|
|
|
|
|
by mdriley
2146 days ago
|
|
(disclosure: I work at Google on side-channel stuff and https://github.com/google/safeside) I'm really excited to read that post! I agree that the best we can claim right now is that we've made Spectre and other speculative attacks "expensive enough" that they're unlikely to be the most profitable area for attack. That said, I'd be a bit worried about the assertion we haven't seen Spectre attacks "in the wild". It is incredibly difficult to put together a set of metrics that would convincingly detect attempts at even a straightforward speculative information disclosure. (haha, two branches, I get it) |
|