[DISCUSSION] Meltdown and Spectre

Discussion in 'PC Hardware' started by scaramonga, Jan 3, 2018.

  1. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    @Daz

    It looks like I discovered new protection. Does not work any single Spectre exploit that I found on a memory zone that is inaccessible to anyone.
    So if you want to hide something from the attackers just
    Code:
    mprotect(addr,PROT_NONE)
    and Spectre is out...
    If necessary,
    Code:
    mprotect(addr,PROT_READ/WRITE) 
    then do it again and again NONE ;)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. VDev

    VDev MDL Member

    Sep 9, 2015
    121
    64
    10
    Does that API hook to all processes running on a machine or just specific apps which must be re-compiled to protect against the exploits.
     
  3. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    #203 Mikorist, Jan 14, 2018
    Last edited: Jan 14, 2018
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    #204 Mikorist, Jan 14, 2018
    Last edited: Jan 14, 2018
    So, you can theoretically make root exploit with spectre if you know how to use mmap precisely inside them. o_O
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. s1ave77

    s1ave77 Has left at his own request

    Aug 15, 2012
    16,093
    24,397
    340
    Interesting. Powershell is part of the system :g:.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. Hadron-Curious

    Hadron-Curious MDL Guru

    Jul 4, 2014
    3,725
    600
    120
    Seriously, I am not going to apply any of the patches to my 3rd generation Intel processor system yet - perhaps I would apply them to other generation processors. If these vulnerabilities had been there for decades without reports of been exploited there's nothing much for me to worry about at the moment.

    Having said that, rumour has it the big online advertising companies probably exploited them without people being aware of them.
     
  8. Daz

    Daz MDL Developer / Admin

    Jul 31, 2009
    9,530
    67,271
    300
    Like I said, "You'll only be impacted if you don't apply application updates and launch an infected executable".

    The application updates prevent Spectre from having an effect. So it isn't much different than your typical trojan, which can already record your keystrokes, steal your passwords and enable remote access.

    With the update applied you shouldn't notice much of a difference. Maybe you'd get slightly slower read and write speeds, but games and everything else are within the margin of error.

    You can skip any BIOS update for now, but you should at least protect yourself from Meltdown.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    It's complicated for someone using a hackintosh.

    I need to manually edit BIOS - or EFI / Clover.

    I posted that on tonymacx86. I suppose RahabMan knows how to solve this.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    #211 Mikorist, Jan 14, 2018
    Last edited: Jan 14, 2018
    I need to go to Wine Emulator support. They must patch him too. Because Spectre works through Wine on a bare metal Linux computer with patches.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  11. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  12. nodnar

    nodnar MDL Expert

    Oct 15, 2011
    1,331
    1,064
    60
    we can ask ourselves that, i suppose.
    lets look at the facts first, before asking `what next?`
    as tiger rightly pointed out, the only safe device
    is probably the abacus.[ i briefly asked myself; `back to the
    80286?`as safe as the abacus,but a bit too slow..]
    the fact is, that we [`they`] took the wrong turning 20 years
    ago. and the result is that we now have zillions of processors
    lying around with a fundamental design flaw. and fundamental
    design flaws can never be corrected. it is damning an industry
    that lacked the creativity to have the flaw staring in their
    faces for two decades without it dawned on them. so now what do
    we have? we have got a civilisation running on useless machines,
    and a generation of coders who know nothing else.
    so if we `sound the deathknell of the x86 standard` now,
    my supermarket will have empty shelves where there should be my hamburger.
    temporarily like venezuela. no fun.
    so we have got no choice really to learn to live with those s**tty
    x86 machines, and adapt.just my 2 bolivars.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  13. Michaela Joy

    Michaela Joy MDL Crazy Lady

    Jul 26, 2012
    4,068
    4,649
    150
    I find it disgusting when I wear a dress, walk up a flight of stairs and some boys at the bottom of the stairs try to look up my dress.
    That's what this society has become: A society of malicious voyeurs. Always looking for a way to "look up each others" dresses.

    When branch prediction was invented some 25 or 30 years ago, it was heralded as a way to push the envelope on Moores' law.
    All of a sudden, high powered apps and power hungry games were able to perform at levels that were previously deemed impossible.

    And now we're being "scared" into throwing it away? The sky is falling???

    So tell me: What would you replace x86 with? A proprietary Harvard architecture? RISC? Vector processors?
    That RISC thing really worked out well for Play Station and X-box.

    Don't allow yourselves to be fooled by the hype. Just patch your systems and be thankful that you have the equivalent of a supercomputer on your desktop.

    And watch out for boys with shiny buckles on their shoes. :D
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    #215 Mikorist, Jan 15, 2018
    Last edited: Jan 15, 2018
    We can just throw those our phones and laptops into the trash.

    In the last 10 years, they could read everything on ANY operating system on ANY machine. (This truth does not like anyone.)

    Now they do not have to read anything about us. When they all know.

    I do not trust anyone anymore that we are safe and can relax.

    I can only lie myself I'm safe.

    I can relax when I die.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  15. Michaela Joy

    Michaela Joy MDL Crazy Lady

    Jul 26, 2012
    4,068
    4,649
    150
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    I believe you:D
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  17. s1ave77

    s1ave77 Has left at his own request

    Aug 15, 2012
    16,093
    24,397
    340
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  18. Mikorist

    Mikorist MDL Member

    Dec 26, 2012
    205
    145
    10
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  19. s1ave77

    s1ave77 Has left at his own request

    Aug 15, 2012
    16,093
    24,397
    340
    Oh boy, so much clickbait all over the net. Must be a feast for certain media :cool2:.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...