4 ms·
I'm a bit confused? Most security issues can be solved with microcode updates, kernel-level mitigations, or compilation level mitigations? I'm not exactly sure
by luyu_wu 2y ago
I'm a bit confused? Most security issues can be solved with microcode updates, kernel-level mitigations, or compilation level mitigations? I'm not exactly sure why this is as big of an issue as you make it sound?
Realistically, anyone who cares about security should turn off SMT, which fixes speculative vulnerabilities (which is most of the serious ones). Additionally, a lot of the headlining vulnerabilities these days seem to require physical access of some kind, more relevant for portable devices.
Edit: the best solution of course would be to have Coreboot.
- getcrunk 2y agoMost != all Os level microcode updates only address a portion of these vulns, same for disabling smt. One unpatched vulnerability is too many let alone numerous. Not all require physical access either