Sophos video about hacked BusinessWeek site

Sophos has a short video showing evidence of a hacked page on the BusinessWeek web site. I was impressed by how Google Chrome handled this:

The interesting point is that we are finding malicious JavaScript on highly reputable sites. Sophos says this one was caused by SQL injection, and I noticed that the page uses Microsoft’s old .asp technology in which it was particularly easy to code insecurely.

What’s the solution? Beats me; there are just zillions of insecure web applications out there. However, it’s disappointing that BusinessWeek still has not cleaned up the pages, which were reported last week (but perhaps that means last thing Friday).

Google Chrome for Mac and Linux will be a long while coming

When I looked at the Chromium source code and did a build, I noticed how much of it was Windows-specific. Although the WebKit rendering component is already cross-platform, it seems that the Mac and Linux versions of Chromium and therefore Chrome are a long way from ready. This is from the build notes for Mac OS X:

Right now, the Mac build is a work in progress that is much closer to the start than the finish. No application that renders web pages is generated at the end of these instructions!

Cross-platform work usually involves compromises, and it looks like the Google team pointed the dial more towards optimising for Windows than towards ease of porting. That surprises me, since it likely means more work maintaining the application for several platforms as well as delays now.

Chrome’s ambitions as an application platform cannot be realised until it runs on the Mac. Further, a disproportionate number of web designers and developers use Apple.

How long is a long while? Good question. I’ll be seeing some Google folk tomorrow; I’ll let you know what they say.

Technorati tags: , , , ,