3 ms·
Until someone figures out how to exploit it using JavaScript. The speed this moves it could be any minute now.
by static_noise 9y ago
Until someone figures out how to exploit it using JavaScript. The speed this moves it could be any minute now.
- kodablah 9y agoFrom spectre.pdf: > In addition to violating process isolation boundaries using native code, Spectre attacks can also be used to violate browser sandboxing, by mounting them via portable JavaScript code. We wrote a JavaScript program that successfully reads data from the address space of the browser process running it. (granted I think site isolation, if enabled, mitigates crossing domain boundaries) It goes on to show a sample JS impl that JITs into the expected insns using V8.
- deleted 9y ago[deleted]
- flukus 9y agoAnd we can't even read TFA with javascript disabled, you have to be less secure just to read the google security blog. Edit - mixing it up with this other article (https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html https://security.googleblog.com/2018/01/todays-cpu-vulnerabi...)
- jwilk 9y agoI can read the article without JS just fine.
- deleted 9y ago[deleted]
- baybal2 9y agoYet another argument against running any native or 1-to-1 bytecode in the browser like WASM