19 ms·
> if you have a device running macOS or iOS with Apple's A-series or M-series CPUs. This includes all recent iPhones and iPads, as well as Apple's laptops and d
by jeron 3y ago
> if you have a device running macOS or iOS with Apple's A-series or M-series CPUs. This includes all recent iPhones and iPads, as well as Apple's laptops and desktops from 2020 and onwards.
as a rare Intel Mac owner, I guess I am not affected then
- lern_too_spel 3y agoIf you're on MacOS, you can simply not use Safari. If you're on iOS, you have to use lockdown mode, which is the only safe way to use an iPhone. Any benchmarks done without lockdown mode should be considered as useful as CPU benchmarks run with mitigations=off.
- worthless-trash 3y agoCan you link to me where lockdown mode would prevent this kind of attack ?
- kevincox 3y agoThat's absolutely not fair. Lockdown mode isn't the default and should only provide defense in depth. Devices running the default configuration are absolutely expected to be secure.
- lern_too_spel 3y ago> Devices running the default configuration are absolutely expected to be secure. That might be the customer's expectation, but that isn't what Apple is providing. We've time and again seen that the default configuration is not secure. Apple has known about this bug for more than a year now, and the only protection remains to use lockdown mode.
- brookst 3y agoNothing in the world is 100% secure; there are tradeoffs. Lockdown mode is more secure (but certainly not 100% secure) at the expense of less usable and less performant. Demanding absolute security on the default configuration is unreasonable. No platform provides that.
- lern_too_spel 3y ago> Demanding absolute security on the default configuration is unreasonable. No platform provides that. That's not what we're expecting. Most consumer platforms provide fixes for known secret-stealing vulnerabilities in the order of weeks. What we're seeing here is an outlier.
- worthless-trash 3y agoApples initial fixes for spectre/meltdown were for safari only. They did not fix the rest of the OS for some time.
- saagarjha 3y agoYeah, no, this is absolutely not true. Every competitor has similar issues in deploying fixes: better in some places, worse in others.
- lern_too_spel 3y agoMore than a year to deploy a fix for a secret leaking vulnerability in a supported product? Do you have any examples?
- saagarjha 3y agoYou're probably affected; the cache hierarchy would just be a bit different and require some changes to the proof of concept.