Page 1 of 2 12 LastLast
Results 1 to 10 of 17
Like Tree4Likes

Thread: Vulnerabilities: Spectre and Meltdown

  1. #1
    C-57D VincentVega's Avatar
    Join Date
    Mar 2006
    Location
    Altair IV
    Posts
    45,885

    Vulnerabilities: Spectre and Meltdown

    So, as all of you have probably heard by now, many CPUs built over the last two decades are susceptible to some nasty flaws that can compromise security.

    There are all kinds of reports and articles on these problems, and I will leave one here:

    https://www.csoonline.com/article/32...s-at-risk.html

    I can't describe it any better myself. What should you do? Get all of the latest BIOS and O/S updates that are available to you. Luckily for me, I use a professional-grade computer and had BIOS, microcode, and O/S updates pretty quickly from the manufacturer. Personally, I am not sure if that is the end of it, or if these are just temporary patches with more to come, so I am keeping an eye out.

    What's the big deal? Any and all solutions to this result in a performance penalty. For people like me that routinely abuse their computer, it definitely hurts. I think I can already feel the slowdown in my virtual machines (from what I understand, I/O is especially harmed by the patches). I run multiple drives, the old-school O/S SSD with spinning platter secondary. I made work buy me a 1TB SSD to replace the secondary, hoping that will offset things some.

    Anyway, stay updated out there.

  2. #2
    Time 2 Play DigitalDD's Avatar
    Join Date
    May 2003
    Location
    The Land of OZ
    Posts
    6,573

    Re: Vulnerabilities: Spectre and Meltdown

    I think I posted the XKCD comic on this issue before but it probably fits best here..



    its also good to point out those vulnerabilities to the Intel Management Engine that have cropped up over the past 2 years are also fixed with BIOS and firmware updates

  3. #3
    C-57D VincentVega's Avatar
    Join Date
    Mar 2006
    Location
    Altair IV
    Posts
    45,885

    Re: Vulnerabilities: Spectre and Meltdown

    Yeah, I noticed I got updates to ME as well. Good point

  4. #4
    Time 2 Play DigitalDD's Avatar
    Join Date
    May 2003
    Location
    The Land of OZ
    Posts
    6,573

    Re: Vulnerabilities: Spectre and Meltdown

    Get ready for round 2. The new ones are called Skyfall and Solace.

    Following the recent release of the Meltdown and Spectre vulnerabilities, CVE-2017-5175, CVE-2017-5753 and CVE-2017-5754, there has been considerable speculation as to whether all the issues described can be fully mitigated.

    Skyfall and Solace are two speculative attacks based on the work highlighted by Meltdown and Spectre.

    Full details are still under embargo and will be published soon when chip manufacturers and Operating System vendors have prepared patches.
    https://gizmodo.com/intel-claims-90-...atc-1822192075
    VincentVega likes this.

  5. #5
    C-57D VincentVega's Avatar
    Join Date
    Mar 2006
    Location
    Altair IV
    Posts
    45,885

    Re: Vulnerabilities: Spectre and Meltdown

    Eventually, I guess my modern processor will about keep up with a DX4-100

  6. #6
    Jack pwns my FACE FuzzyLogik's Avatar
    Join Date
    Jan 2006
    Location
    Well above sea level.
    Posts
    27,083

    Re: Vulnerabilities: Spectre and Meltdown

    From what I understand these are all band-aid fixes. The Microcode helps but that doesn't change the underlying CPU architecture. I believe they were designed this way very specifically (to make CPU processes faster) but...unfortunately somebody just figured out how to make it do stuff never intended (or likely thought about). heh! So, it might really only be fixed when you grab a new CPU that has been developed after this vulnerability was exposed :P

    Anyways - there's a program running around now that can help check your computer (not 100% perfect though) but might be worth a shot to take a look at to see if you're a bit more prepared:
    http://www.guru3d.com/news-story/download-inspectre-meltdown-and-spectre-check-tool.html
    VincentVega likes this.
    "Good...Bad...I'm the guy with the gun."

  7. #7
    Time 2 Play DigitalDD's Avatar
    Join Date
    May 2003
    Location
    The Land of OZ
    Posts
    6,573

    Re: Vulnerabilities: Spectre and Meltdown

    FYI: guru3d pointed here: https://www.grc.com/inspectre.htm so get it direct from the source. The tool also has options to disable protection if you are running into performance issues (older CPUs), most Windows version older than Windows 10 1709 (the creators update) will fail most checks, and if your motherboard has no bios updates for you or you are running older chips which Intel did not release any updates for you'll fail the Spectre tests.

    Intel is telling people to hold off on the BIOS updates, seems a few vendors have pulled their most recent BIOS updates too.
    https://newsroom.intel.com/news/root...-and-partners/

    https://www.helpnetsecurity.com/2018...spectre-fixes/

  8. #8
    C-57D VincentVega's Avatar
    Join Date
    Mar 2006
    Location
    Altair IV
    Posts
    45,885

    Re: Vulnerabilities: Spectre and Meltdown

    Well, the rollout sure is going smoothly

  9. #9
    Jack pwns my FACE FuzzyLogik's Avatar
    Join Date
    Jan 2006
    Location
    Well above sea level.
    Posts
    27,083

    Re: Vulnerabilities: Spectre and Meltdown

    And information about an Intel ceo sold $25m worth of stock on the day the news was released. lol

    Intel is also reportedly going to release new CPU's later this year that don't have the problem.... soooo... just happened to not have the problem or they've been in the works for a very long time (thus they knew about it)... i mean, it takes a while to build a cpu from scratch...
    "Good...Bad...I'm the guy with the gun."

  10. #10
    C-57D VincentVega's Avatar
    Join Date
    Mar 2006
    Location
    Altair IV
    Posts
    45,885

    Re: Vulnerabilities: Spectre and Meltdown

    They've known about this since last year at least. I'm due for a new work computer, so I will wait until the new hardware is available

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Advertise:
Ads@StrafeRight.com

Terms of Service || Privacy & DMCA Policies || About Us
Powered by vBulletin® Version 4.2.2
Copyright © 2018 vBulletin Solutions, Inc. All rights reserved.
Search Engine Friendly URLs by vBSEO 3.6.0

All times are GMT -4. The time now is 12:19 PM.
Design by DanFortH