Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No. Packages would not need to be installed as root. Additionally, many possible ways to use the exploit in GP could run as unprivileged users.


Wouldn't the package need to be executed as root, though? Or does spectre/meltdown not require privileged access?


No, that's the entire point. They need almost nothing at all but the ability to run code fast in a loop with memory calls. The entire point is that they bypass privilege checks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: