Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: TaMoDee

I AM a GEEK. My job used to be to extend the sample BIOS supplied by Intel to take advantage of new Reliability And Serviceability (RAS) features for the three operating systems which run on the servers manufactured by my company.

“Physical address bits are security sensitive information and if they are available to user space, it elevates the user to perform other micro architectural attacks.”

There must be something else going on here, because this doesn’t make sense to a geek.

It wouldn’t be the first time that the technical writer scrambles the message. But the capability described above wouldn’t make me lose any sleep.


15 posted on 03/07/2019 8:35:12 PM PST by the_Watchman
[ Post Reply | Private Reply | To 7 | View Replies ]


To: the_Watchman

Engineers etc are rarely required to actually learn how to write good. *nudge*wink*


17 posted on 03/07/2019 8:49:41 PM PST by Rurudyne (Standup Philosopher)
[ Post Reply | Private Reply | To 15 | View Replies ]

To: the_Watchman; TaMoDee
I agree with The Watchman. I would also point out that the way this works is that the bad guys are running user mode code on your computer. They can't do anything remotely. If they run user mode code on your computer, it's mostly game over even before these kinds of bugs which mostly allow privilege elevation.

In theory the user mode code could include javascript that you loaded simply by visiting a website. But I am pretty sure a javascript exploit will never come to fruition. Not only that, but a browser can defend against such an attack rather easily by small randomizations in javascript execution.

20 posted on 03/08/2019 4:30:55 AM PST by palmer (...if we do not have strong families and strong values, then we will be weak and we will not survive)
[ Post Reply | Private Reply | To 15 | View Replies ]

To: the_Watchman
It wouldn’t be the first time that the technical writer scrambles the message. But the capability described above wouldn’t make me lose any sleep.

Thanks for the reassurance; faceless person on the internet.

29 posted on 03/08/2019 7:28:46 PM PST by Elsie (Heck is where people, who don't believe in Gosh, think they are not going...)
[ Post Reply | Private Reply | To 15 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson