After all, there are code samples available today which demonstrate the SPECTRE and MELTDOWN attacks.
After all, there are code samples available today which demonstrate the SPECTRE and MELTDOWN attacks.
You don't need code to prove that a vulnerability exists, it is sufficient, especially for crypto primitives like hash functions or cipher rounds, that there is a mathematical vulnerability that can be potentially exploited.
“Hey, your house door is unlocked.”
“What are you talking about? I left it unlocked on purpose, but it is safe, I wired the metal handle to the power plug, nobody bad can get in.”
“What about the good ones?”
“I installed a Coordinator™ that calls me when you ring, and I can open the door remotely.”
“Wait, didn’t you make this house with the promise that everyone with the key could use it?”
“… well, I don’t see you finding a vulnerability!”
¹ though there are several actual code vulns that have been dismissed by the IOTA team as "FUD" and even threatening researchers with litigation https://prizz.github.io/iota-transaction-spammer-webapp/