A software called RockSalt developed by Harvard researchers boosts app security

RockSalt software improves app security.

Greg Morrisett

School of Engineering and Applied Sciences (SEAS) researchers and two Harvard undergraduates have developed a “clever bit of code” called RockSalt that could boost security for popular Web and mobile applications such as Gmail, Facebook, and Angry Birds.

When a user surfing the Web opens an external application, says Cutting professor of computer science and lead researcher Greg Morrisett, Web browsers such as Google Chrome typically “sandbox” the program’s code by running it in JavaScript, an intermediate—and safer—language. This approach limits native code (computer code compiled to run with a particular processor) to functions that fall within particular security parameters, but can also slow the application. If the application runs in native code instead, it will execute commands more quickly, but at a price: it makes devices more susceptible to hackers looking to gain access to other parts of a computer or mobile device. RockSalt solves the security problems of native code without slowdowns. Developed by Morrisett, former postdoctoral fellow Jean-Baptiste Tristan (now at Oracle), rising seniors Edward Gan ’13 and Joseph Tassarotti ’13, and Gang Tan of Lehigh University, RockSalt enables programmers to code in any language, compile their work in native executable code, and secure it without going through intermediate languages such as JavaScript.

When computer scientists at the University of California, Berkeley, developed a similar solution called software fault isolation (SFI) more than a decade ago, it was limited to devices using RISC chips, a type of processor more common in research than in consumer computing. In 2006, Morrisett developed a way to implement SFI on the more popular CISC-based chips, like the Intel x86 processor, eventually leading to Google’s development of Google Native Client (or NaCl).

When bugs and vulnerabilities were found in the checker for NaCl, Morrissett once again tackled the challenge, turning the problem into an opportunity for his students, and then presenting their research at the June ACM Conference on Programming Language Design and Implementation (PLDI) in Beijing. His team expects RockSalt to be integrated into future versions of common Web browsers, and plans to adapt the tool for use in a broader variety of processors.

“The biggest benefit,” says Morrisett, “may be that users can have more peace of mind that a piece of software works as they want it to.”

You might also like

How the American Revolution Freed a Future Abolitionist

Darby Vassall, an enslaved child freed after the Battle of Bunker Hill, dedicated his life to fighting for liberty.

Öberg to Lead Harvard Faculty Recruitment and Retention

The astrochemist will become senior vice provost for faculty affairs this summer.

Martin Nowak Placed on Leave a Second Time

Further links to Jeffrey Epstein surface in newly released files.

Most popular

Harvard Graduate Student Workers Strike

Union demands higher pay, protections for non-citizen members, and changes to the harassment complaint process.

At Harvard Talk, Retired Supreme Court Justice Breyer Defends Shadow Docket

The current law professor also spoke about affirmative action, partisanship, and the limits of “bright-line rules.”

The Teen Brain

It’s a paradoxical time of development. These are people with very sharp brains, but they’re not quite sure what to do with them...

Explore More From Current Issue

White House and Harvard University buildings split diagonally with contrasting colors.

Harvard Weathers a Year of Turmoil

The federal government has launched unprecedented actions against the University. Here’s a guide.

Illustration of two students in Harvard hoodies, one speaking animatedly to a phone, the other reading, looking annoyed.

We’re All Harvard Influencers, Like It or Not

In the digital age, it’s hard to avoid playing into the mythology.

Brick archway with a sandy base, surrounded by wooden planks and boxes in a dim space.

How the American Revolution Freed a Future Abolitionist

Darby Vassall, an enslaved child freed after the Battle of Bunker Hill, dedicated his life to fighting for liberty.