4 ms·
From FAQ: [Q] How long have users been exposed to this vulnerability? [A] At least nine years. The affected processors have been around since 2014. Amazing
by v8xi 3y ago
From FAQ:
[Q] How long have users been exposed to this vulnerability?
[A] At least nine years. The affected processors have been around since 2014.
Amazing how these vulnerabilities sit around unnoticed for years and then it takes two weeks for someone to code up an exploit.
- robotnikman 3y agoI have a feeling the time spent searching for the vulnerability in the first place was more than 2 weeks though.
- H8crilA 3y agoThose things come in waves. Once the first large CPU vulnerability was found then more followed soon. I think it's obvious why this is so.
- Liquix 3y agoAll a publication indicates is that a white/grey hat researcher has discovered the vulnerability. There is no way to know if or how many times the same flaw has been exploited by less scrupulous parties in the interim.
- mrob 3y agoAnd information leak exploits are less likely to be detected than arbitrary code execution. If somebody is exploiting a buffer overflow, they need to get it exactly right, or they'll probably crash the process, which can be logged and noticed. The only sign of somebody attempting Downfall or similar attacks is increased CPU use, which has many benign causes.
- ibejoeb 3y agoSince it is in a class of other well known vulnerabilities, I'm going to assume that there has been quite a bit of active research by state-operated and state-sponsored labs. I think it's more likely than not that this has been exploited.
- xyst 3y agoLikely work based off of previous exploits.