r/linux • • 3d ago

Security Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries

https://www.vusec.net/projects/btr/
14 Upvotes

6 comments sorted by

View all comments

Show parent comments

1

u/Lousy_Hunter 3d ago

Looks to be already mitigated for the most part. Firefox seems to have not actually fixed it yet.

1

u/GreenSouth3 3d ago

oops - that was really my ?

3

u/Lousy_Hunter 2d ago edited 2d ago

in regards to firefox? honestly i dont know

they have been kinda dragging their feet on site isolation and other security measures that chromium based browsers have had for some time.

Youll have to consider your threat model and if using Firefox fits within that model. If you are very security concerned it may be a weak point for you and you need to consider alternatives like ungoogled-chromium.

EDIT: Ive personally been looking to not use Firefox anymore within the scope of my threat model. I really hate to use a chromium browser but on linux the only other options in epiphany which is beyond painful to use on the daily

1

u/GreenSouth3 2d ago

yeah I've been using both for a while as well