Meltdown / Spectre

Apparently web browsers are vulnerable too. Don't forget to update your browsers and disable javascript Sup Forums.
blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/

How do I use Facebook with JS disabled,

>How do I use Facebook
You don't

you deserve all the bad shit coming your way

funny enough my mozilla browser with noscript ghostery https everywhere and ublock refuses to open that page

Sure thing, tough guy

Holy hell this has really blew up

EVERYTHING is vulnerable to spectre
Intel processors only are vulnerable to meltdown.

But you cant post here with js disabled((

reminder that if you haven't blocked the ukrainian cdn that Sup Forums uses you're really really fucked

What normal person is going to have their computers targeted by such an attack... Why is everyone even worrying?

What's the range for Ukranian IP addresses? I don't want those Soros cocksuckers touching my 1s or 0s

m.facebook.com

Request desktop/PC version for dirty phoneposters

It's and shills making a huge deal over this.

What makes you think it requires someone to specifically target you?

Kill yourself.

Easy wait for the fix of meltdown then run linux in a vm. After every sesion of browsing revert the vm to an earlyer state

bit harsh, chill out

how else can it happen? Either you visit a malicious site and allow it in your script blocker or you are targeted manually.

Let me play out a scenario

1) Malicious company makes seemingly innocent ad with malicious script

2) They buy adspace on jew-run website (aka any website that makes money with ads)

3) You visit jew operated website

4) Your computer loads the ad and it harvests whatever information it can


If you visit sketchy sites, like anything piracy/torrent/warez/porn related, you are at risk

>i have to avoid my fav cam whore site for a while

feels bad man. how will i talk to the opposite sex now :(

Friendly reminder that android smart phones are affected by this bug.

I had my WoW account hacked in a similar way. I believed in computer security up until that moment. Someone managed to install a keylogger via an ad on a WoW addon website.

>adblock
Sup Forums BTFO

Where does facebook fit into this?

Are they really going to get in there?

CSS is also unironically vulnerable
Install Netrunner

>he thinks adblock will protect him

Spoiler alert, it wont. Adblock just blocks popular hosts that have been previously blocked in the past. If someone is going the malicious script route, they make a brand new host just for the script. I'm and I always ran my ad blocker with TONS of lists, yet it still somehow got me.

FB is probably safer, as they don't allow much freedom with their advertisers. Websites that give unrestricted banner ads are the dangerous ones. Those same websites that have random windows popping up can just as easily have your browser running their scripts.

>web browsers are vulnerable too
You mean they are an attack vector too

>unrestricted banner ads
yeah, thought so.
my local newspaper site is the worst for that kind of shit, look forward to the backlash in a weird way.

1) On your computer, open Chrome.
2) In the address bar at the top, enter chrome://flags/#enable-site-per-process and press Enter.
3) Next to "Strict site isolation," click Enable.

>Chrome will load each website in its own process. So, even if a site bypasses the same-origin policy, the extra security will help stop the site from stealing your data from another website.

>Site isolation will increase Chrome's memory use by approximately 10–20%.
Worth.

i think i saw an attack on a site "safe web tool ext.biz" it was making firefox go crazy

You shouldn't be using Facebook in the first place if you value your privacy.

JS is too insecure.

PHP and static page sites will rise again!

It was more a question about thieves steeling from me, I don't think FB are interested in that.
But tru, I am disconnected from all accounts and address's linked to things.

Don't even have anything to hide, nice to be in control though.

h-how?

We live in great times, don't we.

>ESR 52 not getting a patch
what a load of shit

JS was shitty and dangerous since day one, that's why I always hated it.

How would someone actually get affected? I mostly just visit Sup Forums, Youtube, my email, and that's really it.

just don't use your web browsers when you have internet turned on
dumbasses..

Client-side scripting was a mistake. I never understood how anybody could possibly think it was a good idea.

that's why you only get addons from the creator's git
your own fault

Is there something wrong with the supposed Windows 7 update for Meltdown? I put Download on it but nothing has seemed to have downloaded.

one of the perks of no js - no cpu usury

Fuck you.

...