Researchers Discover Seven New Meltdown and Spectre Attacks (zdnet.com)
A team of nine academics has revealed today seven new CPU attacks. The seven impact AMD, ARM, and Intel CPUs to various degrees. From a report: Two of the seven new attacks are variations of the Meltdown attack, while the other five are variations on the original Spectre attack -- two well-known attacks that have been revealed at the start of the year and found to impact CPUs models going back to 1995. Researchers say they've discovered the seven new CPU attacks while performing "a sound and extensible systematization of transient execution attacks" -- a catch-all term the research team used to describe attacks on the various internal mechanisms that a CPU uses to process data, such as the speculative execution process, the CPU's internal caches, and other internal execution stages. The research team says they've successfully demonstrated all seven attacks with proof-of-concept code. Experiments to confirm six other Meltdown-attacks did not succeed, according to a graph published by researchers. Update: In a statement to Slashdot, an Intel spokesperson said, "the vulnerabilities documented in this paper can be fully addressed by applying existing mitigation techniques for Spectre and Meltdown, including those previously documented here, and elsewhere by other chipmakers. Protecting customers continues to be a critical priority for us and we are thankful to the teams at Graz University of Technology, imec-DistriNet, KU Leuven, & the College of William and Mary for their ongoing research."
the year of the k6 processor.
I hereby claim copywrite and trademark privileges to the above work. All rights reserved. Please enquirer directly for permissions or use licensing.
"a sound and extensible systematization of transient execution attacks"
09 F9 11 02 9D 74 E3 5B - D8 41 56 C5 63 56 88 C0 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
How long until they prohibit execution on vulnerable CPUs?
That probably is a little overboard, but I think a 9-figure fine might inspire them to pay a little more attention to security next time.
Why? Scared of formal methods?
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
These aren't "bugs." Bugs are not intentional.
These are design flaws... weaknesses brought about by deliberate abandonment of sound engineering practice. These processors are defective by design, and I would imagine the right subpoenas would reveal that these multi-billion dollar companies knew or should have known that their product was defective by design, and withheld that information from the public.
That is why I am joining the class action lawsuit against all three chipmakers. I figure they owe me approximately 49 billion dollars in real and imagined damages.
Researchers discover that computers are only 100% secure while powered down and still in the box.
Further investigation is need to determine how this affects productivity.
It must have been something you assimilated. . . .
will be lost in vulnerability workarounds :-/
...This wasn't the best way to improve performance. There are other approaches, or modifications to existing ones.
Does anyone know if Itanium 3 was affected? If not, Intel might want to revisit it, as there's bound to be commercial interest in fast, secure processors. (Because it was a ground-up redesign, it would have been free of defects from mainstream processors.)
I'm guessing the UltraSPARC/T3 is safe, for similar reasons. Totally different internal architecture.
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
When does all this hype turn into something besides fear mongering and security asshole "told-ya-so-ism" ?
Important tidbit not mentioned in the summary: "In addition, the research team also discovered that some vendor mitigations that have been already deployed have also failed to stop the seven new attacks, even if they should have, at least in theory."
https://zdnet1.cbsistatic.com/hub/i/2018/11/14/15e46793-eebf-46b5-8fbd-23896b34a1ae/9641c5228c53fbde1d8778dd94ae5832/new-meltdown-attacks.png
Not that quantity of vulnerabilities is everything but Intel and Arm are in serious relative trouble... again. How many of their performance and power advantages over the last several years have been substantially due to the of taking secure design shortcuts? AMD may be even further than the lead than we've realized.
Oh no, not again.
How do you like your clouds now? Do you even know all APTs that now have your keys?
.. but mostly imagined.
Speed....Security...Cheap...Pick only two, can't have it all!!!
hanged.
A painting is hung. CEO's and other criminal miscreants are hanged.
Slashdot, where pedantry will always be alive and well!
Or Buy Intel and Buy T.R.O.U.B.L.E. today, tomorrow, until you Buy AMD.
So Intel where's my money???
I want to hang him like a painting. What the fuck are you talking about, you fucking monster?
You clearly have looked too deeply into the abyss.
wow you need to relax and act age appropriate. the only reason you get trolled is because you overreact to the most minuscule things. you need to chill, maybe smoke a jibber and relax. i can't understand why anyone would want to use your program when you act like a distraught 13 year old girl arguing on facebook about how she said this, and he said that. i think your body aged, but your brain is stuck in a 7th grade level. act more your age, and ignore the trolls.
if your program is good, it should stand on its own merit. you do not need to push it on people in these forums. and why do you reply to yourself all the time?
ignore the trolls, but you act like one yourself so i doubt you have it in you to not troll back. i seriously used to ask why everyone messes with you here, but it took a few days for me to realize why is because you make it SO EASY. think about it. grow up, and maybe you'll get treated more like an adult, but act like a child and you will be treated like one.
For a second I was really curious what SPECTRE was up to and what James Bond was going to do about it.
And fixing them will introduce more attack vectors. What a man can make, a man can break. That is why I don't think quantum communication and encryption is actually unbreakable.
E Proelio Veritas.
I'm even improving my already GREAT PHYSIQUE by getting calf implants
By getting anal rejuvenation surgery. FTFY. I told you before, keep it slow my dude..
so everyone who says anything to you is zip? there is no help for you. i hope you push this to the max, so during discovery everyone can see how literally retarded you are. btw, my name is not zip. trace my ip if you're so good at programming. sped.
They just had to get that in, didn't they?
See how STUPID "ZIP" (Zach Patterson) the CHIMP is (tried to take credit for what I solved before him) https://tech.slashdot.org/comm... (he needs to LEARN TO READ)!
I even SHOW ways to do it YOURSELF https://tech.slashdot.org/comm... (he couldn't).
Delphi/FreePascal/ObjectPascal HAS no issue w/ null-term'd string bufferoverflows - C does, C++ can UNLESS you do what I said 1st loser.
Tell us about CODE SIGNING (which has been STOLEN & ABUSED) https://www.helpnetsecurity.co... MY METHOD CAN'T BE (upmodded +2 INTERESTING in CODING FOR DEFCON no less) https://it.slashdot.org/commen...
"I'm a much better programmer than APK" - by Anonymous Coward ZIP on Monday October 08, 2018 @11:27PM (#57449082) FROM https://yro.slashdot.org/comme...
BIG TALK - Yet ZIP has nothing to show in programs. I can https://news.slashdot.org/comm... from registered /.ers liking/using/praising my work (& 100k users worldwide too). He can't.
LIAR ZIP says he has no account "I don't have an account, so I don't have mod points" https://news.slashdot.org/comm...
Yet LIAR ZIP says he downmods my posts (IMPOSSIBLE MINUS AN ACCOUNT on /.): "I down-modded a few of your post on other threads" - by Anonymous Coward "ZIP" on Thursday October 11, 2018 @11:31AM (#57461058) FROM https://yro.slashdot.org/comme...
APK
P.S.=> KEEP IMPERSONATING ME CHIMP - this comes out every time, lol!... apk
You said it ZIP: Where's your work everyone can see/use? It's not. It's HOTAIRWARE/NOTWARE (lol) "I'm a much better programmer than APK" - by Anonymous Coward ZIP on Monday October 08, 2018 @11:27PM (#57449082) FROM https://yro.slashdot.org/comme...
The BETTER PROGRAMMER w/ no programs, lol - @ least you can say your "code" has NO BUGS - of course, it also does ZERO (like you) since it does nothing @ all, lol!
You hotair BLOWHARD talker, lol!
You f'd up ZIP https://tech.slashdot.org/comm...
Yet 100,000++ users of my ware & dozens of even REGISTERED /.ers like/use/praise MY work https://news.slashdot.org/comm... vs. your HOTAIR talk punk!
* LMAO!
(Let's see how YOU take it when I publicly SHIT ALL OVER YOU by letting FACTS of YOUR FUCKUPS vs. ME https://science.slashdot.org/c... do the job for me)
APK
P.S.=> You STUPID & LAZY all talk chimpanzee - KEEP IMPERSONATING me - I'll expose your BLOWHARD INCOMPETENCE publicly, lol... apk