3 ms·
In today’s “agentic” world, everyone seems to have forgotten approximately everything we used to know about security. And this new CPU is going all in on value
by amluto 2mo ago
In today’s “agentic” world, everyone seems to have forgotten approximately everything we used to know about security. And this new CPU is going all in on value speculation. Delightful.
Maybe if “cyber” models get good enough at exploiting speculation attacks, people will start demanding equipment that is less prone to these attacks.
- archipelago123 2mo agoAttacker: I can run any code on this machine? Time for speculation attacks! Attacker: Oh wait, I can run any code? I already own the machine...
- debugnik 2mo agoNot really, Spectre showcased an attack from within a JavaScript sandbox, which isn't considered to own the machine. Any side effects from speculation machinery can easily become a side-channel to infer values across security boundaries.
- samrus 2mo agoDid you forget about spectre and meltdown?
- dzaima 2mo agoaarch64 has a CPU mode, DIT (Data Independent Timing), specifically for allowing software to request all fancy value prediction stuff to be disabled for the duration of processing of sensitive data. (doesn't help when the attack target is general-purpose/user-controlled code leaking things, but if you're relying on a process not leaking memory plainly available to it without full careful control of what the process runs, you've already been fully-SOL on that for decades and nothing has nor will nor can change about that)
- amluto 2mo agoNo way, ARM screwed this up less than Intel and at least allows user code to access the control bit. Intel’s equivalent, DOITM, is not accessible at CPL3.
- scotty79 2mo agoI think security is going to get devalued in the near future. The safest strategy is going to be to need as little as possible of the stuff that you need to keep secret. And you won't keep that stuff on a device that is shared in any manner, or maybe even connected anywhere.