4 ms·
> What uses cases involve running new untrusted code on legacy unsupported systems? Well yes, you shouldn't be doing that (particularly the 'unsupported' bit).
by speakeron 9y ago
> What uses cases involve running new untrusted code on legacy unsupported systems?
Well yes, you shouldn't be doing that (particularly the 'unsupported' bit). The thinking here, I suppose, is that Meltdown makes privilege escalation straightforward once a malicious party has access to the system via another vector.
In my company, we run self-hosted physical servers (i.e. we're the only user on the systems) and debated whether to disable the page table isolation fix since we were seeing about a 30% performance hit.
The decision we took was that we would accept the performance hit since Meltdown means that any unauthorized entry into the system has a privilege escalation path since kernel memory is essentially readable by any process. (Quite an easy and quick decision, really.)
- Dylan16807 9y ago> The thinking here, I suppose, is that Meltdown makes privilege escalation straightforward once a malicious party has access to the system via another vector. On an unpatched system, that's not likely to be hard in the first place.