<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Foreshadowing the end of computing as we know it ... in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Foreshadowing-the-end-of-computing-as-we-know-it/m-p/13822#M1456</link>
    <description>&lt;P&gt;Like I told you, it's all about having &lt;A href="https://community.isc2.org/t5/Industry-News/The-Spectre-of-multi-core-CPUs/m-p/10827#M1002" target="_blank"&gt;multi-core CPUs and race conditions&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First came Spectre and Meltdown.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we've got &lt;A href="https://foreshadowattack.eu/" target="_blank"&gt;Foreshadow&lt;/A&gt;, which can grab protected information even under virtual machine and hypervisor situations.&amp;nbsp; (That is a good overview paper, but you can also get some &lt;A href="https://twitter.com/yuvalyarom/status/1029413004000088066" target="_blank"&gt;random discussion from Twitter&lt;/A&gt;.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this stuff isn't new.&amp;nbsp; Apparently someone found a &lt;A href="https://www.tomshardware.com/news/x86-hidden-god-mode,37582.html" target="_blank"&gt;four byte jump from ring 3 (user space) to ring 0 (the root kernel) in old x86s&lt;/A&gt;.&amp;nbsp; (Don't know why they bothered, since almost everyone ran everything in root mode anyway, but ...)&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 08:54:31 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2023-10-09T08:54:31Z</dc:date>
    <item>
      <title>Foreshadowing the end of computing as we know it ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Foreshadowing-the-end-of-computing-as-we-know-it/m-p/13822#M1456</link>
      <description>&lt;P&gt;Like I told you, it's all about having &lt;A href="https://community.isc2.org/t5/Industry-News/The-Spectre-of-multi-core-CPUs/m-p/10827#M1002" target="_blank"&gt;multi-core CPUs and race conditions&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First came Spectre and Meltdown.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we've got &lt;A href="https://foreshadowattack.eu/" target="_blank"&gt;Foreshadow&lt;/A&gt;, which can grab protected information even under virtual machine and hypervisor situations.&amp;nbsp; (That is a good overview paper, but you can also get some &lt;A href="https://twitter.com/yuvalyarom/status/1029413004000088066" target="_blank"&gt;random discussion from Twitter&lt;/A&gt;.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this stuff isn't new.&amp;nbsp; Apparently someone found a &lt;A href="https://www.tomshardware.com/news/x86-hidden-god-mode,37582.html" target="_blank"&gt;four byte jump from ring 3 (user space) to ring 0 (the root kernel) in old x86s&lt;/A&gt;.&amp;nbsp; (Don't know why they bothered, since almost everyone ran everything in root mode anyway, but ...)&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:54:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Foreshadowing-the-end-of-computing-as-we-know-it/m-p/13822#M1456</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T08:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Foreshadowing the end of computing as we know it ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Foreshadowing-the-end-of-computing-as-we-know-it/m-p/13849#M1464</link>
      <description>&lt;P&gt;VMWare poke one of my admins this morning with just such a warning or to be more succinct a corporate CYA moment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since following this vulnerability since last week and see the natural progression from theory to NMap to some exploit code but nothing wide spread yet or is this actually being exploited under our noses without notice?&lt;/P&gt;&lt;P&gt;Thus far it appears that you'd have to be near the hypervisor itself while reading a vulnerable machine through a tunnel while conversing with a free range unicorn under cover of darkness.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus far I am not seeing the opportunity to win this trifecta several times in a row or at least in this environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone give me a reasonable scenario or example of exploitation, please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;B/Eads&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 20:42:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Foreshadowing-the-end-of-computing-as-we-know-it/m-p/13849#M1464</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2018-08-20T20:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Foreshadowing the end of computing as we know it ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Foreshadowing-the-end-of-computing-as-we-know-it/m-p/13856#M1468</link>
      <description>&amp;gt; Beads (Contributor II) posted a new reply in Industry News on 08-20-2018 04:42&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Since following this vulnerability since&lt;BR /&gt;&amp;gt; last week and see the natural progression from theory to NMap to some exploit&lt;BR /&gt;&amp;gt; code but nothing wide spread yet or is this actually being exploited under our&lt;BR /&gt;&amp;gt; noses without notice?&lt;BR /&gt;&lt;BR /&gt;Nope, no exploit yet.&lt;BR /&gt;&lt;BR /&gt;Yeah, I figure you're right: it'd be pretty specialized. However, it does indicate&lt;BR /&gt;how bad and complicated the race condition problems are, and that it needs ot be&lt;BR /&gt;fixed.&lt;BR /&gt;&lt;BR /&gt;I remember reviewing a book on optimization, with a great quote on the topic:&lt;BR /&gt;"Optimizations always bust things, because all optimizations are, in the long haul,&lt;BR /&gt;a form of cheating, and cheaters eventually get caught."&lt;BR /&gt;- Larry Wall&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;A: Yes.&lt;BR /&gt;&amp;gt; Q: Are you sure?&lt;BR /&gt;&amp;gt;&amp;gt; A: Because it reverses the logical flow of conversation.&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; Q: Why is top posting frowned upon?&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://www.infosecbc.org/links" target="_blank"&gt;http://www.infosecbc.org/links&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;</description>
      <pubDate>Mon, 20 Aug 2018 23:54:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Foreshadowing-the-end-of-computing-as-we-know-it/m-p/13856#M1468</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-08-20T23:54:05Z</dc:date>
    </item>
  </channel>
</rss>

