3 ms·
> Suppose I'm a typical desktop user, how is important information going to be stolen if I have mitigations turned off and JavaScript enabled? https://github.c
by staticassertion 4y ago
> Suppose I'm a typical desktop user, how is important information going to be stolen if I have mitigations turned off and JavaScript enabled?
https://github.com/google/security-research-pocs/tree/master/spectre.js https://github.com/google/security-research-pocs/tree/master...
I don't imagine I'm going to explain it better than the many others who have already done so.
> What state does my browser have to be in, and what actions do I have to take (or not take) for the attack to succeed?
Your browser would have to be pretty old/ outdated since they've been updated to mitigate these attacks. Otherwise it's just necessary that you visit the attacker controlled website.
> What likelihood is it that someone has deployed an attack that meets those requirements?
That's not a simple question. Threat landscapes change based on a lot of factors. As I said earlier, we won't see these attacks because people have already patched and attackers have other methods.
> So we agree it's OK to leave mitigations off and browse the web?
You can do whatever you want, idk what you're trying to ask here. What is "OK" ? You will be vulnerable but unlikely to be attacked for the reasons mentioned. If you are "OK" with that that's up to you.
- coldpie 4y agoYeah again, that's a carefully controlled research setup. These attacks are not going to dump your bank passwords straight to badguys.com. They're going to get some random chunks of memory that very probably don't contain anything of value. Browser renderer process don't contain contiguous memory chunks that say like, "BANK_PASSWORD_IS:asdf1234", it would take an incredibly amount of luck and further investigation of every single memory chunk retrieved to possibly gain anything of value. That's not how drive-by attacks work. It's a really impractical attack outside of extremely targeted scenarios. It's not something real desktop end-users need to worry about. The mitigations slow down your system for zero benefit. > You can do whatever you want, idk what you're trying to ask here. What is "OK" ? Maybe re-read the thread from the start? The first guy I responded to was making an assertion that running without spectre/etc mitigations means you should turn off javascript.
- staticassertion 4y ago> Yeah again, that's a carefully controlled research setup. The POC runs in visitors browsers lol it's a public demo that runs in your browser, not in a "carefully controlled research setup". > that very probably don't contain anything of value Lots of things are valuable other than passwords. Even just leaking addresses can be useful for further exploitation. The main issue is it's a violation of a security boundary. > The first guy I responded to was making an assertion that running without spectre/etc mitigations means you should turn off javascript. They said "I hope you <do that>". Presumably because it would also mitigate the issue.