3 ms·
Previously posted on HN as well: https://news.ycombinator.com/item?id=14988157 https://news.ycombinator.com/item?id=14988157 The top comment said: > This basi
by Pyxl101 9y ago
Previously posted on HN as well: https://news.ycombinator.com/item?id=14988157 https://news.ycombinator.com/item?id=14988157
The top comment said:
> This basically adds another set of tools to the architectural-level attack toolbox. From reading this I expect we'll see some interesting developments in the future.
And of course there's an obligatory comment beginning with "this cannot possibly work... "
- wilun 9y ago> And of course there's an obligatory comment beginning with "this cannot possibly work... " its a good point about TLB and VIPT but I don't think this closes the whole class of potential issue; if too-much speculative execution is performed (even just a little bit, even just when you use some obscure instructions) on anything data depend that has been speculatively loaded before privilege checking, I guess its possible to recover the data.