4 ms·
Not quite. A meteor is an object with no drive or desire. Attackers are adversarial and thoughtful. You can't liken a random event to a purposeful act like this
by staticassertion 4y ago
Not quite. A meteor is an object with no drive or desire. Attackers are adversarial and thoughtful. You can't liken a random event to a purposeful act like this.
It's more like saying "refusing to leave your house because you're worried you might get mugged", which might actually be very reasonable if you live in a bad neighborhood, you're a common target of crime, etc. It may not be reasonable for many others.
But analogies are pretty rough in general.
- coldpie 4y agoNo, I think meteor is closer. Mugging is in the realm of possibility, this javascript driveby theoretical attack is wildly implausible. Like, take the time to spell it out: what sequence of events has to occur for this attack to be successfully pulled off?
- staticassertion 4y agoWhich attack are you referring to? There have already been POCs for many speculative execution attacks.
- coldpie 4y agoWhatever one Veliladon was referring to when they asserted one must run either mitigations or no javascript. My point is those POCs are not sufficient evidence that mitigations with real performance impact are justified for the typical desktop end-user. Again: > The number of stars that have to align for this theoretical attack to work in practice is so high that I don't think any normal desktop end-user has reason to worry about it.
- staticassertion 4y agoOh ok. So, no, the stars don't have to align at all. The attack is straightforward, the POCs show that. The reason we don't see these attacks is because everyone patched the major issues immediately. Further, attackers don't need to really go for these sorts of attacks, there are more reliable, well-worn methods for attacking browsers.
- coldpie 4y ago> So, no, the stars don't have to align at all. The attack is straightforward, the POCs show that. Please spell it out for me. Suppose I'm a typical desktop user, how is important information going to be stolen if I have mitigations turned off and JavaScript enabled? What state does my browser have to be in, and what actions do I have to take (or not take) for the attack to succeed? What likelihood is it that someone has deployed an attack that meets those requirements? > Further, attackers don't need to really go for these sorts of attacks, there are more reliable, well-worn methods for attacking browsers. So we agree it's OK to leave mitigations off and browse the web?
- digitaLandscape 4y ago[dead]
- staticassertion 4y ago> Suppose I'm a typical desktop user, how is important information going to be stolen if I have mitigations turned off and JavaScript enabled? https://github.com/google/security-research-pocs/tree/master/spectre.js https://github.com/google/security-research-pocs/tree/master... I don't imagine I'm going to explain it better than the many others who have already done so. > What state does my browser have to be in, and what actions do I have to take (or not take) for the attack to succeed? Your browser would have to be pretty old/ outdated since they've been updated to mitigate these attacks. Otherwise it's just necessary that you visit the attacker controlled website. > What likelihood is it that someone has deployed an attack that meets those requirements? That's not a simple question. Threat landscapes change based on a lot of factors. As I said earlier, we won't see these attacks because people have already patched and attackers have other methods. > So we agree it's OK to leave mitigations off and browse the web? You can do whatever you want, idk what you're trying to ask here. What is "OK" ? You will be vulnerable but unlikely to be attacked for the reasons mentioned. If you are "OK" with that that's up to you.
- coldpie 4y agoYeah again, that's a carefully controlled research setup. These attacks are not going to dump your bank passwords straight to badguys.com. They're going to get some random chunks of memory that very probably don't contain anything of value. Browser renderer process don't contain contiguous memory chunks that say like, "BANK_PASSWORD_IS:asdf1234", it would take an incredibly amount of luck and further investigation of every single memory chunk retrieved to possibly gain anything of value. That's not how drive-by attacks work. It's a really impractical attack outside of extremely targeted scenarios. It's not something real desktop end-users need to worry about. The mitigations slow down your system for zero benefit. > You can do whatever you want, idk what you're trying to ask here. What is "OK" ? Maybe re-read the thread from the start? The first guy I responded to was making an assertion that running without spectre/etc mitigations means you should turn off javascript.
- asveikau 4y agoMugging isn't a good analogy also because software attacks, once possible, can be automated and distributed widely, are "wormable", and mugging is harder to do at scale.
- staticassertion 4y agoYes I hate analogies.
- asveikau 4y agoI was going to say a new virus emerging was a good example. In both cases: We know they are theoretically possible. We cannot say for sure when they'll emerge. Once they emerge, they can spread by themselves and become common. I guess the place it doesn't hold up is that in the exploit case, they're intentionally engineered, and for a virus, well there's the Wuhan bioweapon conspiracy theory but no, it's more like random mutations cause it.