Live data from Hacker News

Meltdown Proof-of-Concept

github.com

41–50 of 187 posts

Re: Meltdown Proof-of-Concept

#44
post #40
post #33

Earlier quoted context omitted.

Nice tool. Sadly, it reports that my browser (Chromium 63.0.3239.132 with strict site isolation (chrome://flags/#enable-site-per-process) enabled) is vulnerable to Spectre. Do you know if there are any other steps that I can take to secure myself aside from using Firefox?

I'm running the same version of Chrome(with site isolation enabled), its reporting "Your browser is NOT VULNERABLE to Spectre" for me. Also in incognito mode with extensions disabled.

Thanks! It reports the same thing for me too now. I had to enable Top document isolation (chrome://flags/#enable-top-document-isolation) as well.

Re: Meltdown Proof-of-Concept

#45

Earlier quoted context omitted.

Except if you are into *BSD. In that case you might want to label it "selective disclosure" instead of "responsible disclosure".

Yeah, if you're not using Linux/Windows/macOS, this sucks. I wonder what happens next. Either alternative OSs for Desktops/Servers will become less popular or people are moving away from Intel chips. Obviously Intel CEO's betted on the latter - stocks are a representation of the future value of a company. Last year I was already hoping that ARM Chromebooks would become more popular but in reality you cannot find them…

probably because Intel doesn't look too fondly at companies who make ARM motherboards.

I believe it's high time the long history of anticompetitive actions by Intel end, and their near/effective monopoly in major market segments be regulated.

Re: Meltdown Proof-of-Concept

#46
post #15

Earlier quoted context omitted.

I think for a bug this big it is pretty understandable. So far, it seems clear the actions of all involved were in a good spirit of responsible disclosure.

Except if you are into *BSD. In that case you might want to label it "selective disclosure" instead of "responsible disclosure".

Well, since some of the BSD folks publicly stated that they’d ignore any embargo, that seems like a pretty predictable consequence. And in this case I understand that it took a while to develop workable mitigations. Immediate disclosure might have caused great harm.

Re: Meltdown Proof-of-Concept

#48
post #15
post #14

Earlier quoted context omitted.

I wonder what happened to "This bug is subject to a 90 day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report will become visible to the public." Executive meddling? Edit: Probably the 'extreme circumstances' bit mentioned in https://news.ycombinator.com/item?id=16108434

I think for a bug this big it is pretty understandable. So far, it seems clear the actions of all involved were in a good spirit of responsible disclosure.

See https://news.ycombinator.com/item?id=16087060 .
Post reply on HN