From: Amel Date: 2020-12-01T17:05:09+01:00 Subject: [ruby-core:101181] Re: Spectre Mitigations Trusted code can potentially be vulnerable to Spectre attacks, as branch prediction on modern processors occurs in all code where there are branches. The question is how can I stop security critical branches from being executed out-of-order and thus protect my trusted code? Amel On 01.12.20 16:44, Chris Seaton wrote: > I wouldn���t recommend using Ruby to run in-process untrusted code in the first place. Are people doing that? > > Chris > >> On 1 Dec 2020, at 15:32, Amel wrote: >> >> Hi there! >> >> I've already asked this question in the ruby-talk mailing list and it was hinted at that ruby-core could be the better place to ask, so here's my question. >> >> Are there any mitigations in Ruby for the Spectre security vulnerability? Maybe in the interpreter itself or a function which is similar to the lfence-instruction. >> If there isn't, are there any mitigations planned? >> >> Cheers, >> >> Amel >> >> >> Unsubscribe: >> > > Unsubscribe: > Unsubscribe: