Spectre just became a much bigger problem.
not really... this is only a vulnerability in so much as specific gadgets were intentionally placed in code. it's more of a danger for intentional data exfiltration covertly, not an issue of attacking random servers like ssh or web servers to get keys. show me a vulnerable ssh or web server and i'll be worried, otherwise, this is just hype about a new class of theoretical attack that has no known actual real world ta…
this class of attack is theoretical, and all the hype is unsubstantiated. clearly y'all haven't read the paper. people never read past the headlines any more...
you don't even have to take my word for it, READ THE PAPER:
> As NetSpectre is a network-based attack, it cannot only be preventedby mitigating Spectre but also through countermeasures onthe network layer. A trivial NetSpectre attack can easily be detectedby a DDoS protection, as multiple thousand identical packets aresent from the same source. However, an attacker can choose anytrade-off between packets per second and leaked bits per second.Thus, the speed at which bits are leaked can simply be reducedbelow the threshold that the DDoS monitoring can detect. This istrue for any monitoring which tries to detect ongoing attacks, e.g., intrusion detection systems. Although the attack is theoretically not prevented, at some point the attack becomes infeasible, as the time required to leak a bit increases drastically. Another method to mitigate NetSpectre is to add artificial noise to the network latency. As the number of measurements depends on the variance in network latency, additional noise requires an attacker to perform more measurements. Thus, if the variance in network latency is high enough, NetSpectre attacks become infeasible due to the large number of measurements required.