4 ms·
What happened to concerns on Spectre/Meltdown being exploitable through high-resolution timers implemented through shared buffers/multithreading in Chrome?
by m1el 8y ago
What happened to concerns on Spectre/Meltdown being exploitable through high-resolution timers implemented through shared buffers/multithreading in Chrome?
- gok 8y agoI believe the solution is treating same-process code as same-security code, as probably always should have been the case.
- mmastrac 8y agoAccording to [1] > Note that SharedArrayBuffer was disabled by default in all major browsers on 5 January, 2018 in response to Spectre. Chrome re-enabled it in v67 on platforms where its site-isolation feature is enabled to protect against Spectre-style vulnerabilities. [1] https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/SharedArrayBuffer https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
- feross 8y agoFixed by these: - Site Isolation (https://www.chromium.org/Home/chromium-security/site-isolation https://www.chromium.org/Home/chromium-security/site-isolati...) - Cross-Origin Read Blocking (https://www.chromium.org/Home/chromium-security/corb-for-developers https://www.chromium.org/Home/chromium-security/corb-for-dev...)
- bzbarsky 8y agoIt's not fully fixed by those, for what it's worth; I'm happy to provide examples outside a public venue. Chrome just decided it doesn't care about the security holes it's creating in websites. Other browsers are working on rolling out other mitigations they consider security-critical before being OK with re-enabling SharedArrayBuffer.