4 ms·
https://misc0110.net/web/files/keystroke_js.pdf https://misc0110.net/web/files/keystroke_js.pdf
by chapill 9y ago
https://misc0110.net/web/files/keystroke_js.pdf https://misc0110.net/web/files/keystroke_js.pdf
- FreedomWarrior 9y agoYou started this thread to warn about the risks of running untrusted JavaScript before the appropriate mitigations are in place, yet you expect people to open a PDF from misc0110.net with no additional context?
- kimusan 9y agoIts actually the page of one of the researchers (Michael Schwarz) who found the javascript keystroke timing attack (which is in the paper in the link). He is also one of the authors of the Meltdown/Spectre CPU Attack papers so the document is actually worth reading
- rainbowmverse 9y agoThe link goes to a site with a spammy-looking domain, and there's no reason to assume a URL with .pdf at the end is actually a PDF. There's nothing stopping the server from serving a malicious JavaScript file instead. Assuming it's safe based on available information is very bad. Even your comment isn't enough because you could be working with someone to drive people to a malicious link.
- lossolo 9y agoSo you've created your account 1 hour ago and want me to open some pdf from unknown source on unknown domain?
- jzelinskie 9y agoI think it seems pretty reasonable to disable the ability for new accounts to post links until they are no longer new. This could totally avoid scenarios like this one, regardless of whether or not this PDF is actually harmless or not.
- jrs235 9y agoI like this idea. You should email the mods with your suggestion!
- EgoIncarnate 9y agoThis has nothing to do with the recent CPU issue.