@rossjanderson Professor Ross Anderson, FRS, FREng Dear friend and treasured long term campaigner for privacy and security, Professor of Security Engineering at Cambridge University and Edinburgh University, Lovelace Medal winner, has died suddenly at home in Cambridge.
Important note about cyber security and media interaction during active incidents:
When those who know the details can’t talk, those who can talk won’t know the details.
Dropping #Downfall, exploiting speculative forwarding of 'Gather' instruction to steal data from hardware registers. #MeltdownSequel
- Practical to exploit (POC/Demo)
- Defeat all isolation boundaries (OS, VM, SGX)
- Bypass all Meltdown/MDS mitigations.
downfall.page
Where @dotMudge makes an important point at @SummerC0n: real data on ATOs shows that SMS 2FA is fine for the vast majority of users. It prevented 100% of 3.3B automated password stuffing attacks, 96% of 12M bulk phishing, and even 76% of <10k targeted attacks seen over last year.