Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ddworken
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
31.
▲
by
ddworken
6y ago
While I don't know anything specific about RedLeaf, I highly doubt that it is completely immune to Spectre. Spectre fundamentally stems from how modern CPUs are designed and the current understanding is that there is no way to fix Spec
32.
▲
by
ddworken
6y ago
What do you mean by "drop it"? I guess I could imagine that a CPU would allow a specific process to disable speculative execution. That could be an interesting feature though I'm skeptical that any real world applications wou
33.
▲
by
ddworken
6y ago
Fundamentally, Spectre is a class of bugs that arises from how modern CPUs are designed. It isn't just an Intel bug, an x86 bug, or a JS bug. CPUs that perform speculative execution after a branch prediction are generally expected to b
34.
▲
by
ddworken
6y ago
Not yet! But soon. :) See Project Fission [1]. Currently if you're using Beta or Nightly you can toggle it on and I believe it is getting very close to being ready to ship. [1]: https://wiki.mozilla.org/Project_Fission
35.
▲
by
ddworken
6y ago
While this POC may not reliably work on Safari, it is worth noting that from a defense perspective Safari is missing site-isolation (which Chrome, Edge, and soon Firefox all have). So if an attacker were to get this to work on Safari, the i
36.
▲
by
ddworken
6y ago
Yeah, Firefox doesn't have it yet but as I understand it, they're getting very close to shipping Project Fission.
37.
▲
by
ddworken
6y ago
It is worth noting that this POC was specifically targeted at Chromium based browsers. To quote the blog post, they also developed "a PoC which leaks data at 60B/s using timers with a precision of 1ms or worse". So Firefox&#x
38.
▲
by
ddworken
6y ago
This only allows reading data from the current process. Chrome and Edge have something called site-isolation where every site has its own process. In principle, this means that a site can only read its own resources. The catch here is that
39.
▲
by
ddworken
6y ago
The big caveat to this is that an attacker can generally get a browser to include a cross-site resource in their process. For example, `<img src=" https://sensitive.com/myprofilepic.png ">` will cause the imag
40.
▲
by
ddworken
6y ago
Chrome's design ensures that Spectre can only access resources that end up in an attacker controlled process. And this [1] post on "Post-Spectre Web Development" goes into detail about how a given website can ensure that its
41.
▲
by
ddworken
6y ago
As I understand it (though I don't work directly on Chrome), a key part of Chrome's threat model is that a compromised renderer process (where there is one renderer process per site) has limited security impact. So being safe agai
42.
▲
by
ddworken
6y ago
Yeah, I think it is a bit unfortunate that there doesn't seem to be any way of hiding this implementation detail from developers. In general though, Chrome is very thoughtfully designed so things mostly work as you'd hope. The cor
43.
▲
by
ddworken
6y ago
Chromium has site-isolation (with some caveats around phones with limited resources) so both Chrome and Edge have site-isolation. Firefox is getting very close with Project Fission [1] and I predict they'll ship it relatively soon. Cur
44.
▲
by
ddworken
6y ago
See this[1] paper for more information. I think from the browser POV it is more about admitting that it just isn't possible to reliably mitigate Spectre and instead focusing on what can be done at the browser level. And at the browser
45.
▲
by
ddworken
6y ago
Last year Chrome published a great paper on this[1]. The summary is that we no longer think it is possible to completely prevent speculative execution bugs. A big focus nowadays is on providing tools (mainly via HTTP headers) that allow a w
46.
▲
by
ddworken
7y ago
Vault's SSH certificate signing support is definitely really great and is something I modeled this project after while developing. Though I see it as more of a building block as opposed to a complete solution. With this project you: *
47.
▲
Keybase SSH CA
(keybase.io)
44 points
by
ddworken
7y ago
|
4 comments
48.
▲
by
ddworken
10y ago
Wow, very surprised to hear that. I definitely recommend taking Marten up on his offer and sending him an email (this behavior—of the CEO reaching out to hackers—is much more in line with my own experiences with them). Good luck with everyt
49.
▲
by
ddworken
10y ago
Wow, I'm definitely really surprised to hear that just because it is in such stark contrast to my own experience. If you don't mind me asking, how long ago was this? From my own experience, they're continually improving (they
50.
▲
by
ddworken
10y ago
Just wanted to chime in and say that working with them as a hacker is also a great experience. They put a ton of emphasis on the community with publicly disclosed reports ( https://hackerone.com/hacktivity/popular ), sta
51.
▲
by
ddworken
10y ago
Over on his website [0], Samy provides a link to the source: https://github.com/samyk/poisontap [0]: https://samy.pl/poisontap/
52.
▲
by
ddworken
10y ago
Yeah exactly. I certainly was in it for more than the money and would have happily worked on it even if there were no bounties.
53.
▲
by
ddworken
10y ago
While I do have a bit of experience with it, I still try to remain casual about it. Not by any means the only thing I do (Heading out hiking on the appalachian trail tomorrow!) so I try not to take it seriously. Thanks though! Also if anyon
54.
▲
by
ddworken
10y ago
Yup planning on going to college so not interested in any full time job offers (though I have received them...).
55.
▲
by
ddworken
10y ago
Well I did get to meet with the Secretary of Defense and get his personal challenge coin! And they did pay out bounties, I just wasn't the first to report the ones I sent in (despite sending most of them in on the first day).
56.
▲
by
ddworken
10y ago
It has now been fixed. The problem stemmed from allowing the `Javascript:` scheme for the home_page, download_url, and the url parameters in the setup.py.
57.
▲
by
ddworken
10y ago
Thanks for reposting that comment here (I posted it on /r/python). I'm now in contact with him and I'll update this once it has been fixed.
58.
▲
Show HN: Skipping the line to get Signal Desktop
(github.com)
4 points
by
ddworken
11y ago
|
0 comments
59.
▲
by
ddworken
11y ago
For anyone curious, you can easily host html, css, and javascript on KBFS without too much extra work. See dworken.keybase.pub/blog/index.html. (See https://dworken.keybase.pub/blog/posts/website-hosting-
60.
▲
by
ddworken
11y ago
They have started sending out invites to people who wanted to join their beta program. So now they are actually issuing certs.
More ›