I've been asked to give a 20 minutes presentation on Spectre and Meltdown this Tuesday (Jan 30): http://quintessenz.at/d/000100034598 Yes, I told them that I'm not really a processor security person. ¯\_(ツ)_/¯ Here are my slides: http://www.clifford.at/papers/2018/spectre/ … Constructive feedback is welcome.
Replying to @oe1cxw
Have you seen my take on this? The Spectre variants (which are really two completely separate issues) go quite a bit beyond biting JS/JITs. They can be used cross-process in principle. IMO we will never get rid of Variant 1 via CPU fix, but 2,3 are doable. https://github.com/marcan/speculation-bugs …
9:19 AM - 28 Jan 2018
0 replies
2 retweets
8 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.