3 ms·
(blog author here) It's unclear but I doubt it is practical given the preconditions required in the Spectre paper. see https://spectreattack.com/spectre.pdf ht
by philip_coinbase 9y ago
(blog author here) It's unclear but I doubt it is practical given the preconditions required in the Spectre paper. see https://spectreattack.com/spectre.pdf https://spectreattack.com/spectre.pdf, section 5 for the details of Spectre2 (aka branch target injection). Successful exploitation depends on the ability to predict the location of a useful gadget in target process memory and impact is limited to processes running on the same physical core. It also requires a branch mis-prediction training period which seems to be significantly easier to execute if you're running as an application and share a library with your target. Not saying it is impossible, but the bar to success seems way, way higher than with Spectre1.
- javert 9y agoThanks for weighing in. Speaking as a layman: Running on the same physical core is a pretty common case on laptops. Sharing a library with your target is probably a very common case. For instance, libc.
- gesman 9y ago>> Let us know by filing a ticket ... Last few tickets I filed with Coinbase took days/weeks/never to get a response. Others seems to have a similar experience: https://www.reddit.com/r/Bitcoin/comments/735yqe/how_do_you_get_coinbase_to_respond_to_a_support/ https://www.reddit.com/r/Bitcoin/comments/735yqe/how_do_you_... >> However, there are a few actions you should take right now to limit your exposure ... None of the actions suggested includes the action of keeping cryptocurrency in user's own deterministic wallet to avoid any exposure from Coinbase side.
- deleted 9y ago[deleted]
- goldenkey 9y agoCoinbase is such a giant scam. Insider trading...questionable banning of users..the list goes on. Doing business with the devil is never pleasant!