From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leah Rowe Subject: Re: What do Meltdown and Spectre mean for libreboot x200 user? Date: Wed, 10 Jan 2018 08:56:41 +0000 Message-ID: <405e966d-581d-d6f5-e085-ecad532ffcc6@gluglug.org.uk> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:40694) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eZCBl-0003NL-3b for guix-devel@gnu.org; Wed, 10 Jan 2018 03:56:50 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eZCBk-0003VE-6C for guix-devel@gnu.org; Wed, 10 Jan 2018 03:56:49 -0500 Received: from web006.ispnoc.net ([2a00:1ca8:e:2::8476:d9ce]:37668) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1eZCBj-0003Uf-RI for guix-devel@gnu.org; Wed, 10 Jan 2018 03:56:48 -0500 Received: from 1.0.0.0.7.f.0.4.0.0.0.0.0.0.0.0.9.7.7.6.6.d.4.1.0.b.8.0.1.0.0.2.ip6.arpa ([2001:8b0:14d6:6779::40f7:1]) by web006.ispnoc.net with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.89) (envelope-from ) id 1eZCBc-00307x-QR for guix-devel@gnu.org; Wed, 10 Jan 2018 09:56:40 +0100 List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Hi Alex, The libreboot mailing list is down, so you can't CC it at the moment. I was notified about this thread. There's not much we can do from the Libreboot side, but there are mitigations on kernel side... since it's exploitable from javascript you could also e.g. not run JavaScript. specing on #libreboot IRC had the idea to run Firefox without the JIT enabled - we both tried to compile the latest ESR however, with --disable-ion, and it segfaulted. I tried to build ff 45esr instead, but that build failed. - -- Leah Rowe Libreboot developer and project founder. Use free software. Free as in freedom. https://www.gnu.org/philosophy/free-sw.html Use a free BIOS - https://libreboot.org/ Use a free operating system, GNU+Linux. Support computer user freedom https://fsf.org/ - https://gnu.org/ Minifree Ltd, trading as Ministry of Freedom | Registered in England, No. 9361826 | VAT No. GB202190462 Registered Office: 19 Hilton Road, Canvey Island, Essex SS8 9QA, UK | Web: https://minifree.org/ -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE+JRrnG26iGmvPhSA/0W3TPnRz5QFAlpV1UgACgkQ/0W3TPnR z5T9qAf+PH4YUo39T5irNIbzyljufibnn0zHGtwKOYtxHtZvzPAsaht2/VK6D1UT MUjH2EI2UYQsYzUPoza9SJ86TTtvukpZ9eBVNUW+Ah3KHO/ljHPFco3I0FlkjsoC rSRC2y7Nb1e8jidSXJ6bAqZGYqlNjmMcPU+7ct41bIwARybAD8PDsTXHnSH8Iqkk 7SP+XE062VOG41faKt7CZurxvdxBkn6ZfgCOc6+6jrhJBbOB7MPGTUuhxMjY+mPo tSJ4jAC15kZ9mQHu5f2ewnOn0zMQhTWU+AaOOaqdfh1RfK4nlf6UQkASw1pJ7/01 ywauC8hFVD2qDxr3OXXFCKdgbw61jw== =QnYX -----END PGP SIGNATURE-----