5 ms·
The Meltdown and Spectre attacks require code execution on your local machine. You can avoid both the Meltdown and Spectre attacks by not downloading and runnin
by Pilfer 9y ago
The Meltdown and Spectre attacks require code execution on your local machine. You can avoid both the Meltdown and Spectre attacks by not downloading and running untrusted software.
The Javascript attack vector for Spectre will be patched by browser vendors.
If you operate safe computing practices it is unlikely you will be hit by either the Meltdown or Spectre attacks.
- Shank 9y agoIsn’t the performance loss due to KPTI still a big factor for consideration? The security risk might not be huge but you’re still losing at least some performance due to added overhead on nearly every OS. I suppose you could disable it on Linux, but at that point it seems like you’re going against the tide.
- mkagenius 9y ago> The Javascript attack vector for Spectre will be patched by browser vendors Not just limited to browsers though. Content may be injected via other sources. Its difficult to get an exhaustive list of such application. But here is an example of iMessage : https://threatpost.com/inside-the-latest-apple-imessage-bug/117337/ https://threatpost.com/inside-the-latest-apple-imessage-bug/...
- mrunseen 9y agoMaybe OS-wide blocker for malicious JS?
- Yetanfou 9y agoNo thanks, just thinking about running 'Norton Anti-JS' (et al) on a server is enough to induce nausea. In other words, blocking 'malicious' code is reactive, not pro-active. Reactive solutions by definition end up solving yesterday's problems while being oblivious to today's - viz. liquids restriction in hand luggage.
- Pilfer 9y agoiMessage uses the WebKit rendering engine to run Javascript. The WebKit engine will be patched by its vendor Apple.
- ZenoArrow 9y agoUnless I'm missing something, Spectre isn't really a JS-based vulnerability. As far as I know, any code that runs directly on a computer with one of the affected CPUs could be used to perform the Spectre attack. Feel free to correct me if I'm wrong.
- barrkel 9y agoThere are two components: the branch prediction needs to be trained (to get it to speculatively execute the right instructions on context switch to the victim process) and precise timing needs to be available (to exfiltrate data using differences in what got cached). Without executing code, it's difficult to see how the two components could be triggered. Loading complex file formats is structurally similar to interpreting code; the output of the interpretation is some data structure, rather than some side effect, but otherwise it's very similar. There may be some loaders that are controllable and configurable enough to be programmed by data - perhaps something in the video decoding space that isn't offloaded to dedicated hardware or GPU - but I think it would be tough to find. JS or a downloadable game (which already lets people in the front door) of some kind are the best vectors.
- ZenoArrow 9y agoSure, JS was the most obvious attack vector, but my point was that it's not limited to JS. Any code that runs natively on an affected computer can exploit it. The only advantage JS has is that it's easier to get targets to run malicious code through a web browser. You seem to be in agreement with me on this.
- et-al 9y agoUgh.. when Apple introduced apps and stickers into iMessage, I knew it could be a vector for attacks. Too bad Apple doesn't give users the option to have only "text-only" messages.
- chrisper 9y agoYep, until your "trusted code" (e.g. Apache, PHP,...) has a remote code execution vulnerability. This is such a dangerous advice... you should really only disable these things if: a) your computer is not connected to the internet in any way b) it is in a trusted environment
- teget 9y agoI wonder how long it will take to get the fixes to all electron/cef based applications.