Reply to post: Remove high accuracy timers?

Thought you'd addressed those data-leaking Spectre holes on Linux? Guess again. The patches aren't perfect

Henry Wertz 1 Gold badge

Remove high accuracy timers?

Is it possible to just remove nanosecond-accuracy timing sources from Linux?

When they found (much to everyone's surprise and alarm) that both Firefox and Chrome had fast enough Javascript (JIT compiler compiling the Javascript into native code) to allow these timing effects INSIDE THE BROWSER, Firefox and Chrome simply removed access to nanosecond-accurate timers; they Javascript high-accuracy timer calls are now simply rounded off so they have like 1ms (1/000th of a second) accuracy. Could the same be applied to the Linux user-space itself? Maybe 1/10,000th of a second accuracy (since things like ping show 0.1ms timings)... there's a lot of wiggle room between that and the nanosecond (billionths of a second!) accuracy timers that exist now.

Is there a technical problem with this, like instruction counter or something that's hard to trap? Otherwise, this'd let most mitigations be left off with no ill side effects.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon


Biting the hand that feeds IT © 1998–2020