⛔ Prevent Meltdown and Spectre Security Flaws From Affecting Your Computer

in #technology7 years ago (edited)

Introduction
This post is meant to be an information and warning for users who are specifically having Intel as processorRefer to this and latest windows installed. However, this does not limit to possibilities for Apple and AMD users. Always take my information with a grain of salt and if you have nothing to hide, zero bank account, don’t give a shit about your privacy, and ready to be spied on 24/7 then sure, ignore this post at its finest. If your computer CPU is behaving very unusual then you might want to read this futher.

ERROR 8004001.jpg

Meltdown, Spectre and its effects

Meltdown and Spectre are a computer vulnerabilities which allows attackerred: hackerto leak information if it’s exploited. This newly discovered security issues were discovered by the team from google project zero. They find out that the CPU data cache can be abused to efficiently leak information out of miss-speculated execution Readmore. It is known to affect modern processor such as Intel, AMD, ARM and according to the the recent news, apple has confirmed that their products are affected by this vulnerabilities.

Here is the technical term to understand the Meltdown and Spectre

1
Spectre attacks involve inducing a victim to specula-tively perform operations that would not occur during
correct program execution and which leak the victim’s confidential information via a side channel to the
adversary.

2
Meltdown exploits side effects of out-of-order execution on modern processors to read arbitrary kernel-memory locations including personal data and passwords. Out-of-orderexecution is an indispensable performance feature andpresent in a wide range of modern processors. The attack is independent of the operating system, and it does notrely on any software vulnerabilities.

Meltdown and Spectre in 3 minutes

Additionally, according to Spectre publication, The attack also works on non-intel processors, including AMD and ARM processors and has been verified attacking the AMD Ryzen CPUs.

A worse case if it is exploited

I am not trying to spoke you or anything but this is something you have to be aware. You can have your finacial data password stolen such as : online banking, e-mail and online shopping, possibilities endless. Next, your social media and similar password also personal data - information on your device could be encrypted for ransom. I believe that people on steemit wants to protect their cryptofolio, so this knowledge is important, unless you don't give a shit about it.

In short, Metldown and Spectre vulnerabilities is like having a code to unlock your door, but your door is open and the code is written on the front door and the door knob. And obviously it’s pointless to have a password to protect your privacy or whatever you want to protect. This is a main concern especially for people who trade at exchanges and who always opt for saving the password. Thus, I also recommend if you trade at a large scale, having a hard wallet is a consideration.

Simple steps to prevent your computer from further exploit

Technically, we're all affected but anyway to prevent further exploit since there's no report on this case here is what you can do about it.

  • Update your browser that comes with meltdown and spectre prevention.

If you are using Firefox make sure it's V57:04. If you are unsure check your firefox

about:config?filter=privacy.firstparty.isolate Double-click on privacy.firstparty.isolate to set the preference to true.

If you're on chrome then use this : chrome://flags/#enable-site-per-process Next to 'Strict site isolation', click Enable then relaunch browser.

  • Install Noscript and ad blocker (optional)

  • Update and patch your computer as illustration: I was running windows10

Go to update system setting and select update, make sure it's windows10update-kb4056892. At the moment I am running lubuntu so I don't give a shit. They have released a patch but I am too bothered to check them.

  • Make sure your CPU is working normally.

  • Regularly check your update settings and perform the task right away.

References


Sort:  

eeeeh...
What you mentioned the other day... people walking with some nasty program/malware on their USB sticks ready to seed them...
Bleh.
I didn't know this is so serious...

@aschatria, oh that's different story but this was just 3 days ago where they found those security vulnerabilities. My case was different story so knowing this, I was heavily guarded and it sucks losing everything.

Very informative and helpful!

Thanks to @djlethalskillz, this post was resteemed and highlighted in The Daily Sneak.

Thank you for your efforts to create quality content!

@sneakyninja,

Much thanks and also kudos to my bro @djlethalskillz :)
Thank you for spreading the awareness and the word out there!

Holy crap,I didn't know anything about this ,so thank you for sharing! I wish I could go Linux full-time but there are programs that I depend on, unfortunately.

@irreverent-dan I was using lubuntu the whole time but I am having Intel installed so I don't think it was good either. I am just going to stay tuned for further update since I don't think there's a really safe way to get out of this flaw ( unless you're willing to disconnect from the internet). There's no report on this flaw exploit but uh advanced prevention is a good idea.

I didn’t even think about updating my browser to help with this, so thank you for the tip to stay safe :).

a very rushy post I wrote though it's been happening since 3rd january but I think the awareness is still less and emergency updates are being released. I think that browser is more vulnerable since usually users opt for save password for an easy login.

Lol...you just saved my day. I will follow your directions to avoid the stress.

@mrxplicit sure thing :) and I've been continuously updating the post. I am trying to cover more information and references to read but like I know skim everything and just go to the steps is the easiest thing a user can do.

Thank you for sharing this, though I don't care about privacy 😂

Stay passionate, stay blessed !

Yeah heard about this huge flaw. Updated my windows immediately.

@howtostartablog took me a while to update my windows but now it's updated. Not necessarily safe but prevention has been made.

Amazing info and updates, i will follow the instruction Kudos! Upvoted and Resteemed to help spread the message out, keep it up !

@djlethalskillz, thank you brother :D hope your followers can read this !

I had no idea about this... But I'm not sure how to check if my CPU is behaving normal?

@kerlund if you are running windows like myself it's easy to check through task manager. It should show you something like this. I run a pretty old laptop :D and since it was wiped out couple days ago I don't have too many software installed. Having read from various sources, the current patch will slow down your CPU about 25%.

Capture.PNG

Thank you! I recently found out my computer got attacked by hackers so I will definitely be more careful!

Coin Marketplace

STEEM 0.16
TRX 0.16
JST 0.030
BTC 57307.38
ETH 2434.94
USDT 1.00
SBD 2.32