3 ms·
I don’t agree that exploit mitigation is where the bulk of the complexity in the compiler comes from. And if anything, with all the UB inference going on, moder
by codeflo 5y ago
I don’t agree that exploit mitigation is where the bulk of the complexity in the compiler comes from. And if anything, with all the UB inference going on, modern compilers might be more likely to compile exploitable bugs into your code than old ones were. Several well-known examples of this happening exist.
(To explain: A decade ago, if there was a code path where you dereference null, you would get a clean crash. Not pretty, and potentially a denial of service, but usually not further exploitable. Nowadays, the compiler will infer that this path is not taken, eliminate the if, potentially eliminate other checks as well because they are then reasoned to be redundant, and then randomly execute something. This is practically more dangerous in a lot more situations than Spectre ever was.)
- flerchin 5y agoIt's pretty easy to disable the spectre mitigations, and pretty easy to measure the performance impact (~10% in some workloads).