4 ms·
How easy or how likely is a meltdown attack likely to be successful against a moderately protected PC or say a VMware Cluster...these kinds of things seem hard
by DiffEq 9y ago
How easy or how likely is a meltdown attack likely to be successful against a moderately protected PC or say a VMware Cluster...these kinds of things seem hard to pin down...and if all one can do is READ - exactly what is to gain here? It seems that the machine would have already had to have been compromised in another way to get the memory that has been READ off and out of the computer system.
- captn3m0 9y agoThere are known PoCs for Meltdown using JS, which is what made this so scary. Heartbleed was far worse in comparison since it was remotely exploitable. But the JS vectors for Meltdown make it scary.
- jnordwick 9y agoWhere? We've been told it is possible, but I have yet to see a JavaScript exploit that wasn't basically a canned demo.
- unclepresent 9y agoI doubt it is possible to be done on JavaScript. Timing cache access is a challenging task for such high level language. The key to the attack is to figure out latency of memory access. A JavaScript app that is dealing with 100 layers of intermediate code before it actually gets to the physical memory could not see a difference between reading from actual memory or from cache. It is too slow to notice any change. Should be a pure assembler code to reliably estimate the effect of caching.
- jnordwick 9y agoIf you are already running untrusted binaries, there are bigger issues. Without a JS exploit, I'm not sure this is a big problem. And we haven't seen a real world binary version either. The versions I've seen all take running starts so to speak.
- bennofs 9y agoThe problem is that it bypasses sandboxes and isolation features... normally, JavaScript running in a VM in a sandbox in your browser cannot read all of your memory. With meltdown, that could be possible. Although for that scenario, you need to combine Meltdown with Spectre variant 1, allowing you to read arbitrary kernel memory from JavaScript in a browser.
- willvarfar 9y agoYou browse the web on your moderately protected PC? You likely run JavaScript. Nice logins and passwords to all your sites and banking stuff you have there... You connect to a wifi hotspot at the cafe with your moderately protected laptop or phone? It likely runs the JavaScript on the connect page, and all the browsing you do afterwards too. Nice passwords and logins and I see you use this laptop of private banking too... Thanks! You run your moderately protected VM on a cloud provider? So do I. In fact, mine runs on the same hardware as yours ... Nice private key you had there...