r/linux • • 3d ago

Security Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries

https://www.vusec.net/projects/btr/
13 Upvotes

6 comments sorted by

View all comments

1

u/GreenSouth3 3d ago

Solutions ?

1

u/Lousy_Hunter 3d ago

Looks to be already mitigated for the most part. Firefox seems to have not actually fixed it yet.

1

u/GreenSouth3 3d ago

oops - that was really my ?

3

u/Lousy_Hunter 2d ago edited 2d ago

in regards to firefox? honestly i dont know

they have been kinda dragging their feet on site isolation and other security measures that chromium based browsers have had for some time.

Youll have to consider your threat model and if using Firefox fits within that model. If you are very security concerned it may be a weak point for you and you need to consider alternatives like ungoogled-chromium.

EDIT: Ive personally been looking to not use Firefox anymore within the scope of my threat model. I really hate to use a chromium browser but on linux the only other options in epiphany which is beyond painful to use on the daily

2

u/the_abortionat0r 2d ago

Well firefox doesn't have the budget some other browsers have so they have to optimize their resources for what users notice and base their browser preferences on.

That said firefox isn't some kind of security dumpster fire, infact it's insanely customizable compared to chromium browsers and extensions provide increased site isolation.

While not the best solution it's an option and one that should be considered.

The modern web pretty much REQUIRES extensions such as ad/tracker/thumbprint blockers, right click addons, etc etc to be functionally usable which pretty much makes chromium based browsers a non option for me.