4 ms·
Security through obscurity is really a bad idea, and Apple is no exception. In the long run, this will likely drive the adoption of RiscV as a better alternativ
by xpuente 3y ago
Security through obscurity is really a bad idea, and Apple is no exception. In the long run, this will likely drive the adoption of RiscV as a better alternative.
- colejohnson66 3y agoThis RISC-V evangelism is worrying. Using RISC-V doesn't make your system secure; Good ISA implementations do. The ISA has no bearing on security vulnerabilities. Perhaps a faulty decoder could be a vulnerability vector, but a faulty RISC-V decoder wouldn't be compliant, and neither would a faulty ARM decoder. If I add a custom crypto extension to a RISC-V core and implement it badly, is that the fault of RISC-V? No! It's my own. And RISC-V doesn't help anyone here because their license allows me to keep my extension completely closed source - no different than Apple is today with ARM.
- xpuente 3y agoMy comment was not about the ISA implementation or specification, It's about the TCB (trusted compute base), which in Apple (like intel and AMD) is closed. In RiscV is open. I would recommend you to educate yourself on any topic before lecture others.
- snvzz 3y ago>The ISA has no bearing on security vulnerabilities. Complexity leads to bugs, some of which are going to be security bugs. ISAs impose complexity upon implementations. To claim they do not matter would be disingenuous.
- tzs 3y agoWhat does this have to do with security through obscurity? This is an issue with cache prefetching.
- xpuente 3y agoIt has to with the secure processor. Although you seems to ignore what is the TCB.
- tzs 3y agoNo, this only works on the regular processor cores. It's a cache timing attack that depends on the attack code and the targeted cryptographic code running on processors that share cache. See the FAQ at https://gofetch.fail/ https://gofetch.fail/
- meindnoch 3y agoYes. This is good for Bitcoin.