so, I'm hearing about a browser exploit of the speculative execution bug (which needs a cool name btw); does that rely on getting code-exec first, or can it be done directly from JIT'd JS like with rowhammer?
Replying to @11rcombs
Hector Martin Retweeted Hector Martin
Speculative execution is a bitch. Hypothetical attack but I bet it can be made to work.https://twitter.com/marcan42/status/948584088696483840 …
Hector Martin added,
Hector Martin @marcan42
Replying to @marcan42 @_riatre
Keep in mind this is all speculative execution... so all bets are off. For example, what if JS issues a bounds check, but the CPU predicts it to pass and steamrolls right off into speculatively executing a massive out of bounds read into kernelspace?
9:20 AM - 3 Jan 2018
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.