barbos
Contributor
Nobody seems to want to create the thread about potentially biggest security vulnerability ever.
Just google "Meltdown Spectre" and feel scared.
Just google "Meltdown Spectre" and feel scared.
I'm not certain what to expect from this. I can imagine that Intel and AMD aren't exactly certain either. All I know if that the CIA and NSA are pissed that this was discovered.
If the CPU architecture used to frame his experience of the world is hackable, is he?I thought this was another "Is Donald Trump mentally ill?" thread.
Nobody posted explanations of what they are. Just in case you've been living under a rock[ent]hellip[/ent]
https://www.scientificamerican.com/...-expose-the-dark-side-of-superfast-computers/
Hardware fix is fairly trivial. So I expect fixed CPUs within a year. Problem with existing CPUs, because they can't be fixed with microcode update software would have to be written with these bugs in mind for decades now.One of these security flaws can't be fixed until a new generation of CPUs come out, which I expect will take years.
These boil down to privilege escalation attacks, so in systems where the hardware is owned and operated by the same entity that is running the software, the risks are small.
The real problem comes where processors are shared between unrelated entities - ie 'The Cloud'. If you are running software 'in the cloud', then you are vulnerable to attacks from any other user whose code is executed on the same hardware as yours - and you have no way of knowing who that might be.
A black-hat could open a normal cloud storage account with the same provider that hosts your business software, and use these vulnerabilities to pull credentials for your system (or other sensitive data) out of the host processor.
What about Linux? Does it offer better protection than Microsoft or Mac?
Having AMD cpu helps too. They are potentially affected but they don't have working exploit yet.Not good. Perhaps sticking to known safe sites, not opening dodgy links, etc, may help?
What I found:
Firefox users: update to 57.04
https://www.mozilla.org/en-US/firef...um=firefox-browser&utm_source=firefox-browser
Chromium or Chrome users:
https://support.google.com/chrome/answer/7623121
Linux mint:
https://blog.linuxmint.com/?p=3496
Ubuntu:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown