Live data from Hacker News

Why Raspberry Pi Isn't Vulnerable to Spectre or Meltdown

raspberrypi.org

231–232 of 232 posts

Re: Why Raspberry Pi Isn't Vulnerable to Spectre or Meltdown

#231

I was already on the lookout for a small ARM-based mini PC, just for doing financial transactions and record-keeping. Now that seems more pressing but I don't know of any such thing in existence. I tried doing that on RPi 3, but the IO seemed not up to the job -- the CPU appeared to be just about tolerable, but using micro SD as a disk was too slow and prone to failure (I'd have tried an external USB disk but I belie…

(coming late to this thread ...)

arm-powered chromeboxes don't exist (yet?), so perhaps an arm-powered chromebook?

(chromeboxes tend to be more upgradeable than their chromebook counterparts)

Linux OS, kept up to date for you (with google backporting security fixes to their kernel, and of course - updating their browser), running on arm.

Can be used as a simple browser-only machine, or if you are decently comfortable with linux, you can unlock its potential and use it as a fully-fledged linux machine. Your choice.

If you want to avoid being part of the google foodchain, you could try dual-booting into another arm distro of your choice.

Best I can think of, at the moment ...

Re: Why Raspberry Pi Isn't Vulnerable to Spectre or Meltdown

#232

Earlier quoted context omitted.

Cache timing goes back to 2005 with Percival. I published a couple weeks before them. :-)

"Cache timing goes back to at least 2005 with Osvik and Tromer. This isn't a simple cache timing bug, though." (tptacek) "Cache timing goes back to 2005 with Percival. I published a couple weeks before them. :-)" (cpercival) Cache timing goes back to the VAX Security Kernel (early 1990's) designed for those A1 certification requirements that tptacek calls useless, "red tape." One of the mandated techniques was covert…

Could you direct us to a list of known immune processors like the pi...so that those of us who are listening can protect ourselves until this parade of liars passes. None of these companies is answering the simplest question: " Am I vulnerable while using your product?".
Post reply on HN