Page de-duplification is the new branch prediction.

We're watching modern computational optimization dissolve.

@literorrery it just lets you use known classes in very flexible ways.

i'm convinced every optimization allows for some attacker control or theft of information at this point.

@Fuego Wouldn't shock me. Lots of optimizations fall into a general pattern of short-circuiting what a system's been told to do with something else that provides the same output in less time through side effects. Those side effects have predictable impacts on the system that are invisible to the software, and thus can be leveraged to permit operations the software can't prevent.

@literorrery even apart from those side effects, optimizations are using some extra information to make these short circuit decisions so you can always infer the information. Further, you can sometimes control the short circuit if you can influence the extra information.

@Fuego So, what you're saying is that there are multiple avenues for an attacker to exploit the concept of optimization, because optimization represents the system interacting with stuff outside the software's control while reporting to the software that everything is normal. And any gap between what a system does and what it reports it did is a potential vector. And that's how we get Twitch Plays Amazon, or whatever the next TASBot masterpiece is.

Sign in to participate in the conversation
Awoo Space

Awoo.space is a Mastodon instance where members can rely on a team of moderators to help resolve conflict, and limits federation with other instances using a specific access list to minimize abuse.

While mature content is allowed here, we strongly believe in being able to choose to engage with content on your own terms, so please make sure to put mature and potentially sensitive content behind the CW feature with enough description that people know what it's about.

Before signing up, please read our community guidelines. While it's a very broad swath of topics it covers, please do your best! We believe that as long as you're putting forth genuine effort to limit harm you might cause – even if you haven't read the document – you'll be okay!