4 ms·
Which attack are you referring to? There have already been POCs for many speculative execution attacks.
by staticassertion 4y ago
Which attack are you referring to? There have already been POCs for many speculative execution attacks.
- coldpie 4y agoWhatever one Veliladon was referring to when they asserted one must run either mitigations or no javascript. My point is those POCs are not sufficient evidence that mitigations with real performance impact are justified for the typical desktop end-user. Again: > The number of stars that have to align for this theoretical attack to work in practice is so high that I don't think any normal desktop end-user has reason to worry about it.
- staticassertion 4y agoOh ok. So, no, the stars don't have to align at all. The attack is straightforward, the POCs show that. The reason we don't see these attacks is because everyone patched the major issues immediately. Further, attackers don't need to really go for these sorts of attacks, there are more reliable, well-worn methods for attacking browsers.
- coldpie 4y ago> So, no, the stars don't have to align at all. The attack is straightforward, the POCs show that. Please spell it out for me. Suppose I'm a typical desktop user, how is important information going to be stolen if I have mitigations turned off and JavaScript enabled? What state does my browser have to be in, and what actions do I have to take (or not take) for the attack to succeed? What likelihood is it that someone has deployed an attack that meets those requirements? > Further, attackers don't need to really go for these sorts of attacks, there are more reliable, well-worn methods for attacking browsers. So we agree it's OK to leave mitigations off and browse the web?
- digitaLandscape 4y ago[dead]
- staticassertion 4y ago> Suppose I'm a typical desktop user, how is important information going to be stolen if I have mitigations turned off and JavaScript enabled? https://github.com/google/security-research-pocs/tree/master/spectre.js https://github.com/google/security-research-pocs/tree/master... I don't imagine I'm going to explain it better than the many others who have already done so. > What state does my browser have to be in, and what actions do I have to take (or not take) for the attack to succeed? Your browser would have to be pretty old/ outdated since they've been updated to mitigate these attacks. Otherwise it's just necessary that you visit the attacker controlled website. > What likelihood is it that someone has deployed an attack that meets those requirements? That's not a simple question. Threat landscapes change based on a lot of factors. As I said earlier, we won't see these attacks because people have already patched and attackers have other methods. > So we agree it's OK to leave mitigations off and browse the web? You can do whatever you want, idk what you're trying to ask here. What is "OK" ? You will be vulnerable but unlikely to be attacked for the reasons mentioned. If you are "OK" with that that's up to you.
- coldpie 4y agoYeah again, that's a carefully controlled research setup. These attacks are not going to dump your bank passwords straight to badguys.com. They're going to get some random chunks of memory that very probably don't contain anything of value. Browser renderer process don't contain contiguous memory chunks that say like, "BANK_PASSWORD_IS:asdf1234", it would take an incredibly amount of luck and further investigation of every single memory chunk retrieved to possibly gain anything of value. That's not how drive-by attacks work. It's a really impractical attack outside of extremely targeted scenarios. It's not something real desktop end-users need to worry about. The mitigations slow down your system for zero benefit. > You can do whatever you want, idk what you're trying to ask here. What is "OK" ? Maybe re-read the thread from the start? The first guy I responded to was making an assertion that running without spectre/etc mitigations means you should turn off javascript.
- staticassertion 4y ago> Yeah again, that's a carefully controlled research setup. The POC runs in visitors browsers lol it's a public demo that runs in your browser, not in a "carefully controlled research setup". > that very probably don't contain anything of value Lots of things are valuable other than passwords. Even just leaking addresses can be useful for further exploitation. The main issue is it's a violation of a security boundary. > The first guy I responded to was making an assertion that running without spectre/etc mitigations means you should turn off javascript. They said "I hope you <do that>". Presumably because it would also mitigate the issue.