It seems to me, and I have stated this before, sandboxers do not care what other asynchronously do in the instruction cache. Sandboxers secure the core, are spectre compatible among themselves. We should b able to meet the spectre spec within the applications, as long as we have a kernel function to run secret keys. All we need is a kernel memory observable only by the kernel function.
No comments:
Post a Comment