4 ms·
How about side channel attack (such as meltdown and spectre) from ads? Is it possible?
by indigo62018 7y ago
How about side channel attack (such as meltdown and spectre) from ads? Is it possible?
- zie 7y agoNormally yes, but most browsers have mitigations in place that prevent this from happening, for some degree of prevent. But browser mitigations, plus OS updates and Intel/AMD firwmare updates, for machines that stay up to date make the specific Meltdown/Spectre attacks mostly not a thing in JS(in the browser). That said, Javascript(in browser) and Security are basically 100% opposites. If you can execute JS in a browser, you can do whatever you want to that page in the browser.
- zzzcpan 7y agoThere is a problem with mitigations in web browsers, the only practical problem they are targeting is a hypothetical situation of a 3rd party script running in a sandboxed iframe, but almost none of them do! They don't need side channels to steal anything, they are not isolated. And the only acceptable use for a sandboxed 3rd party iframe is to block it by default.
- zie 7y agoWell, I was going to say more on the subject, but didn't want to get flamed by JS lovers. I did say "If you can execute JS in a browser, you can do whatever you want to that page in the browser." I don't disagree with your point, but there is another perspective that the mitigations aim to stop, which is cross-tab/window data gathering (and cross process), which is most of the point of Spectre and friends anyways, which is stealing data from some other process, not the process you are running under. Stealing from your own process is easy. Stealing from another process is supposed to be hard, and stealing from the kernel is supposed to be impossible.