Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Page as a whole seems over-broad. E.g. the first FAQ entry:

> Have I been affected by this attack?

> If you have an Intel processor or an Apple device with the M1 chip, then yes with very high probability. We also expect our attack to be effective for AMD machines, however this has been only partially demonstrated.

while also further down

> Has Spook.js been abused in the wild?

> We do not have any evidence so far that Spook.js has been or not been abused in the wild.

and I haven't been able to find any references whatsoever to evidence that this technique has been actively used.



Pretty much...

> Have I been affected by the polonium sushi attack?

> If you have a digestive tract, then yes with very high probability. We also expect our attack to be effective against those fed via IV, but this has only been partially demonstrated.


Yea. They are calling both the vulnerability and the exploit as "the attack", but they are wrong.

I'll just take a moment to point out that the article requires js for the FAQ. It may use JS for other areas I am unaware.


Perhaps there's a preexisting template for "dramatic spectre-related security announcement website" that has that part of the FAQ pre-populated.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: