Meltdown of CPUs: Spectre is hunting you!

in #news7 years ago

More information is out on yesterday’s vulnerabilities of CPUs. Yes, you read that right, it’s plural. There are actually 2 vulnerabilities, named Meltdown and Spectre, that can potentially be used in 4 different exploits.

Which systems are affected by Meltdown?
Desktop, Laptop, and Cloud computers may be affected by Meltdown. More technically, every Intel processor which implements out-of-order execution is potentially affected, which is effectively every processor since 1995 (except Intel Itanium and Intel Atom before 2013). We successfully tested Meltdown on Intel processor generations released as early as 2011. Currently, we have only verified Meltdown on Intel processors. At the moment, it is unclear whether ARM and AMD processors are also affected by Meltdown.

Which systems are affected by Spectre?
Almost every system is affected by Spectre: Desktops, Laptops, Cloud Servers, as well as Smartphones. More specifically, all modern processors capable of keeping many instructions in flight are potentially vulnerable. In particular, we have verified Spectre on Intel, AMD, and ARM processors.

Which cloud providers are affected by Meltdown?
Cloud providers which use Intel CPUs and Xen PV as virtualization without having patches applied. Furthermore, cloud providers without real hardware virtualization, relying on containers that share one kernel, such as Docker, LXC, or OpenVZ are affected.

What is the difference between Meltdown and Spectre?
Meltdown breaks the mechanism that keeps applications from accessing arbitrary system memory. Consequently, applications can access system memory. Spectre tricks other applications into accessing arbitrary locations in their memory. Both attacks use side channels to obtain the information from the accessed memory location.

Source of the quotes, from the security researcher’s website: https://spectreattack.com/
Project Zero technical explanation

Sort:  

very nice post.

Thank you so much for useful post

damn creepy picture

hope all intel drivers get updated soon.
And hope all cloud services I use update their shit! 🤣

there will be millions of non-updated computers...

I scared 😅

Coin Marketplace

STEEM 0.15
TRX 0.15
JST 0.028
BTC 53948.70
ETH 2245.46
USDT 1.00
SBD 2.29