It's more like saying "refusing to leave your house because you're worried you might get mugged", which might actually be very reasonable if you live in a bad neighborhood, you're a common target of crime, etc. It may not be reasonable for many others.
But analogies are pretty rough in general.
> The number of stars that have to align for this theoretical attack to work in practice is so high that I don't think any normal desktop end-user has reason to worry about it.
The reason we don't see these attacks is because everyone patched the major issues immediately. Further, attackers don't need to really go for these sorts of attacks, there are more reliable, well-worn methods for attacking browsers.
Please spell it out for me. Suppose I'm a typical desktop user, how is important information going to be stolen if I have mitigations turned off and JavaScript enabled? What state does my browser have to be in, and what actions do I have to take (or not take) for the attack to succeed? What likelihood is it that someone has deployed an attack that meets those requirements?
> Further, attackers don't need to really go for these sorts of attacks, there are more reliable, well-worn methods for attacking browsers.
So we agree it's OK to leave mitigations off and browse the web?
https://github.com/google/security-research-pocs/tree/master...
I don't imagine I'm going to explain it better than the many others who have already done so.
> What state does my browser have to be in, and what actions do I have to take (or not take) for the attack to succeed?
Your browser would have to be pretty old/ outdated since they've been updated to mitigate these attacks. Otherwise it's just necessary that you visit the attacker controlled website.
> What likelihood is it that someone has deployed an attack that meets those requirements?
That's not a simple question. Threat landscapes change based on a lot of factors. As I said earlier, we won't see these attacks because people have already patched and attackers have other methods.
> So we agree it's OK to leave mitigations off and browse the web?
You can do whatever you want, idk what you're trying to ask here. What is "OK" ? You will be vulnerable but unlikely to be attacked for the reasons mentioned. If you are "OK" with that that's up to you.
It's a really impractical attack outside of extremely targeted scenarios. It's not something real desktop end-users need to worry about. The mitigations slow down your system for zero benefit.
> You can do whatever you want, idk what you're trying to ask here. What is "OK" ?
Maybe re-read the thread from the start? The first guy I responded to was making an assertion that running without spectre/etc mitigations means you should turn off javascript.
The POC runs in visitors browsers lol it's a public demo that runs in your browser, not in a "carefully controlled research setup".
> that very probably don't contain anything of value
Lots of things are valuable other than passwords. Even just leaking addresses can be useful for further exploitation. The main issue is it's a violation of a security boundary.
> The first guy I responded to was making an assertion that running without spectre/etc mitigations means you should turn off javascript.
They said "I hope you <do that>". Presumably because it would also mitigate the issue.
In both cases: We know they are theoretically possible. We cannot say for sure when they'll emerge. Once they emerge, they can spread by themselves and become common.
I guess the place it doesn't hold up is that in the exploit case, they're intentionally engineered, and for a virus, well there's the Wuhan bioweapon conspiracy theory but no, it's more like random mutations cause it.
Properly engineered security fixes don't cause performance regressions, either because you find improvements to pay for them, or you get the hardware updated to make them cheaper. (That'd be PCID in this case.)