View Single Post
Old 05-04-18, 06:31 AM   #5
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,500
Downloads: 9
Uploads: 0


Default

If you think this is only about personal data theft, than you have not understood the dimension of the problem. Although personal data theft already is serious enough, when you consider login data for online shops and online banking/brokering, but also your profile: risk evaluation when you ask an insurance company for a policy, getting sniffed out when you ask an employer for a job, targetted advertisement by businesses as well as political parties, social bonus points and bad notes for you when analysis shows that you like or dislike like you should (or should not), and your typed in views being in line or not with the wanted public opinions and views... Look at China, they are doing right this now, it gets reported these days.

Think in terms of enforced remote control of IT infrastructure in cities, traffic infrastructures and institutions, hospitals, energy production - blackmailing, cyber warfare - oh wait - that hospitals get blackmailed by cyber attackers, already is a common practice now it seems.

Think in terms of taking over IT hardware - and everything that it controls. Think in terms of bot nets.

Like it is said somewhere in the articles: our complete IT infrastruture's security is rotten at the very core level already. And the easier it is to abuse these weaknesses, the more dangerous the situation becomes, and the more likely it becomes that attacks take place. Spectre NG represents such a dramatic simplification, in parts at least. I have read this morning that it got leaked that one of those eight vulnerabilities consists of only four brief lines of code injected in an environment that bases on the use of a VM. What the...? Just four lines of code to spell desaster?

It takes years to become a competent fencer and hit your opponent at 1 meter. But every every idiot can shoot and hit with a pistol at 10 meters. Thats why simplifying the execution of Meltdown- and Spectre-based attacks is so dangerous.
__________________
If you feel nuts, consult an expert.

Last edited by Skybird; 05-04-18 at 10:06 AM.
Skybird is offline   Reply With Quote