children of spectre

der.hans PLUGd at LuftHans.com
Thu May 3 11:38:36 MST 2018


Am 03. May, 2018 schwätzte Herminio Hernandez, Jr. so:

moin moin,

> Just when you thought it could not get any worst... so when will we be
> moving to RISC??

We're already on risky :).

I expect we will continue having new vulns discovered for at least the
next couple years.

ciao,

der.hans

> On Thu, May 3, 2018 at 9:12 AM, Stephen Partington <cryptworks at gmail.com>
> wrote:
>
>> struth....
>>
>>
>> On Thu, May 3, 2018 at 9:11 AM, der.hans <PLUGd at lufthans.com> wrote:
>>
>>> moin moin,
>>>
>>> 8 new intel flaws set for announcement.
>>>
>>> https://www.heise.de/ct/artikel/Exclusive-Spectre-NG-Multipl
>>> e-new-Intel-CPU-flaws-revealed-several-serious-4040648.html
>>>
>>> At least one of the kids appears to be much worse than spectre.
>>>
>>> "an attacker could launch exploit code in a virtual machine (VM) and
>>> attack the host system from there – the server of a cloud hoster, for
>>> example. Alternatively, it could attack the VMs of other customers running
>>> on the same server."
>>>
>>> "Intel's Software Guard Extensions (SGX), which are designed to protect
>>> sensitive data on cloud servers, are also not Spectre-safe."
>>>
>>> ciao,
>>>
>>> der.hans
>>> --
>>> #  https://www.LuftHans.com   https://www.PhxLinux.org
>>> #  "But you could teach these skills to a high-school student, and you
>>> could
>>> #  probably teach them to an artist."  -- Richard Roberts
>>> ---------------------------------------------------
>>> PLUG-discuss mailing list - PLUG-discuss at lists.phxlinux.org
>>> To subscribe, unsubscribe, or to change your mail settings:
>>> http://lists.phxlinux.org/mailman/listinfo/plug-discuss
>>>
>>
>>
>>
>> --
>> A mouse trap, placed on top of your alarm clock, will prevent you from
>> rolling over and going back to sleep after you hit the snooze button.
>>
>> Stephen
>>
>>
>> ---------------------------------------------------
>> PLUG-discuss mailing list - PLUG-discuss at lists.phxlinux.org
>> To subscribe, unsubscribe, or to change your mail settings:
>> http://lists.phxlinux.org/mailman/listinfo/plug-discuss
>>
>

-- 
#  https://www.LuftHans.com   https://www.PhxLinux.org
#  "I decry the current tendency to seek patents on algorithms.  There are
#  better ways to earn a living than to prevent other people from making use
#  of one's contributions to computer science."  -- Donald E. Knuth


More information about the PLUG-discuss mailing list