17 ms·
Update on Meltdown and Spectre
- deleted 9y ago[deleted]
- jngreenlee 9y agoA notably worthy response while others aren't handling it so well. It's nowhere close to being Coinbase's fault, but they are far in front the matter. Kudos.
- javert 9y agoDon't think this is right on one detail. Spectre2 should allow malicious JavaScript to read data from other processes. Running browser tabs in separate processes (e.g. Google Chrome's new Site Isolation) should protect data from Spectre1 alone but not Spectre2. See the table here: https://security.googleblog.com/2018/01/more-details-about-mitigations-for-cpu_4.html https://security.googleblog.com/2018/01/more-details-about-m... If that's not right I'd love to be corrected. Probably no known exploit of this yet.
- macawfish 9y agoThat's a pretty serious detail. Does that mean someone could read the clipboard?
- javert 9y agoI think so. But I'm just inferring that from Google's security blog posting; I can't say with real expertise. Would love for an expert to chime in.
- cookiecaper 9y agoDisclaimer: I'm not a CPU designer or a kernel developer so I'm not sure I've grokked this yet, but I think I did. Someone who knows, please correct me if I'm wrong. My understanding is that Spectre will allow an attacker to read any memory anywhere in userspace, so yes, that would include the clipboard. Meltdown is just an enhancement to Spectre that allows it to also read into kernel space (ring 0). Spectre is the systemic issue that accurately deduces memory values based on CPU cache heat. Meltdown is the implementation-specific issue, which affects many ARM SKUs and virtually all Intel SKUs, that makes privileged memory susceptible to the same.
- philip_coinbase 9y ago(blog author here) It's unclear but I doubt it is practical given the preconditions required in the Spectre paper. see https://spectreattack.com/spectre.pdf https://spectreattack.com/spectre.pdf, section 5 for the details of Spectre2 (aka branch target injection). Successful exploitation depends on the ability to predict the location of a useful gadget in target process memory and impact is limited to processes running on the same physical core. It also requires a branch mis-prediction training period which seems to be significantly easier to execute if you're running as an application and share a library with your target. Not saying it is impossible, but the bar to success seems way, way higher than with Spectre1.
- javert 9y agoThanks for weighing in. Speaking as a layman: Running on the same physical core is a pretty common case on laptops. Sharing a library with your target is probably a very common case. For instance, libc.
- gesman 9y ago>> Let us know by filing a ticket ... Last few tickets I filed with Coinbase took days/weeks/never to get a response. Others seems to have a similar experience: https://www.reddit.com/r/Bitcoin/comments/735yqe/how_do_you_get_coinbase_to_respond_to_a_support/ https://www.reddit.com/r/Bitcoin/comments/735yqe/how_do_you_... >> However, there are a few actions you should take right now to limit your exposure ... None of the actions suggested includes the action of keeping cryptocurrency in user's own deterministic wallet to avoid any exposure from Coinbase side.
- deleted 9y ago[deleted]
- goldenkey 9y agoCoinbase is such a giant scam. Insider trading...questionable banning of users..the list goes on. Doing business with the devil is never pleasant!
- helenius 9y agoFriendly reminder to disable Javascript, at the very least, by default. Only run Javascript on domains you really need and trust, and even then the minimum amount required for the site to function. https://github.com/gorhill/uMatrix/ https://github.com/gorhill/uMatrix/
- iak8god 9y ago> Only run Javascript on domains you really need and trust, and even then the minimum amount required for the site to function. This is so inconvenient that practically no one is going to do it. I used to use NoScript but found I was just constantly clicking "temporarily allow."
- macawfish 9y agoI think this is a foreshadow of what's to come with quantum computers. While side channel attacks aren't directly related to quantum computing, they're of a similar character. Quantum computing will enable new kinds of analysis that aren't possible to do quickly right now, and exploits based on it will very likely take people by surprise in the same way that this one has... even those of us who saw it coming. It will be a weird, unsettling feeling when these classical cryptography algorithms, which everyone trusts so casually right now, start actually being compromised.
- gizmo686 9y agoQuantom computers are going to be much "slower" in terms of becoming a problem. We just had the public disclosure of Meltdown and Spectre, and I suspect that, with what is known publicly, a non trivial amount of CS undergrads would be able to successfully craft an exploit based on this. In contrast, even if we suddenly solved the engineering challanges of building a large quantum computer, it would likely take a while for the economics to work out where a quantum based attack would be economical. For one, for the foreseable future, quantom computers would be expensive (needing high cooling at a minimum), so a 'casual' attacker would need to wait for an economical rental type service to emerge. Also, it would take time to scale up production, so the first bunch of quantum computers will be expensive due to market pressures from big players. In reality, it is likely that quantom computers would see a gradual (even if exponential) rise in power that would give some idea of a timeline for when we have to adapt. Not to mention the research into replacing quatom vulnerable crypto with quantom resistent crypto for over a decade, and has already led to (seemingly) quantom resistent replacements.
- macawfish 9y agoThis is an interesting perspective. It reminds me of waking up one day and watching a video of boston dynamics' atlas sticking a backflip. Yes, these things have been in development for decades, but there's something very startling about when you suddenly realize how much they've matured.
- 9y ago
- wslh 9y agoKnowing Coinbase uses AWS, they were my main concern: https://news.ycombinator.com/item?id=16066221 https://news.ycombinator.com/item?id=16066221 They answered fast.
- DennisAleynikov 9y agoGlad to see coinbase communicating proactively to assess their own risk factors and let them be known
- matthewaveryusa 9y agoHow does cycling AWS instances quickly provide additional security beyond obscurity?
- sanxiyn 9y agoObscurity does provide additional security.
- MichaelApproved 9y agoThey aren’t trying to obscure, they’re trying to be a moving target.
- lloydde 9y agoRotate, Repave, and Repair “Its idea is quite simple. Rotate datacenter credentials every few minutes or hours. Repave every server and application in the datacenter every few hours from a known good state. Repair vulnerable operating systems and application stacks consistently within hours of patch availability. Faster is safer.” https://builttoadapt.io/the-three-r-s-of-enterprise-security-rotate-repave-and-repair-f64f6d6ba29d https://builttoadapt.io/the-three-r-s-of-enterprise-security...
- disordr 9y agoWhen you reboot your EC2 instance, that VM is provisioned on a (patched) system.
- _callcc 9y agoYes, they would have been better off leaving out this "cycling" bit altogether.
- TJSomething 9y agoPerhaps proving that you're running on the same hardware as Coinbase is most easily done by statistical attacks, which requires collecting data over time.
- dsacco 9y ago> How does cycling AWS instances quickly provide additional security beyond obscurity? The same way issuing a new session token for each login improves security. If the changes are unpredictable, whatever process an attacker uses to guess the correct target must be restarted every time the target changes.
- cookiecaper 9y ago> Coinbase runs in Amazon Web Services (AWS) and our general security posture is one of extreme caution. Now more than ever, this statement just does not compute. What good reason could something as sensitive as Coinbase have to remain on a third-party cloud provider and let Amazon hold the keys to the kingdom, especially after this disclosure that informs us that our imagined VM sandboxes have been a fairy tale all along? There's a secret from a time not so long past that makes these attacks nearly-irrelevant: "don't run untrusted code". Maybe the corollary "don't run on hardware that runs untrusted code" is necessary (though I personally feel it's a little redundant). It's embarrassing that Coinbase would continue to expose their application to this attack surface after yesterday's disclosures. Honestly, it should've been that way before; this isn't the first time VM isolation has been broken, and it won't be the last. It's just the least-fixable breakage so far. > Sensitive workloads, especially where key handling is involved, run on Dedicated Instances (instead of shared hardware). Where we do run on shared hardware, we make it more difficult to accurately target one of our systems by rapidly cycling through instances in AWS. I'm quoting this just because I know people will say I'm excluding the context if I don't. If you're going to run on "dedicated instances" anyway and pay the huge price premium for them, there's no reason to continue to put your secrets in Amazon's hands. Little ragtag startups may use the excuse "We're scared of real sysadmins, they will laugh at us because they're over 25", but that excuse should not work for something as big and serious as Coinbase. Playing Instance Roulette by "rapid cycling [instances]" in hopes that you get away from any bad neighbors ASAP is extremely silly, please give me a break. Just buy some hardware. How is this so hard?
- hellbanner 9y agoNot sure why you're being downvoted. Running any kind of financial service I would expect a corp to run their own hardware.
- jlgaddis 9y agoThose who trust Amazon with all of their secrets don't like to be told that they shouldn't be doing it.
- 9y ago
- liamzebedee 9y ago[related] Has anyone considered the possibility of a Spectre-style attack in Ethereum's Turing-complete EVM? Not that the state would be unique for all contracts, but there's a possibility of communicating to an external contract with the output.
- lkjkjhkjhjkh 9y agoGPU's don't have branch prediction, so that's nice.
- moyix 9y agoThere's a twitter thread where some cryptographers speculate on the possibility. The upshot is that it doesn't seem like it will be possible: https://twitter.com/bascule/status/948725249842937857 https://twitter.com/bascule/status/948725249842937857
- gibybo 9y agoFrom my understanding there are a couple things that probably make this a non-issue: 1) Worst case scenario, it only allow you to read the memory of systems running validator nodes. There aren't very many of these (tens of thousands perhaps) and they generally don't store particularly valuable secrets. A small number of them may store private keys to Eth accounts with a small amount of Eth, but that's not typical operating procedure. 2) The EVM doesn't have any internal mechanism for measuring time (beyond existing blocks), so any timing attack within the EVM would require some very clever way of measuring time.
- _callcc 9y agoIn the Spectre paper they note that while Chrome degrades the resolution of `performance.now()`, they were able to get a timer with sufficient resolution by using a Web Worker (thread) which repeatedly decrements a value in shared memory. As far as I know the EVM intentionally doesn't provide any concurrency because execution must be deterministic, and it seems doubtful that any kind of message-passing from outside the contract would be fast enough to provide the resolution needed. However, the block-lattice cryptos like RaiBlocks that find a way to build in concurrency and shared memory might be different.
- 9y ago
- benjaminjackman 9y ago>Where we do run on shared hardware, we make it more difficult to accurately target one of our systems by rapidly cycling through instances in AWS. Wait, doesn't that just spray their sensitive information over more and more machines that may or may not be sufficiently wiped before it's reassigned to someone else? Or increase the chance they encounter someone running one of these exploits panning for digital gold in the other users RAM?
- jlgaddis 9y agoAnd what happens to that RAM when an instance is terminated. Is it zeroed or does the data linger until it is later overwritten by another process? Or maybe that's what you're referring to?
- TJSomething 9y agoI'd hope that Amazon would zero out that RAM first, since whoever uses the machine next could always dump /dev/mem.
- wqerqwerqwe 9y agoData for coinbase.com sam.ns.cloudflare.com sue.ns.cloudflare.com A direct-connect IP address was found: coinbase.com 107.21.102.138 UNITED STATES Previous lookups for this domain: 2015-04-28: coinbase.com 107.21.102.138 UNITED STATES 2015-02-28: coinbase.com 54.243.122.18 UNITED STATES http://www.crimeflare.us/cgi-bin/cfsearch.cgi http://www.crimeflare.us/cgi-bin/cfsearch.cgi --- They've also used the same EC2 IP address for 3 years, so the claim is bullshit.
- tinix 9y agoYou know an IP doesn't necessarily mean a single machine instance, right?
- mdeeks 9y agoIt is probably an ELB that fronts multiple VMs that they cycle through. Also, that is only their website. I'm sure they have more infrastructure than just the VMs that host their web app. It is quite easy to have a single unchanging IP address and constantly rotating instances behind it.
- thisisit 9y agoThis announcement makes me wonder - Are there any banking laws to protect someone who loses money due to a hack? The JS thing is a huge deal so someone might get their online banking credentials stolen and then account emptied. In which case, how helpful are the banks in helping to recover the money? On the cryptocurrency side people need to secure their own money and ensure they don't open some shady ICO site. So stolen credentials means the money is gone forever. Edit: FDIC insurance is applicable for the banks ie if the banks get hacked. The question here is on individuals getting hacked. I am not able to find if FDIC covers that.
- duncan-donuts 9y agoWould the FDIC cover losses?
- a_cactus 9y agoMoney in banks is FDIC insured. I believe that protects it from things like hacks, even if the bank itself went bankrupt.
- Cyph0n 9y agoFor regular consumers, the FDIC insures up to $250k IIRC.
- walterbell 9y agoInsurance companies usually try to reduce/manage risk. Does the FDIC have security / computer / process requirements for the banks which they insure against hacks?
- Vendan 9y agoI think that would be part of the FFIEC https://www.ffiec.gov https://www.ffiec.gov
- twblalock 9y agoFDIC insurance doesn't cover theft or fraud. It covers your balance (up to a limit) if the bank fails. There are separate regulations for fraud.
- dukeflukem 9y agoPossibly off topic, but is this a bad time to use any software that knows your cryptocurrency private keys. Such as wallet software?
- dredmorbius 9y agoOr, say, ssh-agent, going beyond crypotocurrency.
- Taniwha 9y agoIt's a good thing no one will be running other people's untrusted code on their servers ..... Except for etherium contracts of course .... Anyone want to place bets on how long it takes before someone releases a spectre exploit in a contract? I'll take 4 days ....
- dbancajas 9y agoEvm is a stack based machine with no speculative execution. It has no concept of a process. I find it impossible to think how spectre can be implemented.
- Taniwha 9y agothe machine is still implemented with machine code, it might even be JIT'd ... after all people have used spectre from JS
- gm-conspiracy 9y agoIt is my understanding that JS provides a higher resolution of temporal comparison, which makes the exploit possible.
- grover_hartmann 9y agoI won't take anything Coinbase says seriously until they implement SegWit.
- shams93 9y agoI really appreciate how coinbase is addressing this like Chase has sent nothing about this, coinbase in contrast is telling you how they handle transactions to minimize the potential damage and what they are doing to mitigate the issues on their end. Big thumbs up to coinbase for being aggressively and open about their response to this threat.
- jonknee 9y ago... Perhaps because your money at Chase is safe regardless of the bug.
- andonisus 9y agoNo, no, you misunderstand. Please remember that crypto is good and banks are bad.
- SippinLean 9y agoCan you elaborate on how this differs from Coinbase? My understanding is that they are insured. If you are a US customer your cash balance at Coinbase is insured by the FDIC (like it is on Chase).
- jonknee 9y agoIf someone gets into your Coinbase account and transfers everything to their wallet there is no recourse and you're out all your money. If someone gets into your Chase account and transfers all your money out there is a recourse and you get all your money back. Essentially if Coinbase loses all your USD it should be covered under the FDIC, but if Coinbase loses all your BTC there's nothing you can do.
- SippinLean 9y agoRight, a strength and weakness of cryptocurrency is that you are your own bank. This post was mostly about what Coinbase is doing to mitigate the risk in their architecture (like AWS) I thought you were implying that Chase's vulnerabilites were different in some regard. >If someone gets into your Chase account and transfers all your money out there is a recourse and you get all your money back There is? My understanding is that fraud and theft are not covered by FDIC insurance.