The overview page, https://cpu.fail/ , is on Hacker News as https://news.ycombinator.com/item?id=19911715 .
MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
31–40 of 118 posts
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#32It is funny how ChromeOS is the most ridiculously secure of the commonly available operating systems. It is not as if you can do much other than surf the internet with it. It makes me chuckle to think that my not-so-computer-literate friend whom I gave a Chromebook to is protected from anyone snooping in on Youtube, Hotmail and Youtube running on this toy machine (designed for 9 year olds). There really is nothing to…
You can run Android apps and run Linux programs.
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#33Earlier quoted context omitted.
I don't think that anybody can know whether this is true, since exploitation leaves little evidence. Even before this is witnessed in the wild for the first time, you can't really know which secrets of yours have already been exfiltrated.
Everything that can't be fixed with a ten minute phone call to my bank is already public knowledge thanks to Experian, so I really don't have anything left to fear.
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#34Earlier quoted context omitted.
I don't think that anybody can know whether this is true, since exploitation leaves little evidence. Even before this is witnessed in the wild for the first time, you can't really know which secrets of yours have already been exfiltrated.
Everything that can't be fixed with a ten minute phone call to my bank is already public knowledge thanks to Experian, so I really don't have anything left to fear.
No pictures of your kids that they might not want spilled into a searchable database and used for machine learning to sell them things later in life?
No private or symmetric keys which might be used to impersonate you or eavesdrop on you later?
No in-progress documents which you aren't ready to publish?
No conversations with political allies that you might not want the state to peruse?
No intimate conversations with sexual partners?
If that's true, then I think you have a very different attack surface than most people. I think most people are willing to take a small performance hit not to open up access to much of the data that goes across their CPU, which is not an exaggeration for the combination of attacks which have been published against Intel CPUs over the past 3 years.
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#35It is funny how ChromeOS is the most ridiculously secure of the commonly available operating systems. It is not as if you can do much other than surf the internet with it. It makes me chuckle to think that my not-so-computer-literate friend whom I gave a Chromebook to is protected from anyone snooping in on Youtube, Hotmail and Youtube running on this toy machine (designed for 9 year olds). There really is nothing to…
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#36Earlier quoted context omitted.
I don't think that anybody can know whether this is true, since exploitation leaves little evidence. Even before this is witnessed in the wild for the first time, you can't really know which secrets of yours have already been exfiltrated.
Everything that can't be fixed with a ten minute phone call to my bank is already public knowledge thanks to Experian, so I really don't have anything left to fear.
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#37For me as a home user, taking a performance hit of any kind in response to threats which haven't yet been seen in the wild simply isn't good math.
I'd really like to be given a choice, at least. My gaming PC is used exclusively for gaming, so it needs to be performant, but does not need to be secure.
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#38For me as a home user, taking a performance hit of any kind in response to threats which haven't yet been seen in the wild simply isn't good math.
I'd really like to be given a choice, at least. My gaming PC is used exclusively for gaming, so it needs to be performant, but does not need to be secure.
1. https://yux.im/posts/technology/security/disable-meltdown-an...
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#39I like how Intel prominently thanks their own employees for finding the bugs and later simply acknowledges the existence of any anyone independent reporters with zero thanks.
Re: MDS: Microarchitectural Data Sampling side-channel vulnerabilities in Intel CPUs
#40Presuming the bytecode interpreter would be "slow enough" and "jittery enough" and "indirect enough" to hamper any attempts at exploiting subtle timing+memory layout bugs like that?
IIRC, Konqueror (of KDE) had reasonably fast bytecode JS engine. I wish the browser was still undergoing fast development, used to be my daily driver for many years.