Groups | Search | Server Info | Login | Register


Groups > linux.debian.security > #5607

Re: Intel Microcode updates

From Rob van der Putten <rob@sput.nl>
Newsgroups linux.debian.security
Subject Re: Intel Microcode updates
Date 2019-06-20 14:40 +0200
Message-ID <yb4w9-6Y6-1@gated-at.bofh.it> (permalink)
References (3 earlier) <y7SBb-4VG-1@gated-at.bofh.it> <y7UjD-60r-9@gated-at.bofh.it> <y7Utj-64f-5@gated-at.bofh.it> <yairv-2Y4-1@gated-at.bofh.it> <yar1L-8aV-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi there


On 18/06/2019 20:21, Andrew McGlashan wrote:

> It doesn't have to be JavaScript, it can be ANY scripting.

Or any code.
The whole idea of running software you don't know anything about is insane.

>  When it
> comes to an updated browser, the exploit relies upon very precise
> timing differences between operations -- if the browser won't report
> timing with enough precision, then the exploit cannot work reliably if
> at all (probably not at all).
> 
> Now as for TB, well, one would hope (I don't now the answer), that
> they too have implemented the same fixes that Mozilla made for Firefox
> to thwart the success of an exploit as well, ie have timing being less
> granular to be able to perform the exploit.
> 
> Anyway, if the CPU microcode can be attained for the older CPUs, then
> the licensing issue with Debian providing it is no longer a concern (I
> believe).  Refer https://01.org/mcu-path-license-2018

My CPU isn't even in the list of non-supported CPU's.
In Thunderbird I have JavaScript off. _ALWAYS_!
I Firefox it's off most of the time. It's only on with companies I know 
and trust. I have been doing things this way for decades.
On top of that my Squid proxy server has a redirector with DNS-based 
blacklists (RBLs): If a website is known to have a leaky CMS it's 
replaced with a transparent GIF.


Regards,
Rob

Back to linux.debian.security | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

Intel Microcode updates Russell Coker <russell@coker.com.au> - 2019-06-10 06:10 +0200
  Re: Intel Microcode updates Michael Stone <mstone@debian.org> - 2019-06-10 13:20 +0200
    Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-10 19:50 +0200
      Re: Intel Microcode updates Michael Stone <mstone@debian.org> - 2019-06-10 20:40 +0200
        Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-11 20:10 +0200
          Re: Intel Microcode updates Michael Stone <mstone@debian.org> - 2019-06-11 22:00 +0200
    Re: Intel Microcode updates Russell Coker <russell@coker.com.au> - 2019-06-11 14:00 +0200
  Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-11 04:20 +0200
    Re: Intel Microcode updates Russell Coker <russell@coker.com.au> - 2019-06-11 14:00 +0200
      Re: Intel Microcode updates Moritz Mühlenhoff <jmm@inutil.org> - 2019-06-11 14:30 +0200
        Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-12 17:00 +0200
          Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 13:00 +0200
            Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-23 22:30 +0200
              Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-23 22:40 +0200
                Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-24 04:10 +0200
              Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-24 19:40 +0200
          Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 22:10 +0200
          Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-22 14:30 +0200
    Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-11 19:10 +0200
      Re: Intel Microcode updates Holger Levsen <holger@layer-acht.org> - 2019-06-11 19:20 +0200
        Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-11 21:10 +0200
          Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-11 21:20 +0200
            Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 11:20 +0200
              Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-18 20:30 +0200
                Re: Intel Microcode updates Rob van der Putten <rob@sput.nl> - 2019-06-20 14:40 +0200
            Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 22:10 +0200
            Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-22 14:30 +0200
    Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-23 10:00 +0200
      Re: Intel Microcode updates Lou Poppler <LouPoppler@cableone.net> - 2019-06-24 02:20 +0200
        Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-24 20:00 +0200

csiph-web