4 ms·
I only had a chance for a brief read over the papers, and to be frank, a lot of it goes over my head. However, from what I'm understanding, this makes Heartble
by AnkhMorporkian 9y ago
I only had a chance for a brief read over the papers, and to be frank, a lot of it goes over my head.
However, from what I'm understanding, this makes Heartbleed look like a papercut.
- userbinator 9y agoI'd say Heartbleed was worse. This one requires local code execution, whereas Heartbleed was "connect to any OpenSSL-using server, send a magic packet, and read the private keys from its memory."
- deleted 9y ago[deleted]
- tiles 9y agoTrue, though the fix for Meltdown requiring a performance hit might exacerbate bad incentives (people not wanting to upgrade) or bad publicity for major corporations (server hosts whose clients now have degraded performance). Whereas Heartbleed had a security cost, this has a possible financial cost.
- AnkhMorporkian 9y agoAlso the unpatched devices. Millions of phones don't receive patches anymore, whereas most servers do get patches. They're not really comparable in scale.
- AnkhMorporkian 9y agoThe difference is scale. OpenSSL was on a lot of servers, but this affects literally every device manufactured in the last 9 years or so. A well-crafted virus could infect nearly any computer and exploit it reliably. We're talking billions and billions of devices, as opposed to millions by Heartbleed.
- jonny_eh 9y agoAFAIK, this only allows read access of a host machine. How would it allow a VM to write to its host?
- AnkhMorporkian 9y agoFrom my understanding, the VM can exploit it too via executing a crazy amount of syscalls. I may be misunderstanding, but if that were not the case I doubt that AWS would be forcing quick reboots of a ton of its VMs. Edit: Wait, sorry, I misread. Read is all you really need, write would just be a cherry. If you can read the memory of the host kernel, then you can gain access to any other VMs on the system. This one is bottom-up, you need access to one system and in theory you can gain access to thousands.
- jonknee 9y agoBut you still have to get your code onto the device...
- zeveb 9y ago> This one requires local code execution … … and nowadays almost everyone permits remote sites to execute code in their browsers. I don't know if JavaScript can be used to implement Meltdown though.
- jwilk 9y agoFrom https://www.chromium.org/Home/chromium-security/ssca https://www.chromium.org/Home/chromium-security/ssca : This research has implications for products and services that execute externally supplied code, including Chrome and other browsers with support for JavaScript and WebAssembly.