But I must caution desktop users against doing this for performance, it's _much_ better to have some kind of build server somewhere else with this kernel flag than to run it on your desktop.
Why? because your desktop executes untrusted and rather arbitrary code pretty often, not just in the form of Javascript but that's the largest example I can think of.
Right now there's a kind of herd immunity for these things, nobody would really attack spectre because everyone is running mitigations, but if you make the target large enough there will be working exploits.
For isolated machines running trusted workloads (thinking: databases or webservers serving static content) then it's a really nice flag to have on-hand.
Or a Powershell script from MS: https://support.microsoft.com/en-us/topic/understanding-get-...
Also, do all the major browsers now have their own mitigations built in?
FeatureSettingsOverride is a bit field where bit 0 controls the mitigation for CVE-2017-5715 (Spectre) and bit 1 controls it for CVE-2017-5754 (Meltdown). If the bit value is 0 the corresponding mitigation is enabled, if 1 it's disabled. FeatureSettingsOverrideMask is simply a mask to control which bits of FeatureSettingsOverride to apply. So, for example, FeatureSettingsOverride = 2 and FeatureSettingsOverrideMask = 3 would enable the Spectre mitigation (if available) and disable the Meltdown one.
More info here:
https://support.microsoft.com/en-us/topic/windows-server-gui...
https://gist.github.com/daBONDi/6f86210e54c68e84e85372fc4d1f...
Haven't checked if the program emits different behavior for other CPU's or OS versions.
https://www.reddit.com/r/intel/comments/kp6b6i/how_bad_is_it...
1) we can’t trust people to categorise their own apps because the incentive for performance over security is a trade off we’ve all made time and time again.
2) efforts to address mandatory access controls have a coloured history here: selinux and apparmor both have very low adoption rates no matter your personal anecdotes.
3) These mitigation’s are so thorough that it would be more expensive on performance to even _check_ per application than it would be just to enable it everywhere.
Considering that you have:
A) some list of allowed applications/programs
B) a run of this check on every syscall
C) to be faster than a TLB flush
The impact of TLB flushing, not just the cost of the flush, is really significant - it's going to take a lot of work to be as expensive within the syscall path.
Edit: For that to work that flag would have to work on the context switch level. So every time you switch away from a sensitive process, flush all buffers and whatever else, then switch. This also requires the kernel itself to enable mitigations as necessary when it touches encryption keys before switching back to user space.
Closing a Zoom/Webex meeting, who knows since it’s still running in the background.
I also like meetings sandboxed in a browser so weird things like “automatically take control of your screen and maximize window” doesn’t happen when someone in a Zoom meeting starts sharing their screen.
Even at the expense of more CPU.
How would you know? Or, put another way: Why don’t you want to trust Google Meet, but apparently want to trust Google Chrome?
It's not about spying from the software authors (having these softwares on your computer makes that impossible to defend against), but about knowing whether the people you were just talking to still have access to your camera and microphone feeds.
Again, how would you know that? There is no reasonable way you could possibly know that.
While Skype is an unmitigated disaster that can’t do simple stuff like copying text there is Citrix that requires a wizard installer with admin rights that deploys 3 background services and requires an audio plugin (separated, with another wizard installer) to do a worse remote streaming experience than what discord does for teenagers using a browser.
> While Skype is an unmitigated disaster that can’t do simple stuff like copying text
Do you mean from shared contents or from the chat? The latter works for me, but since you also mention using Citrix Workspace, which sounds like a remote desktop/application tool, it seems likely to me that this is actually the fault of Citrix, not Skype. Remote clipboards seem to be rather unreliable, I'm using DCV 2017 and the clipboard breaks basically every five minutes, necessitating a reconnect.
I’m not sure if it’s the clipboard because my employer does not allow shared drives, clipboard, usb or any resource from my local machine except for mic and webcam.
Ohhh and let’s talk abou the HUGE black ribbon at the top of the screen when you are sharing your window. It totally covers the browser tabs. You have to restore the window and switch tabs and maximize it again. It _is_ an unmitigated disaster that degrades the overall experience.
It's not Citrix doing this, but your administrator.
Seriously: try installing Firefox on Windows 10 (I had to do this recently, I have now one computer in the house on Win 10 due to a hard requirement for some software/hardware combo), and you'll see Microsoft learned next to nothing from the browser wars lawsuit. They're simply asking to have this done to them again, they now actively discourage Firefox to be installed by claiming it can 'damage your computer' and is insecure. Incredible this stuff.
Oh, and Google will return a link for Chrome as the first item when you search for Adblock for Firefox. You can't make this stuff up.
Has there ever been a large company in IT that didn't turn absolutely evil as soon as the opportunity presented itself?
What is personally more annoying is Edge keeps randomly popping up a banner asking if I'm sure it shouldn't be the default browser. When a user declines once, the OS shouldn't nag repeatedly.
Haha, ... when you apply that standard to the modern world - you sometimed wish the stoneage back.
Seriously, there is something deeply wrong with society, when all this shit just gets accepted by everyone.
"Telemetry" such a innocent word. If they would write we record allmost everything you do on your computer and send that data to wherever we want to .. I doubt much would actually change, as MS office software is still mandatory in many places, but maybe there would be more awareness of it.
No?
Maybe your profile affects results, here:
"Adblock for Firefox"
returns
"https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/"
"adblock"
returns 1st url = https://adblockplus.org
2nd url is = chrome.google.com
Bill Gates
> What the [user] is supposed to do is feel uncomfortable, and when he has bugs, suspect that the problem is DR-DOS and then go out to buy MS-DOS.
MS SVP Brad silverberg
> If you're going to kill someone there isn't much reason to get all worked up about it and angry. Any discussions beforehand are a waste of time. We need to smile at Novell while we pull the trigger.
MS VP Jim alchin
What has changed? Nothing, of course. Settling and paying fines for blatant abuses of dominant market positions has been Microsoft’s MO for decades.
Maybe a Win10 Home, or some other version? Or was that in a search result (or ad) not actually Windows?
Edit: On re-reading, I believe OP was specifically referring to false positives with SmartScreen that crop up regularly, like at https://www.reddit.com/r/firefox/comments/n7gige/ms_edge_blo...
The idea that it applies to trusted vendors like Mozilla shipping code-signed executables is bonkers to me.
Nice way to promote further centralization into services like app stores that don't suffer from this!
Yeah, I actually think this is a case of "don't explain by malice that which could be adequately explained by stupidity" or something.
I'm only a casual Windows user (only use for it games) and never bother to install another browser, Edge works well enough to download Steam and occasionally look up something on the internet.
Earlier this week when it installed the new update I also got the same "use recommended browser settings" dialog box. I think I had disabled 3rd party cookies or something as well as the random junk on the new page, so not willing to click around for half an hour I denied using anything and all went well. I'm pretty sure this isn't the first time I see the "use recommended settings" on this PC, since seeing it gave me an "again?!" reaction.
This is a Win10 Pro that's always been kept up to date.
I like nuances, though. "absolute evil" is a bit strong.
There were companies who were engaged with enslaving people and working them to death. (some still are)
I am no fan of googles development, but absolute evil leaves no room to describe other companies who are actually worse.
well that's an understatement[0].
I alos think it's less productive to interpret the phrase absolute evil as a comment on an entity's moral alignments (because it's a corporation, it's not chaotic evil or neutral good, it just is) but as a comment on the foundation and effects of the economic and political systems defining of the corporations (capitalism under neoliberalism). Absolute evil seems like a fairly decent personification of those metrics to me: every extra push to manufacture another product pushes us closer to a climate catastrophe (even 'green' products like Teslas, especially green products like Teslas[1]). Even if you deny climate change, you can't deny that workers are being taken advantage of near habitually. If we're going to personify the destruction of the earth and the worker, absolute evil does not seem too far off.
0: https://en.wikipedia.org/wiki/Foxconn_suicides for one 1: https://www.wired.com/2016/03/teslas-electric-cars-might-not...
Exploiting people because they are desperate is a big problem. Maybe call it modern day slavery. But it really is not the same as what slavery means for people who are literaly and 100% owned by others.
That's been true since the very beginning.
I very nearly filed papers to oppose class council in one of the state lawsuits on the basis that the proposed settlement was calculated to create a new antitrust injury to the class.
But I didn't because I was young and pro se and there was no way for me to afford or find representation. If I had to do it again I would've filed pro se requesting that they reject the settlement on that basis and appoint a guardian ad litem to roll the dice anyway.
If turning evil increases shareholder value, it’s their fiduciary duty to do so.
Meh. Maybe not: https://medium.com/bull-market/there-is-no-effective-fiducia...
As far as I understand browsers still get owned at every pwn2own. So you might want to stop running untrusted JavaScript anyway.
If you want to be overly reductionist then you can argue nothing matters because your just staring at a box with lights in it.
I tend to agree with what you're saying but the ship has sailed very much and running without javascript is a losing proposition these days.
(my web browser starts up with javascript disabled except for some whitelisted sites and it usually only takes 15 minutes for me to find something completely broken on the internet and re-enable javascript entirely).
So for example, you can whitelist urls to all the major JavaScript frontend frameworks’ CDNs, like bootstrap, etc. while leaving known trackers and spyware blacklisted by default.
Anecdotally it seems most websites still work with their trackers disabled, as long as they have their frontend framework/s loaded.
Which is why I just use basic ublock origin and regulary wipe the browser cache.
What's the difference between that and just using the standard easylist/easyprivacy filter? I suppose there's a small chance that a third party site went rogue and isn't on the default lists, but I'm skeptical how many attacks that would thrawt in reality. The attacks I heard of tend to be first party/supply chain (would be white listed by you), or delivered through an ad network (probably already be on a blacklist).
It's not that hard, nor time consuming. Again, my wife can do it and she's not a developer.
Still though. There are sites that would not work at all until everything is enabled, including ads. Imagine not being able to buy a plane ticket because wizzair wants to serve you ads
>you'll eventually get into the habit of blindly enabling scripts when a site breaks, negating any security benefits.
The key here is that when you're deciding whether to whitelist a JS import, and you don't know what it is and don't want to take the time to look it up, then whitelist it temporarily not permanently. It will be moved back to the blacklist the next time you restart the browser.
Only permanently whitelist JS that you know for sure isn't a tracker or malware or sketchy.
What’s the whitelist based on? URI? Or file content hash? Because today’s “criticalsitefunctunality.js” is tomorrow’s “upstream got p0wned and there’s a Bitcoin miner in there too now”.
Sites churn so often that “permanently” whitelisting hashes is probably a never ending chore, and you’re unlikely to want to constantly re-inspect minimized JS, so this eventually turns into semi-blind faith.
And permanently whitelisting URIs is pure security theatre; that file could contain anything, next request.
If you have a better approach that accomplishes both of those objectives, do tell.
Use a browser that isolates the JS engine in its own process and leave spectre mitigations enabled rather than try to play kid-plugging-holes-in-dike-with-finger by auditing all the world’s constantly-changing JS for spectre/meltdown gadgets?
Definitely. All for that.
>and leave spectre mitigations enabled
I do that anyway. The performance cost is unnoticeable to my normal workloads.
>rather than try to play kid-plugging-holes-in-dike-with-finger by auditing all the world’s constantly-changing JS for spectre/meltdown gadgets?
I'll continue doing this too, largely because I want to see what's going on behind the scenes on all the websites I visit. Useful for me to see it all, especially as it changes over time as you observe.
That said, Easylist and Privacylist are also great if you'd rather crowd-source the finger-in-dike-hole-plugging.
Yeah I went through this too, figuring out all the CC purchase redirects. Some are just idiotic to the point I wish govts would pass a law mandating zero redirects for online purchases. Stripe, Paypal, Square, Braintree and a few others do payments just fine without the redirects so it's clearly possible.
But eventually even that gets solved and the redirects get whitelisted. Haven't encountered this problem for a long time.
That said, when there's something old, important, and/or dumb looking, I usually spawn a new Firefox container (using Multi-Account Container plugin) and use NoScript's temporary bypass function.
Security is only part of my motivation, though, and not the main part -- I mostly do it because it protects me by default from all the pop-up type crap that so many websites foist on you. Yes, it's a pain to un-break sites sometimes. But I resent it less than going through the equivalent pain in "privacy settings" popups, wriggling chat widgets, "ate you sure you don't want to sign up for our newsletter?" nags, etc. Websites are already broken; as long as that's true, I'd rather be in control of why.
However, overall I can tell you for absolute certain: if you have JS partially disabled things break in non-obvious ways and I find myself playing whack-a-mole with allowing various domains to load javascript to get the page working.
I'm pretty certain you do also, because it's basically impossible to tell why certain damned sites are broken and the most obvious thing to do is just enable JS temporarily to see if it works at all.
This is especially annoying on some part of a site such as checkout- where reloading the page causes a form resubmission.
For banking i use their phone app or else visit them in person. But I use a credit union not a bank as I want to trust the people holding my money.
You can disable mitigations on Windows too.
Aren’t the most affected group of users cloud users (and providers), not desktop users? I thought the biggest risk of specter attacks is the ability to glean information on other server residents who should be segmented off. There are many more concerns in user space which make attacking a desktop with specter pretty cumbersome for low reward wrt opportunity cost.
The performance savings of speculative execution do seem to be worth the risk on a desktop IMO.
This is also the case with Spectre-related vulnerabilities such as L1TF.
[1] https://aws.amazon.com/speculative-execution-os-updates/
I wonder if that’s weasel words for
“the majority of AWS workloads run single digit cpu utilisation, so a 50% performance hit is not a ‘meaningful performance impact’ for them”?
The need to keep telling this loud and clear for the manufacturers to hear is more needed now than ever since computers are becoming closed systems like smartphones and Manufacturers are claiming 'Customers not having to make hard decisions' to do so.
mitigations=off can only "patch out" some expensive instructions in the syscall path, or sometimes take a different path entirely, but it can't go back to the simple code before this was added in the first place. It also can't undo effects of compiler flags like -mindirect-branch which change the compiled code.
I haven't tested it recently, but when I looked at this more than a year ago, the numbers for a simple syscall (which doesn't do much work beyond the syscall mechanics itself) were something like 130ns, 250ns, 700ns for a "pre mitigation kernel", "new kernel with mitigations=off" and "new kernel with mitigations=on".
Some of the numbers have improved since then as better mitigations have been found, and/or improved CPU support for mitigations via microcode updates.
USB-C and USB 3.0 devices are one common cause, Bluetooth mouse interference by USB another, and external monitors after sleep/wake another.
Does anyone know what is at risk from these exploits?
I’ve been thinking what would happen if cores would be pinned to separate security domains - all kernel processes run on one set of cores and user processes on others. I imagine microkernel OSs could go that way much easier. If kernel and user space communicate only by messages and shared data, there’s no reason they’d need to even share an ISA.