Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Running untrusted code whether in a sandbox, container, or VM, has not been safe since at least Rowhammer, maybe before. I believe a lot of these exploits are down to software and hardware people not talking. Software people make assumptions about the isolation guarantees, hardware people don't speak up when said assumptions are made.


That is not true in this case. It's just a CPU bug; not even a side channel.


The statement about isolation guarantees is in general, doesn't relate to the OP.


Hardware people are the ones making those promises, so I don't think that's right at all. And Rowhammer is a way overstated vulnerability - there are all sorts of practical issues with it, especially if you're on modern, patched hardware.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: