Meltdown Proof-of-Concept
41–50 of 187 posts
Re: Meltdown Proof-of-Concept
#42MacOS is yet to have a patch for 10.12.6 (Sierra) to resolve this.
Re: Meltdown Proof-of-Concept
#43MacOS is yet to have a patch for 10.12.6 (Sierra) to resolve this.
Re: Meltdown Proof-of-Concept
#44Earlier quoted context omitted.
Nice tool. Sadly, it reports that my browser (Chromium 63.0.3239.132 with strict site isolation (chrome://flags/#enable-site-per-process) enabled) is vulnerable to Spectre. Do you know if there are any other steps that I can take to secure myself aside from using Firefox?
I'm running the same version of Chrome(with site isolation enabled), its reporting "Your browser is NOT VULNERABLE to Spectre" for me. Also in incognito mode with extensions disabled.
Re: Meltdown Proof-of-Concept
#45Earlier quoted context omitted.
Except if you are into *BSD. In that case you might want to label it "selective disclosure" instead of "responsible disclosure".
Yeah, if you're not using Linux/Windows/macOS, this sucks. I wonder what happens next. Either alternative OSs for Desktops/Servers will become less popular or people are moving away from Intel chips. Obviously Intel CEO's betted on the latter - stocks are a representation of the future value of a company. Last year I was already hoping that ARM Chromebooks would become more popular but in reality you cannot find them…
I believe it's high time the long history of anticompetitive actions by Intel end, and their near/effective monopoly in major market segments be regulated.
Re: Meltdown Proof-of-Concept
#46Earlier quoted context omitted.
I think for a bug this big it is pretty understandable. So far, it seems clear the actions of all involved were in a good spirit of responsible disclosure.
Except if you are into *BSD. In that case you might want to label it "selective disclosure" instead of "responsible disclosure".
Re: Meltdown Proof-of-Concept
#47Re: Meltdown Proof-of-Concept
#48Earlier quoted context omitted.
I wonder what happened to "This bug is subject to a 90 day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report will become visible to the public." Executive meddling? Edit: Probably the 'extreme circumstances' bit mentioned in https://news.ycombinator.com/item?id=16108434
I think for a bug this big it is pretty understandable. So far, it seems clear the actions of all involved were in a good spirit of responsible disclosure.