Meltdown-Spectre: Malware is already being tested by attackers
zdnet.com
zdnet.com
A popup that says "Intel has detected your computer is vulnerable to Meltdown. Click here to install the fix."
When will this horrible Meltdown end???
If I understand correctly, it is possible to perform these exploits with JavaScript. What about without?
Let's say I set javascript.enabled=false, is it possible to do break out of the browser's sandbox with just HTML5 + CSS? I have read that today it is "Turing-complete"...
The original proof of concept didn't even use a "precise timing API", it features `while(true){ i++; }` to increment a counter, and pulled timing information out of that side-channel.
It is trivial for the browser vendors to disable access to a specific API, but we're in for a game of whack-a-mole.
Dismiss the exploitability of javascript at your own peril - sure, WebWorkers and SharedArrayBuffer are this week's blocked timing attack, but smart money says there are other ways to get timing information that are unpatched.
With just CSS this should be impossible/ very unlikely. I guess it is probably technically possible, but I do not expect to see exploits using just CSS.
With HTML5 idk, that's really outside of my area.
Of what advantage is it for attackers to publish that they are using a particular exploit? Especially due to the nature of these exploits, they would more than likely be silent attacks.
Here's the meltdown repo from the paper if your interested: https://github.com/IAIK/meltdown
Part of me thinks you could read that sentence this week, next week, a month or 6 months from now and it will still hold true...
So: don't panic, but do take precautions as soon as possible.
Possibly because the issues are mostly mitigated in the wild and there are other, easier to exploit, holes out there too (particularly the water-bag problem: human engineering can be a great attack vector). So they are picking the lower hanging fruit instead. As soon as there is a PoC that seems to have a decent ROI for the implementation time, exploits will appear in the wild.
If somebody could already run that code, they'd choose anther attack method.
The real nightmare targets are cloud providers. Many smaller providers have not patched yet.
Perhaps this is a good moment for the IT-world to start eradicating the use of passwords.
EDIT: Of course this will not solve every problem related to these vulnerabilities, but it might go a long way, especially if possible exploits are taken into account when designing new systems.
So they're "only" a problem to the extent that there is information you do not want the attacker to read. Passwords are the first obvious target here.
Of course the same attack could expose other credentials, so it's not a password-specific issue.
Also, it doesn't matter. Passwords, secret hashes, ssh keys; anything can be accidentally acquired.
It's a fair point, but in general security has no silver bullets. Build a better lock, and attackers will build a better lockpick (or go through a window instead).
Lack of universal U2F support (a broader login security spec that Yubikeys supports) is Yubikey's weakness, but it only helps the attackers to be a security nihilist.
More and more sites are starting to support U2F. The biggest being Google (which covers Gmail, Google Cloud, Google Docs, etc), but also Github, Facebook, and Dropbox also support it, among others.
The trade-off between usability and security applies here - prior to meltdown/spectre, authentication cookies were happily isolated, so logging in once every 30-days seemed reasonable. Now, cycling login cookies every day or so is a more aggressive policy that is arguably better, but unfortunately, automatically logging users out after a short period hurts site adoption.
Remember: MFA is a two-or-more combination of: something you know (password, pin, etc.), something you have (keycard, token, fob, etc.), something you are (fingerprint, iris scan, voice recognition, etc.), and potentially even somewhere you are (geolocation).
Though if your attacker has root they can change what is on the screen anyway.