From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leah Rowe Subject: Re: What do Meltdown and Spectre mean for libreboot x200 user? Date: Mon, 15 Jan 2018 11:32:40 +0000 Message-ID: <6e931622-65fc-fe0b-491f-3e94c6acdf0b@gluglug.org.uk> References: <405e966d-581d-d6f5-e085-ecad532ffcc6@gluglug.org.uk> <87shb8qxl4.fsf@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 7bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:46068) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eb30S-0002Cg-GG for guix-devel@gnu.org; Mon, 15 Jan 2018 06:32:49 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eb30R-0008Oe-Cg for guix-devel@gnu.org; Mon, 15 Jan 2018 06:32:48 -0500 Received: from web006.ispnoc.net ([2a00:1ca8:e:2::8476:d9ce]:40407) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1eb30R-0008Ny-4N for guix-devel@gnu.org; Mon, 15 Jan 2018 06:32:47 -0500 In-Reply-To: <87shb8qxl4.fsf@gmail.com> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Alex Vong Cc: guix-devel@gnu.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Hi Alex, On 14/01/18 15:17, Alex Vong wrote: > Thank you. I have updated my kernel. For the browser part, I > currently run tor browser with security level set to high (so that > javascript is disabled by default). Maybe you can tell people on > #libreboot about this solution if you like. This is technically unrelated to Libreboot, even if it is an important issue. swiftgeek and I decided not to document anything about it on the site. In my opinion, GNU+Linux distributions should be the ones advising people, since all of the defense/mitigation is done there at that level. The implications at firmware level are non-existent (for instance, these attacks can't, to my knowledge, be used to actually run/modify malicious code, just read memory, so it's not as if some evil site could install malicious boot firmware in your system). - -- Leah Rowe Libreboot developer and project founder. Use free software. Free as in freedom. https://www.gnu.org/philosophy/free-sw.html Use a free BIOS - https://libreboot.org/ Use a free operating system, GNU+Linux. Support computer user freedom https://fsf.org/ - https://gnu.org/ Minifree Ltd, trading as Ministry of Freedom | Registered in England, No. 9361826 | VAT No. GB202190462 Registered Office: 19 Hilton Road, Canvey Island, Essex SS8 9QA, UK | Web: https://minifree.org/ -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE+JRrnG26iGmvPhSA/0W3TPnRz5QFAlpckVcACgkQ/0W3TPnR z5QjOgf/WGDpNZBYVuk+TxplF/Fq7D3dooTasbEEjjcPt8vnqCUZXHTKg9lZDrjd yCWFkhWvR3ZkTQSoxVMbinHvQg8iDH5ZMOae5KAjxlFVeKFVHvS79UpMwHEs6SE0 PZK5p18rD3g43U1C6ck4UCnKTeSmDmUWrcLqAXa0RAcT+jvnhLCn3b4vAnyxZKjj KguwmMGd0+vO4b22Na9lPA9HoHwDZEMYydr38n1x7U7ZYFw1XymfD9R9i/8+YksE ATbmiVx6Dk0IKHEVU2dtIDOi20fRJIqEKotXFR71TMSIfXOySTn61y1Y0aEziSsQ Cys1b3F9Tux8MwV8aB+mwNga3H/UBQ== =t2lW -----END PGP SIGNATURE-----