4 ms·
https://spectreattack.com/ https://spectreattack.com/ Information site with some more information, and links to papers on the two vulnerabilities, called "Melt
by richadams 9y ago
https://spectreattack.com/ https://spectreattack.com/
Information site with some more information, and links to papers on the two vulnerabilities, called "Meltdown" and "Spectre" (with logos, of course).
(https://meltdownattack.com/ https://meltdownattack.com/ goes to the same site)
- partiallypro 9y agoI feel like the Meltdown logo was done by a real designer, and Spectre was designed by a bored developer.
- steveklabnik 9y agoIt says at the bottom they were both done by the same person.
- partiallypro 9y agoThat's funny, but also makes me wonder how you get contracted to do logos for things like this. Based strictly on her LinkedIn, she doesn't work for Google. Maybe a friend of someone? Kind of a cool gig though.
- Krenair 9y agohttps://www.linkedin.com/feed/update/urn:li:activity:6354450813158461441/ https://www.linkedin.com/feed/update/urn:li:activity:6354450... says: > Want to know what's really going on with the Intel security flaw everyone is talking about? Checkout https://meltdownattack.com https://meltdownattack.com to get all the details. This is my boyfriend's and his research team's latest work. An huge security breach which affects nearly all your computers! Stealing all your secrets never was that easy!
- stock_toaster 9y agoFrom the site: > Both the Meltdown and Spectre logo are free to use, rights waived via CC0. Logos are designed by Natascha Eibl.
- hrpnk 9y agoBoth domains were registered on 2017-12-22. Given the planned disclosure on 9th January that Google mentions and MS and others coding patches silently [1], do the early reports [2] of kernel patches, does this mean that due to coding in the open the whole disclosure procedure has been vastly accelerated? I wonder how the timing relates to New Year and many companies having holidays in CW1. [1] https://lists.freebsd.org/pipermail/freebsd-security/2018-January/009651.html https://lists.freebsd.org/pipermail/freebsd-security/2018-Ja... [2] https://news.ycombinator.com/item?id=16046636 https://news.ycombinator.com/item?id=16046636
- rofex 9y agoSorry to be daft, but hasn't the Google Zero team jumped the gun on the coordinated disclosure date by publishing their blog post 6 days in advance?
- Pharaoh2 9y agoSome researchers had independently create and demonstrated working PoC based on the linux patches they saw which read kernel memory from user space. At that point it was already public. After that its all about PR and getting people prepared for the magnitude and impact early. Also to let people know that patches that were already available can be used (restarting GCP/AWS instances, SPI on chrome).
- _delirium 9y agoAccelerated, but not vastly. Google's post says "We reported this issue to Intel, AMD and ARM on 2017-06-01", so the embargo still ended up holding for 7 months, even with it ending a week early. The domain registration dates of 2017-12-22 seem to be just when Google started to prepare for releasing the publicity materials, not when the vulnerability was discovered.
- olliej 9y agoThe problem isn't "it's not bought forward by that much relatively" in as much as you have an agreed timeline to have coordinated patches (e.g so one org doesn't push a fix before other orgs have). So if you have a bunch of orgs set up to do a release on day X, and then publish on X-[whatever] then you are effectively zero-daying. Is it super important in this case? shrug. But imagine for the sake of argument there was some undocumented cpu behaviour "if instruction x,y,z are executed in that order with these constants then catch fire", then having anyone pre-empt the agreed update time could be bad.