Earlier quoted context omitted.
Has Ubutu botched or did Ubutu botch... please ;)
Can't spell Ubuntu right, though.
Stop staring at my finger. Please ;)
201–205 of 205 posts
Earlier quoted context omitted.
Has Ubutu botched or did Ubutu botch... please ;)
Can't spell Ubuntu right, though.
Stop staring at my finger. Please ;)
Earlier quoted context omitted.
What are you talking about? We've seen working POCs since last week. This isn't "largely theoretical", this is an actively exploitable hole.
Meh, it's not really very serious in the average case. It's a lot of sky-is-falling rhetoric from the infosec community. Remember Heartbleed and how it was end-of-times bad? Yeah, turned out to be a non-event. Information disclosure bugs like this are difficult to glean useful information from in widely targeted attacks. (Obviously if you have nation states or serious criminal organizations trying to breach you regul…
Heartbleed was touted as being bad by those that didn't read too far into it. You could scrape memory, sure. But it was always random fragments. This lets you make targeted address attacks. Force a process to use that memory space through a NOOP and now you can start scraping at will. Or you can just do an entire memory dump and pull things out in plaintext (like scraping Firefox passwords, which we've seen done already).
The only reason this isn't worse is it requires the ability to execute code on the machine. It has high (near absolute) impact, but low-to-moderate on the ease of execution.
Earlier quoted context omitted.
> And replace them with what? An AMD CPU?
Which doesn't have Meltdown but still has Spectre. Furthermore you have to replace at least the whole motherboard on a desktop or probably all of your laptop except the discs and maybe the RAM.
I didn't realize that when I made the comment, and I agree my suggestion falls flat now that I know.
> You have to replace at least the whole motherboard on a desktop or probably all of your laptop except the discs and maybe the RAM.
I'm ok with putting that responsibility on Intel to remedy the situation, even if it deeply hurt them financially or put them out of business. If you sell a faulty product that doesn't live up to its description, yes you risk actually going out of business. But with the fact that AMD has Spectre this idea of replacement no longer makes much sense and your original idea of a partial refund makes the most sense.
Would this entire Meltdown/Spectre thing count as the biggest mess-up of computing history? When yesterday the PoC repo was posted here, the spy.mp4 demo video gave me some chills. And now I can't update my OS before making an installation USB because Canonical can't just follow Linus' releases. Thanks.
I think Y2K had more practical impact across the business world. There was genuine fear that it could cause an actual apocalypse with all major computerized systems failing, medical machines killing people, banks being affected and all money and debts disappearing overnight. It wasn't that bad, because people took it seriously. But there were still tons of practical systems affected and billions of corporate dollars…
See this is why you wait a day or two before patching :)