• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

zenbleed AMD security bug

Medium severity security bug - CHECK
Potential disclosure of sensitive data - CHECK
Ease of attack - CHECK
Vulnerability through remote access - CHECK
Proof of concept code - CHECK
Reliance on updates from vendor through motherboard manufacturers via BIOS update - UH OH
Timing for mitigation December'23 - WTF

I've just about had it with my X570 rig and all the stability and security issues over the years. While others undoubtedly have had better experiences, I am about ready to write AMD off.
I had an ASUS X570 rig for over two years with absolutely zero issues, once I replaced a defective RAM stick.
 
Selective use of javascript is certainly possible. I use noscript with a small collection of servers permanently whitelisted and most of the time it just works like an ad blocker that also gets rid of some of the other extraneous stuff they add these days, sometimes I have to temporarily whitelist some servers for a site to work properly but even then I can usually leave the ad and tracking servers blocked and get a cleaner page.

It's not something I would expect most people to want to deal with but I think it gives me a cleaner web experience than can be achieved with ad blockers alone.
Block anything resembling off site? Yeah, I could see that cleaning up the ads. But then again, so would blocking iframes. But then blocking iframes is probably why sites resorted to javascript.

Even in a javascript-devoid world, ads will be delivered to you. You just move the content delivery to the backend. It's an endless war.
 
Block anything resembling off site? Yeah, I could see that cleaning up the ads. But then again, so would blocking iframes. But then blocking iframes is probably why sites resorted to javascript.

Even in a javascript-devoid world, ads will be delivered to you. You just move the content delivery to the backend. It's an endless war.
I'm not suggesting to get of rid of javascript altogether I'm just saying that for personal use blocking most javascript by default makes for a cleaner overall experience and not just for ads. It does break plenty of pages though too and I realize that most wouldn't want to deal with the hassle, it probably helps that the types of sites that break unless you unblock a ton of servers are generally not ones I visit much.
 
I'm just saying that for personal use blocking most javascript by default makes for a cleaner overall experience
Blocking js by default makes for a nightmare experience for most people in today's world.
 
Yes, but it's still the right thing to do. Ignorance can be pleasure, but doesn't mean it's right.
Okay. That works for you and me.

And now, how do we solve the problem for millions of other people who don't know what we know, or how to do it?
 
7tvqra.jpg
 
As of now there are no exploits in the wild, if any are seen I'm sure the update will be out sooner.


5-6 months isn't that long and for all we know there will never be a known exploit in the wild

At least there's a bios update to fix it coming out, spectre was mostly mitigated by software updates
 
As of now there are no exploits in the wild, if any are seen I'm sure the update will be out sooner.


5-6 months isn't that long and for all we know there will never be a known exploit in the wild

At least there's a bios update to fix it coming out, spectre was mostly mitigated by software updates

From the writeup, it seems fairly exploitable, but what you get out is unlabeled probably string data; easy to show you found something specific, but hard to know you found something good. Are credit card numbers long enough that they'd get copied with sse registers? It's pretty easy to check if something that looks like a credit card number is... But you might not be able to find the rest of the stuff you need.
 
Back
Top