4 ms·
Mitigations for Spectre and Meltdown are also being added to the JavaScript VMs in Chrome [1], Firefox [2] and IE/Edge [3]. Are similar mitigations also needed
by bakery2k 9y ago
Mitigations for Spectre and Meltdown are also being added to the JavaScript VMs in Chrome [1], Firefox [2] and IE/Edge [3].
Are similar mitigations also needed in the VMs for other dynamic languages, such as CPython/PyPy, Ruby MRI and Lua/LuaJIT? What about the JVM and Microsoft's CLR?
Or are these other VMs not susceptible to this form of attack?
[1] https://www.chromium.org/Home/chromium-security/ssca https://www.chromium.org/Home/chromium-security/ssca
[2] https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ https://blog.mozilla.org/security/2018/01/03/mitigations-lan...
[3] https://blogs.windows.com/msedgedev/2018/01/03/speculative-execution-mitigations-microsoft-edge-internet-explorer/ https://blogs.windows.com/msedgedev/2018/01/03/speculative-e...
- UncleEntity 9y ago> Or are these other VMs not susceptible to this form of attack? I think the main difference is all the other dynamic languages don't let someone do a driveby attack, you have to download the code and run it as opposed to clicking a link and having who knows what appear.
- swinglock 9y agoActually it's not entirely exotic for games to use Lua in a manner that's comparable to JavaScript in browsers. Connecting to a server could instruct the client to download a custom map that embeds code or download and execute sandboxed code alone by design.
- pizlonator 9y ago> Are similar mitigations also needed in the VMs for other dynamic languages, such as CPython/PyPy, Ruby MRI and Lua/LuaJIT? Yes. > What about the JVM and Microsoft's CLR? Yes.
- deleted 9y ago[deleted]
- bakery2k 9y agoThanks. I suspected as much for LuaJIT because, like a JavaScript engine, it supports JIT compilation of untrusted code. It's interesting to hear that PUC Lua also needs these mitigations even though it's only an interpreter. As for implementations of Python and Ruby, they might not worry about these attacks - because AFAIK they do not try to support secure execution of untrusted code.