Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Monday November 19 2018, @09:14AM   Printer-friendly
from the another-day-another-breach dept.

Back at the start of the year, a set of attacks that leveraged the speculative execution capabilities of modern high-performance processors was revealed. The attacks were named Meltdown and Spectre. Since then, numerous variants of these attacks have been devised. In tandem, a range of mitigation techniques has been created to enable at-risk software, operating systems, and hypervisor platforms to protect against these attacks.

A research team—including many of the original researchers behind Meltdown, Spectre, and the related Foreshadow and BranchScope attacks—has published a new paper disclosing yet more attacks in the Spectre and Meltdown families. The result? Seven new possible attacks. Some are mitigated by known mitigation techniques, but others are not. That means further work is required to safeguard vulnerable systems.

The previous investigations into these attacks have been a little ad hoc in nature: examining particular features of interest to provide, for example, a Spectre attack that can be performed remotely over a network or Meltdown-esque attack to break into SGX enclaves. The new research is more systematic, looking at the underlying mechanisms behind both Meltdown and Spectre and running through all the different ways the speculative execution can be misdirected.

https://arstechnica.com/gadgets/2018/11/spectre-meltdown-researchers-unveil-7-more-speculative-execution-attacks/?comments=1


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by The Archon V2.0 on Monday November 19 2018, @06:55PM

    by The Archon V2.0 (3887) on Monday November 19 2018, @06:55PM (#763965)

    > The result? Seven new possible attacks.

    Who cares? What are their NAMES? That's what's important! If it's not something ominous, it's nothing to worry about! I propose:
    Revenant
    Apocalypse
    Harbinger
    Pandemic
    Apocalypse 2: Electronic Boogaloo
    FindsYourPornStash
    and OMGSomeoneClonedHitler.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2