Secure browsers

20
Secure Browsers SecureWorld St. Louis 9/14 David Strom, @dstrom

description

This is a talk at St. Louis Secure World conference, Sept 2014 http://www.secureworldexpo.com/st-louis/home

Transcript of Secure browsers

Page 1: Secure browsers

Secure Browsers

SecureWorld St. Louis9/14

David Strom, @dstrom

Page 2: Secure browsers

NSS Labs Secure Browser Report

Page 3: Secure browsers
Page 4: Secure browsers
Page 5: Secure browsers
Page 6: Secure browsers

Certainly you can turn up these security settings

• Block pop-ups• Increase your privacy controls• Refuse tracking cookies • And so forth

Page 7: Secure browsers
Page 8: Secure browsers
Page 9: Secure browsers

Secure browsers type A: sandbox

Page 10: Secure browsers

Secure browsers type B: lockdown

Page 11: Secure browsers

My testbed

• Qualys browsercheck• Ip-secrets.com for browser agent info• Html5test.com for specifics on that• Download sample PDF and Eicar test .EXE file• Malwaredomainlist.com for fun• Added a few phished emails to see what

happens

Page 12: Secure browsers
Page 13: Secure browsers
Page 14: Secure browsers
Page 15: Secure browsers
Page 16: Secure browsers
Page 17: Secure browsers
Page 18: Secure browsers
Page 19: Secure browsers
Page 20: Secure browsers

http://www.networkworld.com/article/2175897/securityecure-browsers-offer-alternatives-to-

chrom/security/secure-browsers-offer-alternatives-to-chrome--ie-

and-firefox.html