5 ms·
This is so deep and complex that I don't expect to be at ease using computer in the future. There can only be more flaws that easily open this can every time so
by binaryapparatus 9y ago
This is so deep and complex that I don't expect to be at ease using computer in the future. There can only be more flaws that easily open this can every time somebody wants to open it.
The only half secure way I see is to carefully pick what I install and forget running any JS code in browser, ever. Typing this in w3m/vim btw. Makes sense?
FreeBSD I am using just issued news about not being ready yet to fix this vulnerability. Fun.
https://www.FreeBSD.org/news/newsflash.html#event20180104:01 https://www.FreeBSD.org/news/newsflash.html#event20180104:01
- cryptonector 9y agohttps://news.ycombinator.com/item?id=16068363 https://news.ycombinator.com/item?id=16068363 > This could be an extinction level event for less popular OSes. Intel, and to a lesser extent AMD, may end up causing enormous damage for which they'll pay nothing much.
- anonacct37 9y agoThis is true, but like other extinction level events it might actually open up the space for some new ideas. Someone on my twitter put it this way: microkernels could see a resurgence if the cost of a context switch into kernel is just as high as the cost of context switching between 2 processes.
- nly 9y agoMicrokernels you say? Yay, more complexity! In all seriousness, the Nintendo Switch users a microkernel and just got completely p3wned. It's extremely fanciful that we know how to build robust modular microkernels when we can't even get the simple stuff right.
- willtim 9y agoI think you have it backwards. Monolithic kernels are by their very nature more complex to reason about due to all the communication backchannels made possible when everything sits in one process.
- SOLAR_FIELDS 9y agoThis discussion seems vaguely familiar for some reason...[1] https://en.wikipedia.org/wiki/Tanenbaum%E2%80%93Torvalds_debate https://en.wikipedia.org/wiki/Tanenbaum%E2%80%93Torvalds_deb...
- marcosdumay 9y agoMicrokernels mean more insulation and standardization. Yes, it's a form of complexity; just not what tend to relate to problems.
- derekp7 9y agoThe complexity comes from when those standards don't let you do something, and you have to do weird things to break through them. Such as leaky abstractions.
- marcosdumay 9y agoMicrokernels IPC ought to be enough for anybody. Seriously, completely generic IPC is not something impossible. You may have some to create some large drivers, but the insulation is still there, even for those.
- anonacct37 9y agoIt's definitely a tradeoff. Distributed systems are hard. Isolation is good. One of the best tools we have for isolation is processes and MMUs. I'm not saying we should all switch, it's just that it's possible, given my understanding of how we're dealing with the intel bug, that one of the arguments against microkernels just went way. So they might make sense in places they previously didn't.
- lloeki 9y agoLISP machines!
- starsinspace 9y agoDepends on the target audience. For example, Haiku most probably won't get around to implement KPTI any time soon. But then again, most people consider it more of a fun/hobby OS[0] anyway, so it wouldn't matter that much. [0] And that isn't meant negatively at all, I actually think the computing landscape would be way more fun again if there were many more projects like it again. Not every OS needs to try and be an everything-OS, and not every OS needs to follow the "always online, everything through the internet" paradigm. If the most interesting use-cases are entirely offline, most of today's popular attack vectors cease to exist.
- userbinator 9y ago...and don't forget TempleOS, which follows the philosophy/religion of deliberately running everything in ring0 and one address space, because it believes the user should have full control over everything in the system.
- waddlesplash 9y agoHaiku has run all GUI applications as root since forever, so as soon as you got RCE you could install a rogue keylogging driver silently. Obviously fixing that is higher up on the priority list than KPTI... and it's unclear when we'll get around to that, even. :(
- agumonkey 9y agoMaybe having arrays of simpler CPUs and safer full stack semantics (linear logic). in order instead of out of order, more trivial parallelism..
- marcosdumay 9y agoLike the Mill. Why don't they release the Mill already? RISC-V is OoO, isn't it?
- agumonkey 9y agoMill guys are not rushing anything to say the least, for better or worse. i don't know riscv arch but I've seen it mentionned in spectre paper so that's probably the case
- jstewartmobile 9y agoYou are talking sanity in an insane world. My money is on more x86 procs with more cores, and even flakier cache coherency and memory protection.
- agumonkey 9y agoIf Intel pulls this off i'll applaud
- jerf 9y agoThat might be a bit of an overreaction. But I will concede this is a close as I've ever seen this get to reality: http://ansible.uk/writing/c-b-faq.html http://ansible.uk/writing/c-b-faq.html Which is really sequel to the short story: http://www.infinityplus.co.uk/stories/blit.htm http://www.infinityplus.co.uk/stories/blit.htm , and which is followed up with http://www.lightspeedmagazine.com/fiction/different-kinds-of-darkness/ http://www.lightspeedmagazine.com/fiction/different-kinds-of... (the "FAQ" I linked above is in between those two things).
- mindcrime 9y agoIt also calls to mind the idea of the "blipvert" from Max Headroom.
- JeremyBanks 9y agoI think the parallel's a bit of a stretch, but I really enjoyed the story, so thanks for sharing.
- jerf 9y agoI agree it's a stretch, but it's a fun link. The parallel I see is that this is as close to anything I've ever seen in this industry to having to start so far back again. I very much suspect that we're going to be playing cat and mouse with timing attacks for the next 10 years, while pie-in-the-sky research projects just get started more-or-less today that will finally fix it. The Mill CPU people have popped up a few times today... they seem to have an interesting opportunity here.
- DanBC 9y agoI love the fact that every now and again Blit gets mentioned on HN. https://hn.algolia.com/?query=blit%20infinityplus&sort=byPopularity&prefix&page=0&dateRange=all&type=comment https://hn.algolia.com/?query=blit%20infinityplus&sort=byPop...
- lisper 9y agoYou left out the real-life version: https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html
- lima 9y agow3m had its fair share of vulnerabilities :) It's parsing untrusted data using C. It's not secure because it renders to a terminal!
- binaryapparatus 9y agoYeah I know, I am so desperate to hope that obscurity will provide security :) Seriously at least no more JS running free in browser makes me happy on so many levels.
- starsinspace 9y agoThe idea of running untrusted code on your computer, and trying to isolate it, seems to be broken for now. I'd also be surprised if this is the last such hardware bug we hear of... As for Javascript: I use uMatrix in Firefox, with a default rule that disables all JS unless I explicitly have whitelisted it for a certain domain. Some websites break and don't show content. I intend to just skip those websites. The reason I set this up was actually to prevent tracking, but now it seems that it's good security practice too... The web is getting more and more annoying anyway, and I waste way too much time with it, so reducing my reliance on it seems like a good idea in any case.
- duozerk 9y agoI do the same when it comes to JS, with noscript (although umatrix looks even better, thanks); if only because - on top of the privacy implication - almost all the browser 0days these days come from JS.
- deleted 9y ago[deleted]