Click here to Skip to main content
15,886,110 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
NewsThe CIA says that China’s security agencies provided funds for Huawei: report Pin
Sean Ewington25-Apr-19 8:16
staffSean Ewington25-Apr-19 8:16 
GeneralRe: The CIA says that China’s security agencies provided funds for Huawei: report Pin
Mark_Wallace25-Apr-19 10:09
Mark_Wallace25-Apr-19 10:09 
GeneralRe: The CIA says that China’s security agencies provided funds for Huawei: report Pin
maze325-Apr-19 22:38
professionalmaze325-Apr-19 22:38 
NewsMicrosoft is now a $1 trillion company Pin
Sean Ewington25-Apr-19 8:01
staffSean Ewington25-Apr-19 8:01 
GeneralRe: Microsoft is now a $1 trillion company Pin
Mark_Wallace25-Apr-19 8:15
Mark_Wallace25-Apr-19 8:15 
GeneralRe: Microsoft is now a $1 trillion company Pin
Joe Woodbury25-Apr-19 16:14
professionalJoe Woodbury25-Apr-19 16:14 
GeneralRe: Microsoft is now a $1 trillion company Pin
Rick York26-Apr-19 4:53
mveRick York26-Apr-19 4:53 
NewsAccording to Google’s JavaScript team; Spectre mitigation doomed to failure Pin
Dan Neely25-Apr-19 4:13
Dan Neely25-Apr-19 4:13 
Software mitigations are an unsustainable path

Fortunately or unfortunately, our offensive research advanced much faster than our defensive research, and we quickly discovered that software mitigation of all possible leaks due to Spectre was infeasible. This was due to a variety of reasons. First, the engineering effort diverted to combating Spectre was disproportionate to its threat level. In V8 we face many other security threats that are much worse, from direct out-of-bound reads due to regular bugs (faster and more direct than Spectre), out-of-bound writes (impossible with Spectre, and worse) and potential remote code execution (impossible with Spectre and much, much worse). Second, the increasingly complicated mitigations that we designed and implemented carried significant complexity, which is technical debt and might actually increase the attack surface, and performance overheads. Third, testing and maintaining mitigations for microarchitectural leaks is even trickier than designing gadgets themselves, since it’s hard to be sure the mitigations continue working as designed. At least once, important mitigations were effectively undone by later compiler optimizations. Fourth, we found that effective mitigation of some variants of Spectre, particularly variant 4, to be simply infeasible in software, even after a heroic effort by our partners at Apple to combat the problem in their JIT compiler.


Fortunately, one of their existing features that has long been sponsored by DRAM manufacturers - isolation via a zillion processes - does appear to work.
Did you ever see history portrayed as an old man with a wise brow and pulseless heart, weighing all things in the balance of reason?
Is not rather the genius of history like an eternal, imploring maiden, full of fire, with a burning heart and flaming soul, humanly warm and humanly beautiful?
--Zachris Topelius

Training a telescope on one’s own belly button will only reveal lint. You like that? You go right on staring at it. I prefer looking at galaxies.
-- Sarah Hoyt

GeneralRe: According to Google’s JavaScript team; Spectre mitigation doomed to failure Pin
Mark_Wallace25-Apr-19 8:03
Mark_Wallace25-Apr-19 8:03 
GeneralRe: According to Google’s JavaScript team; Spectre mitigation doomed to failure Pin
Joe Woodbury25-Apr-19 16:16
professionalJoe Woodbury25-Apr-19 16:16 
GeneralRe: According to Google’s JavaScript team; Spectre mitigation doomed to failure Pin
Rick York26-Apr-19 4:52
mveRick York26-Apr-19 4:52 
NewsMicrosoft knows password expiration policies are useless Pin
Dan Neely24-Apr-19 10:49
Dan Neely24-Apr-19 10:49 
GeneralMicrosoft ~~ are useless Pin
Mark_Wallace24-Apr-19 11:41
Mark_Wallace24-Apr-19 11:41 
GeneralRe: Microsoft knows password expiration policies are useless Pin
Nelek24-Apr-19 21:40
protectorNelek24-Apr-19 21:40 
GeneralRe: Microsoft knows password expiration policies are useless Pin
Joe Woodbury25-Apr-19 16:20
professionalJoe Woodbury25-Apr-19 16:20 
NewsNintendo squashes Super Mario Commodore 64 port which took seven years to make Pin
Sean Ewington24-Apr-19 9:01
staffSean Ewington24-Apr-19 9:01 
GeneralRe: Nintendo squashes Super Mario Commodore 64 port which took seven years to make Pin
Sander Rossel24-Apr-19 11:02
professionalSander Rossel24-Apr-19 11:02 
GeneralRe: Nintendo squashes Super Mario Commodore 64 port which took seven years to make Pin
Joe Woodbury25-Apr-19 16:21
professionalJoe Woodbury25-Apr-19 16:21 
GeneralRe: Nintendo squashes Super Mario Commodore 64 port which took seven years to make Pin
Sander Rossel25-Apr-19 23:39
professionalSander Rossel25-Apr-19 23:39 
GeneralRe: Nintendo squashes Super Mario Commodore 64 port which took seven years to make Pin
Mark_Wallace24-Apr-19 11:44
Mark_Wallace24-Apr-19 11:44 
NewsMicrosoft displays warning messages in Windows 7 about the impending end of support Pin
Sean Ewington24-Apr-19 9:01
staffSean Ewington24-Apr-19 9:01 
GeneralRe: Microsoft displays warning messages in Windows 7 about the impending end of support Pin
RickZeeland24-Apr-19 21:14
mveRickZeeland24-Apr-19 21:14 
NewsWindows 10’s “Sets” tabbed windows will never see the light of day Pin
Sean Ewington24-Apr-19 8:46
staffSean Ewington24-Apr-19 8:46 
GeneralRe: Windows 10’s “Sets” tabbed windows will never see the light of day Pin
Mark_Wallace24-Apr-19 11:46
Mark_Wallace24-Apr-19 11:46 
GeneralRe: Windows 10’s “Sets” tabbed windows will never see the light of day Pin
Graham Cottle24-Apr-19 19:25
professionalGraham Cottle24-Apr-19 19:25 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.