Microsoft Edge Super Duper Security Setting

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
625
Fyi, saw this article that I think Edge afficionados would appreciate and might implement in their browsers.. I already made this adjustment to my Edge, and so far the browser still works as usual. Whether you decide to do the same is a matter of preference.

 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,126
The performance impact seems to be not big:
Disabling JIT may impact performance. Microsoft notes that most users would probably not notice a difference with JIT disabled, Performance data revealed that the disabling does not always have negative impacts. For page load performance, results varied from a positive 9.5% improvement to a negative 16.9% decrease, depending on the page. Memory use's rage was between 4.6% and -2.3%, and power between 15% and -11.4%.
https://www.ghacks.net/2021/08/18/microsoft-edges-super-duper-secure-mode-lands-in-settings/

Right now, when enabled, Super Duper Secure Mode disables JIT (TurboFan/Sparkplug) and enables Control-flow Enforcement Technology (CET), an Intel hardware-based exploit mitigation designed to provide a more secure browsing experience.

In the future, Microsoft also wants to add support for Arbitrary Code Guard (ACG), another security mitigation that would prevent loading malicious code into memory, a technique used by most web browser exploits.
https://www.bleepingcomputer.com/ne...e-just-got-a-super-duper-secure-mode-upgrade/

Additional information about Super Duper can be found on this webpage:
https://microsoftedge.github.io/edgevr/posts/Super-Duper-Secure-Mode/

More information about Edge development can be found in the below MT thread:
https://malwaretips.com/threads/microsoft-edge-developers-build-info.96101/post-955074
 
Last edited:

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,586
"Super duper secure mode." What a doofy name for such an important zero-day mitigation feature. :rolleyes:
The VR team is experimenting with a new feature that challenges some conventional assumptions held by many in the browser community. Our hope is to build something that changes the modern exploit landscape and significantly raises the cost of exploitation for attackers. Mitigations have a long history of being bypassed, so we are seeking feedback from the community to build something of lasting value.

Most importantly we plan to have fun with this project. This includes giving the experiment a slightly provocative name because we think it is funny, and it is a bit too early for something official.
 

plat

Level 29
Top Poster
Sep 13, 2018
1,793
Well for something "funny," I also enabled this (not left at default in edge://flags). Good, I feel a tiny bit safer now.

edge sdsm.png

Anyone else?
 

plat

Level 29
Top Poster
Sep 13, 2018
1,793
All good here with it enabled and only µBO installed.

Yes, me too. uBO seems to be "safe" with a lot of browser modifications and additions, thank goodness.

Looked around various places for any issues regarding enabling this mode and extensions like Norton and 1Password. Nothiing yet. Does anyone think Feedback Hub would be worth it?
 

CyberTech

Level 44
Verified
Top Poster
Well-known
Nov 10, 2017
3,250
Back in August, Microsoft Edge's Vulnerability Research Lead Jonathan Norman revealed that his team is working on a "Super Duper Secure Mode" - that I'll mostly refer to as "SDSM" following this instance for brevity - for Microsoft Edge. With the release of Edge 96.0.1054.29 to the Stable channel, this feature has been quietly added to the browser and is now available for the general public to enable.

Full article
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top