3 ms·
One thing curiously missing from this article is ARM’s laudable in-depth analysis - https://developer.arm.com/support/security-update https://developer.arm.com/
by andreiw 9y ago
One thing curiously missing from this article is ARM’s laudable in-depth analysis - https://developer.arm.com/support/security-update https://developer.arm.com/support/security-update, and their efforts (https://developer.arm.com/support/security-update/compiler-support-for-mitigations https://developer.arm.com/support/security-update/compiler-s...) to bring in architecture-neutral compiler intrinsics to address variant 1.
- roca 9y agoPerhaps I probably should have mentioned that, but I think the array index masking approaches are going to prevail.
- andreiw 9y agoThat’s assuming the only thing you want to prevent is speculative bounds overrun. Even with masking, you can still leak the secret in the array from the path not taken? Do you see evidence of gcc or clang gravitating to the MS approach? In many ways, spectre is one more kind of attack on code that doesn’t properly separate validating untrusted input from acting on that input, except unlike overruns and TOCTOU races, this is microarchitectural.