3 ms·
Then, what is the value of making the software secure if the hardware isn't? The hardware issue is terrifying. And the worst part, it seems not possible to fix
by xpuente 5y ago
Then, what is the value of making the software secure if the hardware isn't?
The hardware issue is terrifying. And the worst part, it seems not possible to fix it without trowing away decades of performance enhancements. This epic screw-up of epic dimensions from computer architecture guys won't go away that easy.
- Nullabillity 5y agoWhile the hardware situation isn't ideal, secure software + vulnerable hardware is still better a better place to be in than vulnerable software + vulnerable hardware.
- krapht 5y agoIs not an epic screw-up. More like 99.9% of compute is not done in adversarial untrusted sandboxes, so who cares if another process with a lot of work can extract data from another one. You leave so much performance on the table if you demand cryptographically secure perf for everything. That means no caching, everything runs in fixed, worst case time, and the amount of work must be fixed as well so there is not any variation in power draw. Here is a simpler solution - do not run untrusted code on your computer. It is just that easy™. PS: I disable JavaScript by default in my browser, and manually whitelist exceptions, for the same reason. I also turned off Spectre mitigation on my workstation.
- stonewareslord 5y agoWhat are you using for JS whitelisting? I used to used uMatrix before it died.
- krapht 5y agouMatrix developer moved on to primarily work on uBlock Origin. It is a good successor. I think some people do not like UBo because by default it is a little light on blocking so most websites just work. Well, you can configure it to block more things, and if you use uMatrix you already are willing to deal with the pain of this process.
- stonewareslord 5y agoAh that's a shame. It isn't nearly as powerful as uMatrix which allows up to per-subdomain configuring of per-subdomain loaded images/js/styles/...
- deleted 5y ago[deleted]
- Veserv 5y agoBecause software is the weak link, not the hardware. It only costs Zerodium $200k for a VMware virtual machine escape [1] which would allow GB/s data exfiltration in contrast to a Spectre attack which only has data rates on the order of KB/s [2]. Finding zero-days in mass deployed, foundational software like operating systems or hypervisors only costs on the order of $100k-$1M and occurs routinely. In contrast, finding vulnerabilities in hardware that breach confidentiality (read-protection) or integrity (write-protection) are so rare that it is a media event when one is discovered every decade or so of aggressive searching. Hardware is literally 100x harder to successfully attack than software. We would be lucky if we had systems that were only as secure as their hardware since they would be 100x better than the status quo. [1] https://zerodium.com/program.html https://zerodium.com/program.html [2] https://www.zdnet.com/article/google-this-spectre-proof-of-concept-shows-how-dangerous-these-attacks-can-be/ https://www.zdnet.com/article/google-this-spectre-proof-of-c...
- deleted 5y ago[deleted]