4 ms·
For an architecture that has been around for so long, if the attack was only discovered recently, then is it fair to call it 'simple'? In retrospect, anything c
by alphakappa 9y ago
For an architecture that has been around for so long, if the attack was only discovered recently, then is it fair to call it 'simple'? In retrospect, anything can be obvious.
- Nexxxeh 9y agoWe don't know when it was discovered first though. We only know that it's been disclosed now.
- halflings 9y agoFrom [1]: > We reported this issue to Intel, AMD and ARM on 2017-06-01. I don't think they have been twidling their thumbs with such a huge discovery without informing constructors. [1] https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html https://googleprojectzero.blogspot.com/2018/01/reading-privi...
- bri3d 9y agoRight - but as always with a vulnerability, especially one that's borderline-undetectable through any kind of log analysis, the question becomes "were Google really the first to think of this?" and the tinfoil kingdom builds itself from there.
- mort96 9y agoWe know (or can guess) approximately when the project zero team discovered the issue, but I think your parent comment meant that we don't know when _someone_ discovered it first. Maybe the project zero team were the very first to discover it, or maybe some state actor discovered it a decade ago and has been using it since then.
- davrosthedalek 9y agoAn obvious flaw doesn't become less obvious if it has been found. So it might be that some blackhat knew about it before, but there a lot of smart sufficiently-pale-shade-of-gray people out in the world for obvious problems to be found in less than decades. So I don't think it's an obvious problem. It seems that at least some ARM might be affected by both Spectre and Meltdown. So far, I have only seen negative meltdown tests for older AMD cores. Is there anything known for Ryzen except for the PR by AMD (and the kernel patch, which might be based on the google project zero information about older AMD cores)? While meltdown is "easy" to fix by not reading memory if unprivileged to do so, spectre is a lot harder. Even if the caches are made safe, for example by having "speculative" cache lines which will be renamed into the "true" cache when the speculative thread is actually accepted and retired: It's not the only place where there is hidden state. For example, the branch prediction might be affected, and might give a timing signal.
- willtim 9y agoIt's simple to describe and all the pieces are big red flags even on their own: Speculative evaluation has side-effects (e.g. the cache is not rolled back), speculative evaluation omits security checks, timing attacks can be used to determine the cache memory. It can even be exploited using JavaScript, no hand crafted CPU instructions required. Perhaps it took so long to find because it's only relativity recently that companies have been paying people to break the hardware?
- wilun 9y agoThere are still a lot of simple attacks yet to be discovered. In SW and in HW designs.