Worth reading re: all the flaws discussion. Just because they require admin privs doesnt make them not dangerous. Sure they're overhyped as hell, and the release "strategy" was bizarre, but the flaws are real and abusable. Good, well-measured thread.https://twitter.com/dguido/status/973628511515750400 …
-
-
In other words, this only affects gullible enterprise IT people who bought into all that stuff. Consumers don't care, they're screwed if they get pwned anyway. Competent large cloud providers are already using custom designs with their own security model.
-
Really, I welcome these vulns as a way for end-users to take control over *their* hardware. We know AMD can't secure their way out of a paper bag, but what if *I* want to run my own secure code on the PSP?
- Show replies
New conversation -
-
-
I’m going to just hide in the closet and go use an abacaus
-
Even mechanical calculators aren't safe from evil miscreants trying to crash them. https://www.youtube.com/watch?v=7Kd3R_RlXgc …
- Show replies
New conversation -
-
-
I mean, as with all things, it's a question of threat model. Does your average skiddie have a use for this? Of course not. Do state actors who might want to drop a totally invisible root kit on a major hosting provider? Yeah absolutely.
-
Sure there are more efficient ways to do this, but the fewer the better, at least imo.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.