https://security.googleblog.com/2018/01 ... d.html?m=1
https://meltdownattack.com/ https://spectreattack.com/
Meltdown - velky problem - len intel, fix stoji 5-30% vykonu
Spectre - vsetci - intel, amd, arm, fix nie je ale ovela tazsie vykonat exploit. Ale proof-of-concept bezi v javascripte .
//edit spectre je cela trieda zranitelnosti.. viz. aj nazov:
Linux kernel inplementoval page table splitting, microsoft taktiez.Why is it called Spectre?
The name is based on the root cause, speculative execution. As it is not easy to fix, it will haunt us for quite some time.
Vsetky velke cloudy maju momentalne restarty (amazon, ibm taktiez rozosielal emaily).
Nejake komentare:
https://twitter.com/nicoleperlroth/stat ... 6249962496
https://news.ycombinator.com/item?id=16065845
Wiki:
https://en.wikipedia.org/wiki/Meltdown_ ... erability)
https://en.wikipedia.org/wiki/Spectre_( ... erability)