That's the equivalent of saying "just don't run bad JS code". It's not workable. Have they given up?
That's the equivalent of saying "just don't run bad JS code". It's not workable. Have they given up?
Of course this could be fixed at the CPU level, but realistically very few people want that since that would drastically slow down modern CPUs which rely on speculative execution.
[1]: https://arxiv.org/pdf/1902.05178.pdf
Disclosure: I work at Google and am involved in deploying some of these cross-origin resource restrictions internally.
Which the (comparably) insecure likes of Firefox (unfortunately) does not have.
A little NoScript goes a long way. At least that way you can pick what you want to run.
Netspectre was able to dump kernel memory just from untrusted received network packets, no jit required.
HN should work without reading timers at all for example.