Apple's Safari, released for the Windows platform in June 2007, is the second newest browser on Windows, behind Google's Chrome. (Naturally, Apple's browser also runs on OS X, and on iPhone and iPod Touch devices in a mobile edition.) Safari leads the pack in anti-phishing filtering and pop-up blocking, but it also has many security weaknesses.
Safari can be freely downloaded from Apple's Web site, and it is offered as an opt-in download option through Apple's Software Update program, which is installed with other Apple software, including iTunes and QuickTime. After Safari is installed, Software Update checks for Safari patches once a week using a Task Scheduler job.
[ See also the security reviews of Firefox, Internet Explorer, Google Chrome, and Opera. For more on browser security and protection against Web-borne threats, see the Security Adviser blog and "Test Center: Browser security tools versus the evil Web." ]
The Safari installer also installs a service called Bonjour, which allows Apple programs to advertise themselves and discover other Bonjour-compatible programs on the local network. Bonjour is used to automatically configure printers, hunt for file sharing opportunities, and find instant messaging peers, and it allows Safari to discover additional Web pages on the local network. In general, most security experts are wary of auto-discovery programs like Bonjour, and Bonjour itself has been involved in at least three known exploits. Bonjour is not essential to Safari's functionality and can be disabled.
Windows Safari
The Safari executable is not User Account Control (UAC)-aware on Windows Vista computers, but Vista automatically elevates permissions for the install because the word "setup" is in the name (potentially, if Vista's heuristics detection functionality is disabled, the install could fail). On Windows Vista, Safari runs as a single process (Safari.exe) with DEP (Data Execution Prevention) disabled, a security negative shared only by Opera; ASLR (Address Space Layout Randomization) enabled; and file system and registry virtualization enabled, all with a MIC (Mandatory Integrity Control) level of Medium. In comparison, the rendering processes of both Internet Explorer and Google Chrome run with the more secure MIC setting of Low.
Safari is a full-featured browser, with common security features, including pop-up blocking, private session browsing, and an anti-phishing filter. The pop-up blocking is among the best, and the anti-phishing filter is the most accurate among the browsers I tested (Internet Explorer, Firefox, Google Chrome, and Opera). Java, JavaScript, and plug-ins can be turned off on a global basis. As with most browsers (Firefox and IE being notable exceptions), Safari provides no security zones in which to place Web sites of varying degrees of trustworthiness, or to enable or disable functionality on a per-site basis.
Get the independent advice and expertise you need to support a virtual workforce.
The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now »Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.
Download now »A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.
Download now »
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »