Live data from Hacker News

MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

techcrunch.com

121–130 of 204 posts

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#121

Earlier quoted context omitted.

It’s not just a problem with journalism but with humans in general. People are more imprecise with their comprehension of things than they are willing to admit.

Thank you. Even here on HN, plenty of folks will comment on all kinds of research they know little about.

> Even here on HN, plenty of folks will comment on all kinds of research they know little about.

I don't see anything wrong with that, because all opinions are not equal.

I think there is some level of pressure to get one's word in quickly, otherwise the nebulous cloud of commenters moves on to the next story, and your well-thought-out comment that took hours to write is seen by no-one. If you're responding to someone hoping to get into a nice conversation, you're out of luck since they have no idea you just responded to them.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#122

Earlier quoted context omitted.

Thank you. Even here on HN, plenty of folks will comment on all kinds of research they know little about.

Any thread about nutrition is so painful here.

Anything related to medicine/biochemistry can get cringe-y pretty quickly here. I think the problem is that the crowd here is generally pretty intelligent, but they know it and it's a coefficient > 1 on the Dunning-Kruger effect

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#123

OT, but is anyone here also redirected to " " rel="nofollow">https://guce.advertising.com/collectIdentifiers?sessionId=3_... ", which gets blocked by µBlock Origin? It's a HTTP redirect. This only happens with my IPv6 landline internet connection (german carrier Telekom), via IPv4 mobile internet (T-Mobile) it loads fine. Happens with two different devices, so it shouldn't be a compromised device, Techcrunch TLS cert…

[deleted]

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#124

Earlier quoted context omitted.

Welcome to journalism.

It’s not just a problem with journalism but with humans in general. People are more imprecise with their comprehension of things than they are willing to admit.

How many synonyms did you try before you landed on “imprecise”?

It’s a very diplomatic choice. Moreso than I’d have gone with. I admire your restraint!

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#125
post #34

The author is here and ought to make it all clear but if you google the title of the article you can download the paper already despite everyone being coy about it and the ACM not having published it yet. It's kind of ridiculous it's getting this kind of press before the paper is officially published and available. If the paper was published and security experts were allowed to analyze it before the tech press went n…

I downloaded Brave after googling it and got a .pkg instead of a .dmg because someone wanted to hack my new laptop, and didn't want to risk a hack that leveraged an exploit only nation states know about. They are sMArt. Like me! I still installed it because I am gullible and lazy.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#126
post #54
post #39

Earlier quoted context omitted.

Hi! I think I can clear a few things up here. Our goal is to demonstrate that we can learn the PAC for a kernel pointer from userspace. Just demonstrating that this is even possible is a big step in understanding of how mitigations like pointer authentication can be thought of in the spectre era. We do not aim to be a zero day, but instead aim to be a way of thinking about attacks/ an attack methodology. The timer us…

Something definitely went wrong here though that more guidance was not provided to the tech journalists. Most of the mainstream articles make it seem like they a) did not read the paper b) are incapable of understanding the paper c) were not provided any guidance about what any of this actually means in the real world. Which is all scary as the paper is well written and very accessible IMO.

Everything you listed are at the very end of the list of things that matter to modern day Journalist. If they even make the list.

But reading your comment does sort of put a smile on my face though. The what others would called a non-cynical world view.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#127
post #54

Earlier quoted context omitted.

Something definitely went wrong here though that more guidance was not provided to the tech journalists. Most of the mainstream articles make it seem like they a) did not read the paper b) are incapable of understanding the paper c) were not provided any guidance about what any of this actually means in the real world. Which is all scary as the paper is well written and very accessible IMO.

a) did not read the paper Yeah, that's a given. Journalists do not have time for optional tasks. b) are incapable of understanding the paper That's a safe bet. c) were not provided any guidance Asking for guidance or clarifications is another one of those optional tasks.

Clearly "did not read the article" applies to some internet commentators.

The article is pretty good and shows good understanding of what the attack is.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#128
post #54
post #39

Earlier quoted context omitted.

Hi! I think I can clear a few things up here. Our goal is to demonstrate that we can learn the PAC for a kernel pointer from userspace. Just demonstrating that this is even possible is a big step in understanding of how mitigations like pointer authentication can be thought of in the spectre era. We do not aim to be a zero day, but instead aim to be a way of thinking about attacks/ an attack methodology. The timer us…

Something definitely went wrong here though that more guidance was not provided to the tech journalists. Most of the mainstream articles make it seem like they a) did not read the paper b) are incapable of understanding the paper c) were not provided any guidance about what any of this actually means in the real world. Which is all scary as the paper is well written and very accessible IMO.

The Techcrunch article is well written and I thought summarises this rather well.

The headline is pretty reasonable too. Apple can't patch this, and as other commentators point out subsequent attack techniques are only going to make this flaw worse.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#130
post #54
post #39

Earlier quoted context omitted.

Hi! I think I can clear a few things up here. Our goal is to demonstrate that we can learn the PAC for a kernel pointer from userspace. Just demonstrating that this is even possible is a big step in understanding of how mitigations like pointer authentication can be thought of in the spectre era. We do not aim to be a zero day, but instead aim to be a way of thinking about attacks/ an attack methodology. The timer us…

Something definitely went wrong here though that more guidance was not provided to the tech journalists. Most of the mainstream articles make it seem like they a) did not read the paper b) are incapable of understanding the paper c) were not provided any guidance about what any of this actually means in the real world. Which is all scary as the paper is well written and very accessible IMO.

> It's kind of ridiculous it's getting this kind of press

> Something definitely went wrong here though

Both of these have the same reason: it's about Apple. I know someone that avoids telling people that they work at Apple, to avoid similar drama.

Post reply on HN