Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> SPECTRE & friends are not a credible attack, for instance because you disable JS by default

That's... an extremely optimistic perspective on what's running on your system. Disabling JS in browser tab contexts (even if it's universal and not just "by default") is going to cover a pretty small percentage of SPECTRE et al. vectors.



What other vectors are there? Assuming that I trust my local software (because if I don't then spectre is the least of my problems).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: