4 ms·
I'm pretty sure he's running an unprivileged binary on his local machine, that shouldn't be able to see Firefox's memory, but can with this attack. I don't know
by gefh 9y ago
I'm pretty sure he's running an unprivileged binary on his local machine, that shouldn't be able to see Firefox's memory, but can with this attack. I don't know of any js exploit - this attack relies on specific machine code instructions that would be very difficult to get a js engine to generate.
- Klathmon 9y ago>I don't know of any js exploit - this attack relies on specific machine code instructions that would be very difficult to get a js engine to generate. The Spectre paper outlines that this is not only possible to do in javascript, but they included a Proof-of-concept of it working in javascript to read anything from that process's memory.
- GunlogAlm 9y agoTheir proof-of-concept only reads memory from the browser it's running within, right? Violating browser sandboxing, yes, but does that mean it would also (theoretically) be able to access the memory of other programs?
- Klathmon 9y agoAs far as I understand it, the JavaScript PoC only allows you to read memory from the same process. Meaning if all processes are isolated, you can't read anything other than your own tab's memory. However many browsers don't do process isolation, and just about none of them do it completely (Even Chrome won't have mitigations to this that prevent iframes from other origins doing this attack for a week or 2). And while that alone might seem pretty innocuous, think of things that are kept in memory for a specific tab. This could make XSS attacks able to grab HTTP-Only cookies, or be able to read some autofill data or potentially password autofill information. I don't know enough about the architecture of those things to know if they are kept in the same process, but if they are it's possible. That being said, I didn't read any specific reason why that JavaScript PoC couldn't be expanded to work on other processes just like the rest of the Spectre attack. And personally I'm assuming it's only a matter of time before it is figured out.
- trendia 9y ago> Even Chrome won't have mitigations to this that prevent iframes from other origins doing this attack for a week or 2 You can enable (experimental) Chrome process separation here: chrome://flags/#enable-site-per-process
- gefh 9y agoWell, shit.