Readit News logoReadit News
dang · 6 years ago
Submissions of lists, like this home page, lead to lowest-common-denominator discussions. People focus on what the list items have in common and its gravity prevents specific items from gaining liftoff. Specific discussions tend to go deeper than generic ones, so we're going to unmerge these threads and have a separate one for each major disclosure:

Zombieload: https://news.ycombinator.com/item?id=19911341

MDS: https://news.ycombinator.com/item?id=19911277

This will take several minutes, so if you see weird incongruities or disappearances, hold your fire.

Edit: Ok, I've done as much of this as I'm going to do. If you notice anything wrong, can you let us know at hn@ycombinator.com so we can fix it?

JdeBP · 6 years ago
This is the overview page. It comes alongside:

* https://zombieloadattack.com/ , on Hacker News as https://news.ycombinator.com/item?id=19911341 (The technical paper is hidden inside a collapsed part of the page and is at https://www.cyberus-technology.de/posts/2019-05-14-zombieloa... .)

* https://mdsattacks.com/ , on Hacker News at https://news.ycombinator.com/item?id=19911277

* Google's announcement about ChromeOS at https://sites.google.com/a/chromium.org/dev/chromium-os/mds-... , on Hacker News at https://news.ycombinator.com/item?id=19911406

( Several Hacker News discussions have since been merged here. And were then re-split. )

pfortuny · 6 years ago
I thught Theo deRaadt was exaggerating when he said that Intel does not know how to build a CPU.
lawnchair_larry · 6 years ago
He was, obviously.
willtim · 6 years ago
Intel certainly does not know how to build a secure CPU.
dsp1234 · 6 years ago
The blog post is buried a bit deep, but has the actual technical information on the topic

https://www.cyberus-technology.de/posts/2019-05-14-zombieloa...

JdeBP · 6 years ago
The overview page, https://cpu.fail/ , is on Hacker News as https://news.ycombinator.com/item?id=19911715 .

( This comment was merged from a duplicate discussion. )

josh2600 · 6 years ago
The worst thing about heartbleed is that it introduced marketing into vulnerability disclosures :(.
the_duke · 6 years ago
In some cases I agree, but these are very interesting attacks, and having a nice, informative landing page about it is very welcome.
kevin_thibedeau · 6 years ago
Boosting your impact factor is how to get tenure. Why stick to dry journals when you can leverage mass media?
josu · 6 years ago
How is that a bad thing?
icelancer · 6 years ago
It isn't. Some people just think "marketing" is the root of all evil, when done right, it's actually just effective communication.
asaph · 6 years ago
I never knew about the .fail TLD.
woliveirajr · 6 years ago
> Computer makers Apple and Microsoft and browser makers Google and Mozilla are releasing patches today.

Computer makers? Wouldn't that be OS makers? They are patching their OS to prevent leaking...

philsnow · 6 years ago
apple makes macs / macbooks etc, microsoft makes surfaces / surface pros...
woliveirajr · 6 years ago
Yes, but I couldn't find anywhere if Apple and Microsoft are patching this as a "hardware" fix for specific products.

Almost like saying that the "software maker" John Deere will fix their latest-model Haverster.

Deleted Comment