MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
which
Search

West: Post-Spectre web development

Friday February 26, 2021. 08:55 PM , from LWN.net
Mike West has posted a detailed exploration
of what is really required to protect sensitive information in web
applications from speculative-execution exploits. 'Spectre-like
side-channel attacks inexorably lead to a model in which active web content
(JavaScript, WASM, probably CSS if we tried hard enough, and so on) can
read any and all data which has entered the address space of the process
which hosts it. While this has deep implications for user agent
implementations' internal hardening strategies (stack canaries, ASLR, etc),
here we’ll remain focused on the core implication at the web platform
level, which is both simple and profound: any data which flows into a
process hosting a given origin is legible to that origin. We must design
accordingly.'
https://lwn.net/Articles/847613/rss
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
May, Wed 8 - 02:13 CEST