https://nvd.nist.gov/vuln/detail/CVE-2019-8601
Remote execution vulnerabilities happen in JavaScriptCore. Tech-savvy won’t save you, all it takes is some malicious ad code or some hacked server providing malicious JS (or media files, etc. etc.)
https://nvd.nist.gov/vuln/detail/CVE-2019-8601
Remote execution vulnerabilities happen in JavaScriptCore. Tech-savvy won’t save you, all it takes is some malicious ad code or some hacked server providing malicious JS (or media files, etc. etc.)
I think it would go a long way to convincing people if you could for example visit a website that eg. changes your desktop background when you visit it, to show how dangerous it is to run unpatched systems.
There are so many documented vulnerabilities that only apply to certain scenarios, that people (myself included) just think, "Hey, that sounds very theoretical, I don't think it applies in my case"
While I do not condone the use of an insecure version of the OS, herd immunity is an underrated factor. Unless you're targeted, malware developers don't spend too much time on 0.5% market share, just like web developers don't optimise for unknown browsers.
Prove me wrong.
Despite lots and lots of POCs, I haven't seen attackers use spectre in the wild yet. Maybe sophisticated actors are using it but they haven't been caught yet, or more likely they just use more traditional and reliable ways to get info leaks. But if traditional info leaks dwindle, they may turn to speculative execution attacks.
No. That’s the point. The burden of proof isn’t on anyone to disprove your untestable theory about market penetration (although in the case of JS vulnerabilities your premise is completely baseless anyway).
That’s like saying “you can’t get cancer from smoking if you immediately drink a herbal tea after every cigarette because of it’s mystical healing properties. Prove me wrong.”
The claim is other people saying "don't use an old OS/mitigations turned off because of drive-by malware."
I am the one asking for proof of this. I know the vulnerability is real, but is there malware on the web, right now, that I might chance upon and risk my data?
Unless your proposition is that there are groups exploiting minority unsupported OSes but that they all remain successfully undiscovered, like Russell's teapot[0].
But as others point out, there actually is at least one known counterexample - WannaCry/EternalBlue.
e.g. If a JavascriptCore vulnerability allows RCE on a Mac running whatever old version, write something to exploit it and execute the "say" command on that Mac, so anyone running that version can go to that webpage and literally see "wow this is a real exploit that actually works and anyone can abuse".
I'd love to see that. Kind of like the XSS script alert triggers, stuff where you can just paste a bit of code and prove that it -is- exploitable, without it actually doing anything harmful.
With Sepctre mitigations rolling out in under a month to almost all PCs, of course there is less incentive to build an exploit. But we know how it was when 90% of PCs were unpatched XP boxes.