Google ensures that users do not have to worry about viruses, malware, and security updates on the new Chrome OS Operating System. However, it is still too early to evaluate the accuracy of these messages, because it takes at least one year before the official version of Chrome OS is released, currently, the only thing we can see is Google's official Chrome OS source code and the virtual machine version compiled by enthusiasts.
In fact, Google has published some information about this. This includes a complete security overview, which describes the long-term security planning of Chrome OS. Nor can they ensure that all goals described in this review can be achieved. But in any case, the security shown in the just-released version is still impressive.
Always up-to-date
First, put all operating system files in one partition, while user data in another partition. The two are isolated forever! Microsoft has made some efforts in this regard, such as through the configuration file to prevent programs from disrupting Windows folders. However, they are far from achieving the crucial step of complete separation.
In Chrome OS, automatic update is not only an option, but a required rule. I once hoped that Microsoft could block users from simply disabling automatic updates through Windows 7, but Microsoft disappointed me. If they have to make it (automatic update) optional, they should at least put it in a place that is not easy to find for junior users and set it to enable by default. Google can easily choose the right path here. When Chrome OS updates are available, all Chrome-based systems will be updated. At the same time, this digital signature verification update is implemented through a secure connection.
Google's Will Drewry introduced a smarter system in a video to prevent users from disabling updates. When an update is downloaded, it is first placed in an independent inactive system partition. After the new download is complete, the system checks the updated code again. It is updated to the new version only after it is confirmed that it has triggered the switch. If this process is interrupted, there will be no semi-Update Status.
Verification at startup
Every time you restart, Chrome OS checks the digital signature of each system element to ensure that the system has not changed. Once it detects any abnormal situation, Chrome OS will immediately refresh through the automatic update process. Theoretically, the restart should be able to clear any malware that threatens the system. But won't malware make itself seem legal by changing the verification process? The Drewry video describes in detail the various measures involved in the verification process. It seems that these measures are hard to be cracked.
This concept of clearing malware through conventional system restoration is not new. Microsoft also provides Window SteadyState (a free movie sub-system developed by Microsoft), a tool kit for configuring Windows systems, it allows you to restore the system to a known normal restore point during restart. There are also some third-party virtual tools and Security rollback tools. However, unless user files are completely separated from system files, this solution cannot achieve the simplicity and reliability of Chrome OS.
Via asp ">PCMAG