4 ms·
Having read the tech reports myself, the interviewee on the Bloomberg report seemed to be most sensible talking head I've yet seen in the media. While most of t
by 3chelon 9y ago
Having read the tech reports myself, the interviewee on the Bloomberg report seemed to be most sensible talking head I've yet seen in the media. While most of the press are shouting that we're all pwned and it's Intel's fault or Apple's fault, or whoever, I'm of the opinion that this is one seriously difficult bug to exploit.
The speculative branch predication vulnerability seems to basically depend on finding a specific instruction sequence in the target code and then going to some extraordinary lengths to exploit it via a highly convoluted side-channel.
My first thought when I started to appreciate the technical details were that this was a Bletchley Park level of exploit, or "nation state" as the man in the interview said. And whilst it's completely possible that the exploit could be packaged up for script kiddies, it seems to me unlikely that someone with the necessary skills would do that, because the return would be too low. But states spying on each other: that seems a much more likely scenario for this.
- collyw 9y agoI am not an expert in these matters in any way, but most vulnerabilities appear fairly difficult to exploit to me (as an application developer). Isn't it usually the case that someone scripts (difficult parts of) the process and then it is a lot easier to exploit?
- 3chelon 9y agoYes, but my point is I think the exploit would be extremely difficult, and any agent capable of doing it would not be too interested in making it available to anyone else. Perhaps I'm naive, but it feels like the kind of thing government agencies would keep in their own armouries.
- katastic 9y agoExcept many hackers run on reputation, and the hacker that releases an amazing new exploit to the masses of script kiddies, is praised for it. "Difficult" is just another word for "look how much greater I am than the competition when I pwn it."
- pjc50 9y agoOr you could just download it from github. https://github.com/paboldin/meltdown-exploit https://github.com/paboldin/meltdown-exploit
- 3chelon 9y agoPerhaps I'm reading the code wrong, but that seems to be a check if your CPU is vulnerable, rather than an exploit. It seems to me that in order to actually obtain any useful information using this method would require far more work. I'm happy to be corrected if that is not the case...
- bpizzi 9y agoPlayed with it a bit, to me it is really reading data of arbitrary size starting at any given memory address. Usage is ./meltdown [hexadrr] [size] Run.sh is first reading the adress where the value of linux_proc_banner is held, with a adequat sed on /proc/kallsyms, then running the meltdown binary to check that this adress has the value stored in /proc/version, which should be the case if the exploit is indeed working (which IS the case with my CPU and current kernel). Meltdown.c is below 300 lines, the actual exploit being maybe half of that. From here, it seems to me that you can extrapolate in reading any value anywhere in the memory.
- PakG1 9y agoThe way the NSA keeps their zero-day tools in a secure locked box so that they'll never be leaked into the wild and be used for things like WannaCry?
- 3chelon 9y agoFair point, but wasn't zero-day back in June when this was first reported to the chip makers?
- pixl97 9y agoThis >I think the exploit would be extremely difficult, and this >The idea nagged at Prescher, so when he got home he fired up his desktop computer and set about putting the theory into practice. At 2 a.m., a breakthrough: he’d strung together code that reinforced Fogh’s idea and suggested there was something seriously wrong. Don't seem to match up. It may be hard, but even a security researcher doesn't bust a hard to exploit hole open in a few hours overnight. I believe that this was an area where no one was looking and now that its out in the open it will be much easier for others to exploit.
- 3chelon 9y agoYes, but again, proving there's an exploit is different to implementing it and actually stealing someone's banking details (which is the media definition of a scary hack). And you say "even a security researcher"... surely they are the guys most likely to be able to perform the exploit, in real life?
- solarkraft 9y agoTo prove the vulnerability is exploitable I'd ideally do ahead and do it. Has this not been done?
- workthrowaway27 9y agoIt's one thing to exploit something locally. It's another to exploit it remotely. And if you have local access to a machine I'm sure there are much easier ways to get root access to it.
- matt4077 9y agoBefore being patched, this exploit would have worked at any of the cloud providers: Google Compute Engine, AWS, etc. You could have run it on thousands of virtual machines and sifted through all the data of other VMs running on the same hardware. Oh, and it works (/worked) on browsers.
- not_kurt_godel 9y ago
- digi_owl 9y agoThe _sec world has its own variant of the architecture astronaut problem. These are researchers that see anything that can't stop a TLA in its tracks as fundamentally flawed. And yes, you will likely find them congregating at defcon, laughing and cheering at the sheeple board, and playing spot the fed.
- walshemj 9y agoDepends if one of the semi criminal subcontractors that the FSB /GRU use or some idiot "booze mah kidney" NSA contractor gets pwnd - all bets are off.
- sydd 9y agoMeltdown is not that hard to exploit: 1. Just download the POC, its a C program which reads the kernel memory at a speed of ~2KB/sec. 2. Deploy it to as many AWS instances as possible. 3. save the results somewhere and search it for stuff like CC card numbers or passwords. Luckily this is not possible because the tech companies were really careful about this issue and deployed a fix very quickly.