top | item 42856310

(no title)

junek | 1 year ago

OK, fun. What can we do to mitigate this until it gets patched?

discuss

order

omcnoe|1 year ago

Serious answer, don't use Safari. Use a browser that properly separates webpages into isolated processes so that this kind of cross-site read is not possible.

goldsteinq|1 year ago

There’re no other browsers on iPhone. Every iPhone browser is a reskin of Safari. They’re in theory supposed to allow other browsers in the EU, but AFAIK it has not happened yet.

amelius|1 year ago

Will that work? Isn't memory treated in a unified way between processes, at some point?

thijsr|1 year ago

From the FAQ:

> While FLOP has an actionable mitigation, implementing it requires patches from software vendors and cannot be done by users. Apple has communicated to us that they plan to address these issues in an upcoming security update, hence it is important to enable automatic updates and ensure that your devices are running the latest operating system and applications.

hmottestad|1 year ago

I wonder if Lockdown Mode would help?

dmitrygr|1 year ago

IIRC, it disables jit and webassembly, so i think yes