4 ms·
This is a great point. Probably someone will argue properly configured apache will not have access to data ... etc. I think the practical reality is in many set
by lsd5you 9y ago
This is a great point. Probably someone will argue properly configured apache will not have access to data ... etc. I think the practical reality is in many setups it already does, and what these hardware bugs mean is that the lazy imperfect - effectively single layer - security that probably exists on the majority of servers is now essentially equivalent to the security of systems where the security minded have been incredibly diligent (and at considerable cost) ensuring multi layer security ... etc. So in some sense it is an attack on their value system and their worth/usefulness.
- jameshart 9y agoI think this is a fantastic insight. There is a particular mindset of security thinking which compartmentalizes breach impacts on the basis of how much of the security infrastructure itself is compromised. 'well, they get remote code execution, but at least they can't recover passwords', or 'this vulnerability is bad because it allows recovery of temporary TLS keys'. And Spectre/Meltdown seems to turn every vulnerability into one of these 'world shattering' security breaches that mean your secret keys are all exposed. But for servers, the application-level vulnerabilities that are needed in order to get meltdown or spectre attacks to run are already devastating. Take over a game server process and you own the in game currency and the scores and the ability to ban users, and probably user level login as well. And you have your pick of privilege escalation mechanisms already, probably.