• 0 Posts
  • 2 Comments
Joined 11 months ago
cake
Cake day: October 29th, 2023

help-circle
  • Not really, there are plenty of things you can do to get around that. It also has been proven many of these bugs, while hard to pull off, can be used to great effect. Most security practitioners don’t have the technical understanding to accurately understand the impact of these types of vulnerabilities and are used to being the smartest people in the room, so sometimes understate the impact of these vulnerabilities.

    This exact thing played out with a number of silicon or microcode vulnerabilities… “well, it only impacts cloud providers, oh, I guess it does impact desktops, but it’s limited to a single core, oh, there is a memory controller that can access things across cores, oh…”.

    Unless someone has experience with HDL or has an extensive low level background, I would encourage people to take what they say with a grain of salt.