• 2

開發人員發現,蘋果 M1 晶片竟有無法修復的安全漏洞

buzzbee wrote:
嚇死人了,再下單一台(恕刪)


刺激經濟救蘋果,欸不是,應該是刺激經濟救台灣(產線)才對。
一流人專做開源未來事,二流人專做停滯不前淘汰事,三流人只做問題進行事,四流人只做同溫取暖裝傻事。
9to5Mac 其實有報,基本上此漏洞沒有什麼傷害性,只是因為他繞開了部分原本處理器設計上應該要阻止的行為才稱之為漏洞

基本上此漏洞無法繞過沙盒也無法攻擊正常軟體,自動偵測利用漏洞的軟體避免被上架到官方App Store也不會很困難,使用上需要有兩個軟體(病毒或廣告軟體)事先互相串通好,才可以互相交換訊息,但你從網路上隨便下載的兩個軟體如果他們串通要互相交換訊息的方式有無限多種,所以實際上沒有什麼影響

這則新聞最主要的特點就是發現者故意模仿最近其他開發者揭露漏洞時喜歡架一個精美的介紹網站,有點潮諷資安界喜歡誇大其詞或使用聳動標題的陋習

以下為9to5Mac節錄該網站充滿詼諧風格的Q&A

Can malware use this vulnerability to take over my computer?
No.

Can malware use this vulnerability to steal my private information?
No.

Can malware use this vulnerability to rickroll me?
Yes. I mean, it could also rickroll you without using it.

Can this be exploited from Javascript on a website?
No.

Can this be exploited from Java apps?
Wait, people still use Java?

Can this be exploited from Flash applets?
Please stop.

Can I catch BadBIOS from this vulnerability?
No.

Wait, is this even real?
It is.

So what’s the real danger?
If you already have malware on your computer, that malware can communicate with other malware on your computer in an unexpected way. Chances are it could communicate in plenty of expected ways anyway.

That doesn’t sound too bad.
Honestly, I would expect advertising companies to try to abuse this kind of thing for cross-app tracking, more than criminals. Apple could catch them if they tried, though, for App Store apps. Wait. Oh no. Some game developer somewhere is going to try to use this as a synchronization primitive, aren’t they. Please don’t. The world has enough cursed code already. Don’t do it. Stop it. Noooooooooooooooo […]

So what’s the point of this website?
Poking fun at how ridiculous infosec clickbait vulnerability reporting has become lately. Just because it has a flashy website or it makes the news doesn’t mean you need to care. If you’ve read all the way to here, congratulations! You’re one of the rare people who doesn’t just retweet based on the page title :-)
kkk123kkk123kkk wrote:
9to5Mac 其實(恕刪)


這讓我想起 之前看 一個節目叫 非你莫屬 的徵才節目

有個自稱黑客的資安人員去應徵

說發現某大平台的安全性漏洞

被追問下 結果他說 他發現後台網址....

然後台下有人問說 那你有辦法登入嗎

他回答 沒有帳號密碼不能登入


.........

智障真的要有底線
貓老闆
kahnmao wrote:
這讓我想起 之前看 (恕刪)


其實發現者本來也不知道是漏洞,之前還在推特上表示他發現了處理器的新功能,後來問了蘋果才知道不是新功能,不過發現者也說蘋果運氣很好這個出問題的處理器功能對沙盒模式還是有反應,不然就是完全不同級別的資安問題了
劍心san wrote:
蘋果的M1晶片、A14晶片都有一樣的漏洞了,不知道M2晶片又會是如何.....?


代代遺傳,那這個應該叫後門吧?
  • 2
內文搜尋
X
評分
評分
複製連結
Mobile01提醒您
您目前瀏覽的是行動版網頁
是否切換到電腦版網頁呢?