Live data from Hacker News

MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

techcrunch.com

1–10 of 204 posts

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#4
post #3

Sounds like it requires physical access to a device, is that right? At least less of a concern than software only, though still not good.

As the article puts it, it's a breach in “last line” security defences. Specifically, it's a mitigation that applies when you already have code execution. It's nothing for most people to worry about. PACs are a new mitigation that Intel Macs didn't have, so it's not like it puts the M1 in a worse position than what it replaced.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#5
OT, but is anyone here also redirected to "" rel="nofollow">https://guce.advertising.com/collectIdentifiers?sessionId=3_...", which gets blocked by µBlock Origin? It's a HTTP redirect.

This only happens with my IPv6 landline internet connection (german carrier Telekom), via IPv4 mobile internet (T-Mobile) it loads fine. Happens with two different devices, so it shouldn't be a compromised device, Techcrunch TLS certificate is valid, so it also should not be a compromised router or my ISP. Are they A/B testing?

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#6

OT, but is anyone here also redirected to " " rel="nofollow">https://guce.advertising.com/collectIdentifiers?sessionId=3_... ", which gets blocked by µBlock Origin? It's a HTTP redirect. This only happens with my IPv6 landline internet connection (german carrier Telekom), via IPv4 mobile internet (T-Mobile) it loads fine. Happens with two different devices, so it shouldn't be a compromised device, Techcrunch TLS cert…

Yeah, I'm getting this too. TechCrunch somehow managed to get even worse.

edit: https://spectrum.ieee.org/pacman-hack-can-break-apple-m1s-la... seems to cover the same thing with less spyware

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#7

This is the second hardware security flaw in the M1. Was this known to Apple in time for M2?

Second security flaw that is nowhere near as significant as Meltdown/Spectre and their endless derivatives. Still a good showing.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#8
As someone with a bit of experience in this area, IMO, the Techcrunch article is more confusing than it should be.

Here's a link to the actual abstract. The work will be presented at ISCA, which will start on June 18. https://dl.acm.org/doi/10.1145/3470496.3527429

Here's a link to MIT's press release. https://www.csail.mit.edu/news/researchers-discover-new-hard...

Here's a link to the vulnerability's website, as is tradition now. (Plus the paper) https://pacmanattack.com/

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#9

OT, but is anyone here also redirected to " " rel="nofollow">https://guce.advertising.com/collectIdentifiers?sessionId=3_... ", which gets blocked by µBlock Origin? It's a HTTP redirect. This only happens with my IPv6 landline internet connection (german carrier Telekom), via IPv4 mobile internet (T-Mobile) it loads fine. Happens with two different devices, so it shouldn't be a compromised device, Techcrunch TLS cert…

Not on my side, but it wouldn't be the first time some third party advertising server would be serving malware. Malvertising will restrict itself to only some visitors to make sure it's not detected and blocked too quickly.

The massive cookie wall I'm met with when opening this site makes it clear that it's probably impossible to determine which third party is responsible this time.

You can read the article safely here: https://12ft.io/proxy?q=https%3A%2F%2Fweb.archive.org%2Fweb%...

The web archive also seems to be redirected for some reason, though that might as well be intentional.

Edit: thinking about it, this might also be an attempt to use first party tracking to bypass third party cookie restrictions. Maybe they're A/B testing a new advertising tool?

Post reply on HN