3 ms·
`boot.kernelParams = [ "mitigations=off" ];` Have there been actual JS-based attacks on users seen in the wild? I feel conflicted about this. I'm very stubborn
by predictabl3 3y ago
`boot.kernelParams = [ "mitigations=off" ];`
Have there been actual JS-based attacks on users seen in the wild? I feel conflicted about this. I'm very stubborn about enabling 2FA everywhere possible, but I just can't convince myself I need to have these mitigations enabled on my laptop. I do leave the mitigations turned on for my "servers".
- stracer 3y agoThese attacks on CPU defects do work, and if they are being used to spy on people connected to internet, the attackers won't announce it. If you really care about secrecy of your data, you would not be asking - you have to enable all mitigations, and do much more work to change patterns of computer use in a radical way to make your data somewhat secure against this level of craft. If you care about sane practices that don't cost a lot but you don't consider yourself to be an interesting target, or you're not going to change your habits of computer use, chances are, someone on the internet slurping your data randomly is not the end of the world. If that is the case (most people), then on your personal laptop you can turn the costly mitigations off. After all, keeping them all on won't by itself give you solid security, most probably there are many more attacks on CPU/kernel out there for which there are no mitigations yet. About the only scenario where keeping mitigations on is important and also "enough" is hosting/cloud vendors. "We follow the minimum industry security standard, but we don't guarantee someone else is not reading your data, that would be almost impossible."