Have there been any reports of exploits using Meltdown/Spectre in the wild yet?
> We don't know.
So probably no reports ;)
131–137 of 137 posts
Have there been any reports of exploits using Meltdown/Spectre in the wild yet?
> We don't know.
So probably no reports ;)
Earlier quoted context omitted.
>>> Before anyone says "but OpenBSD broke an embargo before", this is a different project and besides having BSD in the name don't see why they were excluded. AFAIK they all share the same brand name BSD and they are all closely affiliated.
> AFAIK they all share the same brand name BSD and they are all closely affiliated. This is a gross falsehood. They all variously diverged from a parent project, called BSD, in the 90s. Since then they are wholly independent. Because of the common license and heritage, code sharing is often easy and legally unrestricted. But their leaders, policies, and philosophies are very distinct.
Earlier quoted context omitted.
> AFAIK they all share the same brand name BSD and they are all closely affiliated. This is a gross falsehood. They all variously diverged from a parent project, called BSD, in the 90s. Since then they are wholly independent. Because of the common license and heritage, code sharing is often easy and legally unrestricted. But their leaders, policies, and philosophies are very distinct.
But if one BSD get the memo, the other ones will too right ? That's the point.
FreeBSD secteam does not leak NDAed or embargoed information to other BSDs.
I wonder what will the next big security hole. I'm becoming very pessimistic about how I can trust computers. Computers can do amazing thing, but software seems fragile, unreliable and untrustworthy. I have been keeping notes on paper for years now, and it doesn't look like it's going to change.
Internet-connected computers are more secure now than they ever have been. Just take the standard precautions: update your OS and don't install untrusted apps.
Internet is still growing, and so is the computer security economy. Look at all the data breaches and leaks.
I wonder what will the next big security hole. I'm becoming very pessimistic about how I can trust computers. Computers can do amazing thing, but software seems fragile, unreliable and untrustworthy. I have been keeping notes on paper for years now, and it doesn't look like it's going to change.
>Computers can do amazing thing, but software seems fragile, unreliable and untrustworthy. Think about how many successful jobs computers have done for you/us compared to how many breaches/failures actually occur. We get overwhelmingly more stuff done with computers than without. Even if I had to attempt to send an email 10 times before it worked, that's much more convenient than walking the actual distance and deliv…
Not to mention the damage it can do to individual people, because it hard to measure.
Earlier quoted context omitted.
Meltdown affects some ARM prcessors as well. https://developer.arm.com/support/security-update
My response was in the context of privong stating that Intel and AMD were equivalently affected, when it is specifically Intel that suffers performance degradation in patching due to their unsafe usage of speculative execution.
Earlier quoted context omitted.
Microcode doesn't control everything the CPU hardware does
I'm aware, that's why I asked. Do you know? Do you have a reference? (And I'll laugh pretty hard if it's confirmed that these super-complex branch buffer adjustments are possible, but simple prefetch filters are just not possible on current Intel hardware.)