Live data from Hacker News

Reading privileged memory with a side-channel

googleprojectzero.blogspot.com

61–70 of 639 posts

Re: Reading privileged memory with a side-channel

#63

So, is AMD effected or not? This seems fairly important. The Google blog post sort of goes against itself in this regard. AMD itself has said: "The threat and the response to the three variants differ by microprocessor company, and AMD is not susceptible to all three variants. Due to differences in AMD's architecture, we believe there is a near zero risk to AMD processors at this time." So either AMD is lying or Goog…

It seems like it is not affected by the most serious bug, but may be by a lesser one.

That's what I'm thinking, effected by Spectre, but not by Meltdown. But more clarity would be appreciated on Google and AMD's front. I mean from a pure PR angle, AMD has a lot to gain if they can clear the air more.

Re: Reading privileged memory with a side-channel

#64
Has Google the best security team in the world? It seems like Google security is in a complete different league. I cannot imagine how this impacts companies handling fiat money or cryptocurrencies in the cloud like Coinbase in AWS.

Re: Reading privileged memory with a side-channel

#65
post #31

Speculative execution seems like something that would be very intuitively insecure even to a layperson(relative to the field of course). I'm wondering, was this vulnerability theorized first and later found out to be an actual vulnerability? Or was this something that nobody had any clue about? I'm only saying this, because from a security perspective, I imagine somewhere at some point very early on someone had to ha…

Speculative execution isn't supposed to leak information; if the speculative instructions aren't supposed to execute, all traces of them should be rolled back. I'd be curious to see what the details of this bug really are. I'm not sure how much will be disclosed in the interests of keeping exploits from popping up.

Re: Reading privileged memory with a side-channel

#66
post #54

Could somebody please coin a name for this? Wikipedia currently calls it "Intel KPTI flaw", but that is very vague. It's quite difficult to talk about something without a simple easy-to-remember name. Edit: has been settled, it's https://en.wikipedia.org/wiki/Meltdown_(security_bug) .

https://spectreattack.com/ :).

Re: Reading privileged memory with a side-channel

#67

Earlier quoted context omitted.

"We reported this issue to Intel, AMD and ARM on 2017-06-01" What!

How much in advance do the intel managers have to register a stock sell?

For his sake, I hope longer than 6 months!

Re: Reading privileged memory with a side-channel

#69
post #54

Could somebody please coin a name for this? Wikipedia currently calls it "Intel KPTI flaw", but that is very vague. It's quite difficult to talk about something without a simple easy-to-remember name. Edit: has been settled, it's https://en.wikipedia.org/wiki/Meltdown_(security_bug) .

the MEMTHIEF bug

Re: Reading privileged memory with a side-channel

#70

"Testing also showed that an attack running on one virtual machine was able to access the physical memory of the host machine, and through that, gain read-access to the memory of a different virtual machine on the same host." Holy shit.

Main/Big impacts are on the cloud computer.

For home computer, standard office use, there is no impact at this point, right?

Post reply on HN