhanyisa basa, pasina kukosha kwekuenda kuburikidza nekugadzirisa zvakare.
Mune dzimwe bvunzo, shanduko yakawedzera peak performance ne5-18%. - Shanduko mumaturusi evagadziri vewebhu:
- Muchivharo chine Cookie runyorwa, kugona kukurumidza kuona kukosha kweiyo yakasarudzwa Cookie yakawedzerwa nekudzvanya pane yakatarwa mutsara.
- Yakawedzera kugona kutevedzera marongero akasiyana eanoda-ruvara-chirongwa uye anoda-yakaderedzwa-inofambisa midhiya mibvunzo (semuenzaniso, kuyedza maitiro epeji ine yakasviba system theme kana ine animated mhedzisiro yakadzimwa).
- Dhizaini yeCoverage tab yakagadziridzwa, ichikubvumidza kuti uongorore kodhi yakashandiswa uye isiri kushandiswa. Yakawedzera kugona kusefa ruzivo nerudzi rwayo (JavaScript, CSS). Ruzivo rwemashandisirwo ekodhi runowedzerwawo kana uchiratidza chinyorwa chekwakabva.
- Yakawedzera kugona kugadzirisa zvikonzero zvekukumbira imwe network sosi mushure mekurekodha network chiitiko (unogona kuona inoteedzera yeJavaScript kodhi yekufona iyo yakatungamira kurodha kweiyo sosi).
- Yakawedzerwa "Zvirongwa> Zvaunofarira> Zvitubu> Default Indentation" kurongedza kuti uone rudzi rwekumisikidza (2/4/8 nzvimbo kana ma tabo) mukodhi inoratidzwa muConsole uye Sources mapaneru.
Aoneka debugging mode kuona zvikonzero zvekuvharisa chikumbiro kana kutumira Cookie. - Muchivharo chine Cookie runyorwa, kugona kukurumidza kuona kukosha kweiyo yakasarudzwa Cookie yakawedzerwa nekudzvanya pane yakatarwa mutsara.
Pamusoro pehunyanzvi uye kugadzirisa kwebug, iyo vhezheni itsva inobvisa 51 kusagadzikana. Mazhinji ekusagadzikana akaonekwa semhedzisiro yekuongorora otomatiki uchishandisa KeroSanitizer, MemorySanitizer, Kudzora Flow Kutendeseka, LibFuzzer uye AFL maturusi. Nyaya mbiri (CVE-2019-13725, kuwana yakatosunungurwa ndangariro mukodhi yerutsigiro rweBluetooth, uye CVE-2019-13726, murwi unofashukira mupassword maneja) akaiswa seakaomarara, i.e. inokutendera kuti upfuure ese mazinga ebrowser kuchengetedza uye kuita kodhi pane system kunze kwesandbox nharaunda. Aka ndekekutanga kuti matambudziko maviri akakosha aonekwe mukati meiyo yakafanana budiriro kutenderera muChrome. Kusagadzikana kwekutanga kwakawanikwa nevaongorori kubva kuTencent Keen Security Lab uye
Sechikamu chechirongwa chemari yemubairo wekutsvaga kusasimba kwekuburitswa kwazvino, Google yakabhadhara mibairo makumi matatu nemanomwe inokosha $37 (mubairo mumwe wemadhora zviuru makumi maviri, mubairo wemadhora gumi, mubairo we$80000, mibairo mina yemadhora zviuru zvishanu, mubairo mumwe wemadhora zviuru zvitatu, mubairo wemadhora zviuru zviviri nemazana masere emadhora. $20000 mibairo). Hukuru hwemibairo gumi neshanu haisati yazivikanwa.
Source: opennet.ru