-
NetSpectre — a remote Spectre v1 attack
Michael Heller reports on TechTarget:
Researchers developed a new proof-of-concept attack on Spectre variant 1 that can be performed remotely (say, via a browser)… requires no attacker-controlled code on the target device… this NetSpectre variant is able to leak 15 bits per hour from a vulnerable target system.
Kevin Beaumont had a great analysis:
https://twitter.com/GossiTheDog/status/1022762955983732736?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1022762955983732736&ref_url=https%3A%2F%2Fsearchsecurity.techtarget.com%2Fnews%2F252445965%2FNetSpectre-is-a-remote-side-channel-attack-but-a-slow-one
I’m still not shaking in my boots about Meltdown or Spectre.