Keyboard Shortcuts

Keyboard shortcuts are available for common actions and site navigation.

Skip to content
  • Home Home Home, current page.
  • About

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
IanColdwater's profile
Ian Coldwater 👻🌿✨
Ian Coldwater 👻🌿✨
Ian Coldwater  👻 🌿 ✨
@IanColdwater

Tweets

Ian Coldwater  👻 🌿 ✨

@IanColdwater

Kubernetes breaker, public speaker, @ladiesctfcircle organizer, former teen mom. Tweets in haiku. Opinions my own

South Canada
pronoun.is/they
Joined March 2016

Tweets

  • © 2019 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

  • In this conversation
    Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

    Having trouble keeping all the CPU vulns that dropped today straight? Understandable. There's a lot. This is going to be a thread.

    1:22 PM - 14 May 2019
    • 1,274 Retweets
    • 2,107 Likes
    • You Mattia Campana bmm Kamen Bundev Dimiter Stanev Goupil Calle Englund Matt Cheung Christopher 'Chief' Najewicz
    48 replies 1,274 retweets 2,107 likes
      1. New conversation
      2. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

        Multiple teams of security researchers around the world independently discovered these vulns and have been loosely coordinating to work on these disclosures together. This process was quite long; it took over a year. Four different whitepapers dropped today.

        1 reply 23 retweets 155 likes
        Show this thread
      3. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

        https://mdsattacks.com  goes over two attacks: RIDL and Fallout. These attacks exploit Microarchitectural Data Sampling (MDS) side channel vulnerabilities in Intel CPUs. RIDL paper here: https://mdsattacks.com/files/ridl.pdf  Fallout paper here: https://mdsattacks.com/files/fallout.pdf …

        2 replies 35 retweets 153 likes
        Show this thread
      4. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

        The http://mdsattacks.com  site also contains a FAQ, videos of exploit demos, a really cool interactive guide to speculative execution attacks (seriously, go play with it) and handy tools to check if your system is vulnerable (links in next tweet).

        1 reply 23 retweets 149 likes
        Show this thread
      5. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

        Verify whether your system is vulnerable to the new MDS CPU attacks with these tools from the RIDL team! Windows: https://mdsattacks.com/files/mdstool-win.zip … Linux: https://mdsattacks.com/files/mdstool-linux.zip … GitHub:https://github.com/vusec/ridl 

        3 replies 50 retweets 181 likes
        Show this thread
      6. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

        Also dropped today from TU Graz was #ZombieLoad. ZombieLoad uncovers a novel Meltdown-type effect in previously unexplored fill-buffer logic. https://zombieload.com  is dedicated to this vuln, w/ FAQ. Paper here: https://zombieloadattack.com/zombieload.pdf  Exploit POC here:https://github.com/IAIK/ZombieLoad 

        2 replies 39 retweets 135 likes
        Show this thread
      7. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

        #ZombieLoad is no joke. It has multiple practical attack scenarios across CPU privilege rings, OS processes, VMs, and SGX enclaves. Disabling hyperthreading is the only possible workaround to prevent this extremely powerful attack on current processors.

        3 replies 47 retweets 175 likes
        Show this thread
      8. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 18h18 hours ago

        But wait, there's more!

        4 replies 1 retweet 68 likes
        Show this thread
      9. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 17h17 hours ago

        https://cpu.fail  contains links to the other CPU vulns, and one more whitepaper, which isn't anywhere else. This paper on store-to-leak forwarding shows that Meltdown-style attacks can still work on recent CPUs that aren't vulnerable to Meltdown. https://cpu.fail/store-to-leak.pdf …

        2 replies 45 retweets 159 likes
        Show this thread
      10. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 17h17 hours ago

        These attacks affect all modern Intel CPUs in servers, desktops and laptops, including the latest 9th-gen processors that contain Meltdown mitigations. 9th-gen CPUs are actually more vulnerable to some of these attacks than older-gen hardware. AMD and ARM CPUs are not affected.

        6 replies 52 retweets 163 likes
        Show this thread
      11. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 16h16 hours ago

        Blog post from Red Hat with technical detail on MDS vulns (with long deep-dive video): https://www.redhat.com/en/blog/understanding-mds-vulnerability-what-it-why-it-works-and-how-mitigate-it … Blog post with technical detail on #ZombieLoad: https://www.cyberus-technology.de/posts/2019-05-14-zombieload.html … Intel advisory:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html …

        8 replies 33 retweets 122 likes
        Show this thread
      12. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 2h2 hours ago

        Red Hat advisory on new CPU vulnerabilities, with CVE numbers CVE-2018-12130 CVE-2018-12126 CVE-2018-12127 CVE-2019-11091https://access.redhat.com/security/vulnerabilities/mds …

        0 replies 9 retweets 21 likes
        Show this thread
      13. End of conversation
      1. New conversation
      2. Tom Clement‏ @Tom_Clement 17h17 hours ago
        Replying to @IanColdwater

        Haha, no haiku when shit hits the fan? 🤭

        1 reply 0 retweets 28 likes
      3. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 16h16 hours ago
        Replying to @Tom_Clement

        Technical detail is hard to write in haiku Sorry not sorry

        4 replies 19 retweets 278 likes
      4. CornAnon is notdan and may not be notdan‏ @AnonCorn 16h16 hours ago
        Replying to @IanColdwater @Tom_Clement

        When the form obstructs It is time to move freely Form follows function

        1 reply 0 retweets 39 likes
      5. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 16h16 hours ago
        Replying to @AnonCorn @Tom_Clement

        "Speculative execution" alone is too many syllables to fit in a haiku 😫

        8 replies 0 retweets 36 likes
      6. Jason Frey‏ @Fryguy9 2h2 hours ago
        Replying to @IanColdwater @AnonCorn @Tom_Clement

        CVEs abound Speculative execution Off-by-one errors

        1 reply 0 retweets 2 likes
      7. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 2h2 hours ago
        Replying to @Fryguy9 @AnonCorn @Tom_Clement

        Hardest problem in computer science, and also haiku poetry

        0 replies 0 retweets 3 likes
      8. End of conversation
      1. New conversation
      2. Pepijn de Vos‏ @pepijndevos 10h10 hours ago
        Replying to @IanColdwater

        Is AMD actually better, or just less researched? Almost seems like you just can't have speculative execution.

        2 replies 0 retweets 10 likes
      3. Ian Coldwater  👻 🌿 ✨‏ @IanColdwater 10h10 hours ago
        Replying to @pepijndevos

        There are architectural decisions specific to Intel that make their CPUs vulnerable to a lot of Meltdown-style attacks like these, but AMD isn't immune to speculative execution attacks such as Spectre.

        1 reply 0 retweets 17 likes
      4. Jeff Maxwell‏ @jeffreymaxwell 8h8 hours ago
        Replying to @IanColdwater @pepijndevos

        Seems like a sizable portion of Intel's performance edge over AMD was based on leveraging insecure features.

        1 reply 0 retweets 14 likes
      5. Misel‏ @Misel 8h8 hours ago
        Replying to @jeffreymaxwell @IanColdwater @pepijndevos

        The fact that AMD marketing does not "milk" these advantages suggests that AMDs security was more of a side effect of their design choices rather than an explicit goal.

        2 replies 1 retweet 17 likes
      6. Matt Hawkins‏ @hawko2600 4h4 hours ago
        Replying to @Misel @jeffreymaxwell and

        Or, they're just good people who find publically ridiculing your competition on security vulnerabilities unconscionably bad behaviour that can only invite trouble

        3 replies 0 retweets 5 likes
      7. Pepijn de Vos‏ @pepijndevos 3h3 hours ago
        Replying to @hawko2600 @Misel and

        Big corporations are never good people. At best careful to not paint a target on their back, at worst knowingly withholding vulnerabilities.

        1 reply 0 retweets 9 likes
      8. Jeff Maxwell‏ @jeffreymaxwell 1h1 hour ago
        Replying to @pepijndevos @hawko2600 @Misel

        pic.twitter.com/1v4LbpVqir

        1 reply 0 retweets 0 likes
      9. 1 more reply

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2019 Twitter
      • About
      • Help Center
      • Terms
      • Privacy policy
      • Cookies
      • Ads info