4 ms·
While I mostly agree with that assertion (we do run with mitigations off in our small dedicated devices), there is an important caveat: this only applies if yo
by suid 4y ago
While I mostly agree with that assertion (we do run with mitigations off in our small dedicated devices), there is an important caveat: this only applies if you're 100% positive that you control everything that runs on your box.
If you have _any_ sort of vulnerability in anything that runs on your box and talks to the outside world, that allows for execution of attacker-injected code (even running unprivileged), you're now vulnerable to these speculative execution attacks.
You have to decide how much of a risk you're willing to take in this regard.