oss-sec mailing list archives

Re: Data operand dependent timing on Intel and Arm CPUs


From: John Runyon <me () jfr im>
Date: Mon, 30 Jan 2023 13:38:29 -0600

 I consider this issue to be a CPU security vulnerability

By that logic, allowing users to log into their system is a security
vulnerability.

A choice taken by design is not generally a vuln, even if/though it creates
vulns in other systems.

Current thread: