<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TLBleed - surely it would be ethical to patch it? in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/TLBleed-surely-it-would-be-ethical-to-patch-it/m-p/15353#M510</link>
    <description>&lt;P&gt;Interesting article appeared this morning:&amp;nbsp; &lt;A href="https://searchsecurity.techtarget.com/answer/How-does-TLBleed-abuse-the-Hyper-Threading-feature-in-Intel-chips" target="_blank"&gt;https://searchsecurity.techtarget.com/answer/How-does-TLBleed-abuse-the-Hyper-Threading-feature-in-Intel-chips&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it well known, then surely the emphasis should be on the manufacturer to resolve it, and not place the responsibility on organisations to mitigate it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
    <pubDate>Mon, 08 Oct 2018 19:20:11 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2018-10-08T19:20:11Z</dc:date>
    <item>
      <title>TLBleed - surely it would be ethical to patch it?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/TLBleed-surely-it-would-be-ethical-to-patch-it/m-p/15353#M510</link>
      <description>&lt;P&gt;Interesting article appeared this morning:&amp;nbsp; &lt;A href="https://searchsecurity.techtarget.com/answer/How-does-TLBleed-abuse-the-Hyper-Threading-feature-in-Intel-chips" target="_blank"&gt;https://searchsecurity.techtarget.com/answer/How-does-TLBleed-abuse-the-Hyper-Threading-feature-in-Intel-chips&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it well known, then surely the emphasis should be on the manufacturer to resolve it, and not place the responsibility on organisations to mitigate it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 19:20:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/TLBleed-surely-it-would-be-ethical-to-patch-it/m-p/15353#M510</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-10-08T19:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: TLBleed - surely it would be ethical to patch it?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/TLBleed-surely-it-would-be-ethical-to-patch-it/m-p/15355#M512</link>
      <description>&lt;P&gt;Ethics from a large company...? Devil’s advocate, sure, as Long as it doesn’t cost any money...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would say that enough OEM Customers would need to ask for this to be resolved - get server and desktop producers asking for it then we might see something. Sort of cash for a secure cache...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was at black hat and mitigation’s didn’t seem to impress Ben Gras:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.eweek.com/security/tlbleed-side-channel-cpu-attack-detailed-at-black-hat" target="_self"&gt;http://www.eweek.com/security/tlbleed-side-channel-cpu-attack-detailed-at-black-hat&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe they will fix it going forward.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 20:54:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/TLBleed-surely-it-would-be-ethical-to-patch-it/m-p/15355#M512</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-10-08T20:54:43Z</dc:date>
    </item>
  </channel>
</rss>

