Hacker News new | ask | show | jobs
by XR0CSWV3h3kZWg 3083 days ago
spectre can read, not write.
3 comments

If I can read arbitrary data, what’s stopping me from reading the credentials I need to write data?
What if I read the sites TLS/SSL keys? I could MITM the connection and inject JS to do more malcious thing.

Or even easier get the ssh key for the VM. Then do what ever I want.

If it can read the right data (private keys, etc.), then it can write whatever it wants.