Google introduced Web browser release chrome 98 . At the same time Available Stable issue of free project chromium speaking the basis of Chrome. Chrome is different using Google’s logos, the presence of a notification sending system in case of collapse, modules for playing a copy-protected video conference (DRM), automatic installation and transmission installation system when searching for RLZ parameters. The next issue of Chrome 99 is scheduled for March 1.
- in the browser built-in your own repository of root certificates of certificate centers (chrome root store ), which will be used instead of external storage spacers specific for each operating system. The repository is implemented by analogy with analogous storage of root certificates in Firefox, used as the first link to check the certificate confidence chain when opening https sites. The new storage is not yet used by default. To simplify the translation of configurations tied to system storage facilities, and to ensure portability, a transition period will be valid for a time during which a complete selection of certificates approved on most supported platforms will be included in the Chrome Root Store.
- The implementation of Plan to strengthen protection against attacks associated with the resource request from the local network or user computer (localhost) from scripts downloaded when opening the site.
Such requests are used by attackers to implement CSRF attacks on routers, access points, printers, corporate web interfaces and other devices and services that accept requests from the local network.to protect against similar attacks in case of appeal to any subgraduat in internal Networks, the browser will begin to send an explicit request for the powers of loading such subgrans. The authority request is carried out through
Sending to the Cors-Origin Resource Sharing) with the “Access-Control-Request-Private-Network: True” header, before contacting the internal network or localhost. If an operation is confirmed in response to this request, the server must return the “Access-Control-Allow-Private-Network: True” header. In Chrome 98, the check is implemented in test mode and in the absence of confirmation in the Web Console displays a warning, but the subgrass request itself is not blocked. The blocking is planned to be included not earlier than the release of Chrome 101.