edit: Think of cars on a racetrack. Street worthiness considered ballast...ROAAARRRR!
https://nvd.nist.gov/vuln/detail/CVE-2017-5754
https://nvd.nist.gov/vuln/detail/CVE-2018-3639
> A ddg site search of "cve" returns zero hits.
What was your search query?
https://garudalinux.org/images/garuda/ss/garuda-boot-options...
I'm not sure whether this is misleading or not given the nature of illustrative screenshots, e.g. the package management one shows VLC installed but not Firefox:
There are only few things running untrusted code on a typical end-user system, most notably the browsers executing javascript. Now that would be attack-able. But then again, it seems unlikely that anybody would launch broadly deployed attacks, as the vast majority of systems would run with mitigations on, so it's just not worth the trouble considering that and considering that you also have to get lucky to actually extract something valuable (and recognize it is valuable). On top of that, browsers also bring a bunch of mitigations that make it harder to exploit these bugs even if system mitigations are disabled.
I'm personally not very concerned about anybody trying to attack me with spectre/meltdown class bugs that can be and are usually mitigated, even with mitigations disabled on my system. If somebody wanted to attack me, either at random (broad attack), or targeting me specifically, they'd have far better ways and targets to try first than hoping I'd visit their website and run without mitigations enabled and have something valuable in my memory.
This is different if it's a shared system, like cloud machines/shared hosting, where this is an class of bugs is far more of a concern. And if you know or have reason to suspect you're a specific target, then you might err on the side of caution as well.
These attacks are being done algorithmically, automatically now.
Seriously, I haven't seen any news of these attacks being used against end-user systems, either broadly or targeted. Have some links?
Context:
I am hearing about Garuda Linux in Manjaro forum where I presume "the developer" talked about it in the "Other OS" discussion section. With the deteriorating community relations Manjaro has been having with their community and with some of the Manjaro folks like old time users/volunteers moving to Garuda because of it, Garuda Linux has a place and an opportunity at hand to outshine Manjaro. If they keep their community relationships in check I guess.
I hope they get through it. Manjaro is my goto for my Pinebook Pro.
It may be that a hacked up kernel is what is needed right now to make it work well. I get 6x the battery life than I did before (seriously), and updates don't totally break my system. Two pretty nice features :-D
Because of this there is essentially two parts to Manjaro. Manjaro the Community and Manjaro the Company. Manjaro the Company has funds from HW deals with Pine, laptop vendors and merch.
Manjaro the Community has community donations through opencollective. These funds are parts of the community funds Phil (founder of Manjaro the Company, and project leader) had collected privately and forwarded to this collective. These funds are used to pay for laptops and merch associated with business expenses to forward the interest of Manjaro the Company.
You can see how this creates some tensions when the boundary between the Community and the Company is blurry at best.
https://opencollective.com/manjaro/
https://archived.forum.manjaro.org/t/change-of-treasurer-for...
OpenCollective and CommunityBridge/LFX were set up after the surprise company announcement to collect community donations from that point (and intended to protect them as independent). The previous privately-collected donations were never forwarded.
I don't mean to dismiss the tension or that jonathon has made an unfair stand, but I am not sure I understand how the schism is warranted. Any software that combines outside funding with donations has a risk of this right? Unless I'm missing something it may just be a personal falling out.
The problem is the intransparency in the way things where handled as well. This is the most recent event. There are more quarrels with FreeOffice Manjaro originally planned to pre-install for some reason, but later backpedaled after pushback.