3 ms·
Show us a shred of evidence attacks via javascript are viable using these vulnerabilities. I run ScriptBlock anyway, so it's even less of a concern for me.
by bufferoverflow 6y ago
Show us a shred of evidence attacks via javascript are viable using these vulnerabilities.
I run ScriptBlock anyway, so it's even less of a concern for me.
- deleted 6y ago[deleted]
- cipherboy 6y agohttps://github.com/ascendr/spectre-chrome https://github.com/ascendr/spectre-chrome https://github.com/cgvwzq/spectre https://github.com/cgvwzq/spectre https://github.com/alephsecurity/spectreBrowserResearch https://github.com/alephsecurity/spectreBrowserResearch https://react-etc.net/entry/exploiting-speculative-execution-meltdown-spectre-via-javascript https://react-etc.net/entry/exploiting-speculative-execution... https://www.tomshardware.com/news/meltdown-spectre-exploit-browser-javascript,36221.html https://www.tomshardware.com/news/meltdown-spectre-exploit-b... (I haven't found a JS PoC for Meltdown but I didn't look long.)
- deleted 6y ago[deleted]
- bufferoverflow 6y agoI opened the first link. The description starts with. Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...
- danShumway 6y agoShared Array Buffers are enabled by default in Chrome now, because Chrome has separate mitigations against Spectre. To the best of my knowledge, it does not have mitigations against Meltdown because it assumes those protections will be implemented at the OS/firmware level, but if anyone has more experience or insight than me on that front, they're welcome to correct me. In any case, you're making a kind of wild assumption that the type of user who disables a security feature from their OS to get a speed increase won't also likely disable security features like Site Isolation in their browser when they hear that those features increase Chrome's memory usage by somewhere between 10-20%.
- animalCrax0rz 6y agoCool. I wasn't aware Chrome re-enabled SABs, with mitigations. https://github.com/tc39/ecma262/issues/1435 https://github.com/tc39/ecma262/issues/1435
- jbjohns 6y agoSo there's a known exploit in CPUs and your response is "prove to me it can be exploited or I won't use mitigations"? In 2020 no less? What can you possibly be doing that would even notice the slowdown from these mitigations? Virtually everything we actually do will be bottlenecked by something else long before the CPU becomes an issue.