Keep your cool about Meltdown and Spectre

by Volker Weber

Linus is furious:

Any speculative indirect calls in the kernel can be tricked to execute any kernel code, which may allow side channel attacks that can leak arbitrary kernel data.
Why is this all done without any configuration options?

A *competent* CPU engineer would fix this by making sure speculation doesn't happen across protection domains. Maybe even a L1 I$ that is keyed by CPL.

Now calm the f&ck down. Most of the people who write about this stuff don't know what is going on. They are just copying from what others have already written.

Let's be frank here. There are basically two problems: one is with general CPU architecture and one is a weakness specific to Intel. A weakness does not mean that you have an exploit. What software vendors are doing right now is to mitigate the risk that somebody is going to come up with an exploit that works on their platform. These mitigations do not fix the weakness.

What does it all mean for you? Somebody has to run code on your machine to execute the exploit. If you are a cloud service provider in the IaaS space, you should be very worried. And they are. If you are looking at your own personal device, not so much. Operating systems and browsers are being fixed, and they will need to be fixed for a long time coming.

Most importantly, do not rush.

The mitigations will break things that are working now. One example is anti-virus software. I already have a first fix on my Windows 10 Surface Pro because there is no unsupported software on this machine, Microsoft requires AV vendors to write a registry key before they will offer this fix to your machine.

Do practice safer computing though. Don't install stuff from dubious sources.

Comments

You‘re simply the best ... Happy new year, Volker!

Stephan Perthes, 2018-01-05 14:40

An article explaining this topic and why Raspberry Pi is immune:
https://www.raspberrypi.org/blog/why-raspberry-pi-isnt-vulnerable-to-spectre-or-meltdown/

Karsten Lehmann, 2018-01-05 23:53

Wie schon des öfteren: Danke Volker.
Deine Kommentare bringen es immer wieder auf den Punkt und holen einen auf den Boden zurück.
Im konkreten Fall wird wieder einmal eine Sau von vielen Unwissenden durchs Dorf getrieben. Bei nüchterner Betrachtung ist sehr viel davon deutlich zu relativieren.

W.

Werner Hofer, 2018-01-06 00:23

Danke Karsten ;)

Mariano Kamp, 2018-01-06 09:09

Heise ist mir bislang nicht als Journal zum Sau-durchs-Dorf-treiben aufgefallen.

Habt ihr alle Javascript abgeschaltet? Benutzer ihr keine Browser?

Zitat Stiller im heutigen Heise Hintergrundartikel: "
nicht nur Clouds und Server sind betroffen, sondern auch die PCs zuhause, insbesondere gibt es auch Angriffsmöglichkeiten via Browser, "

Na dann, lasst euch ruhig Zeit mit den Updates...

Lucius Bobikiewicz, 2018-01-08 07:04

Recent comments

Nina Wittich on Is your phone hurting your dating life? at 20:43
Ragnar Schierholz on Bohemian Rhapsody at 16:22
Ragnar Schierholz on Be My Eyes :: What a wonderful idea at 16:04
Armin Grewe on Is your phone hurting your dating life? at 16:01
Jason Hook on Apple HomePod vs Sonos Beam :: Ein unfairer Vergleich at 15:26
Chris Frei on Android Security Updates at 14:59
Volker Weber on Ein super-schönes E-Bike at 14:36
Andreas Braukmann on Ein super-schönes E-Bike at 14:24
Nina Wittich on Is your phone hurting your dating life? at 13:36
Horia Stanescu on Be My Eyes :: What a wonderful idea at 12:00
Alexander Wrede on Is your phone hurting your dating life? at 11:45
Hubert Stettner on Be My Eyes :: What a wonderful idea at 10:33
Ingo Seifert on Eine einfache Frage at 10:33
Johannes Matzke on Is your phone hurting your dating life? at 09:43
Christian Tillmanns on Is your phone hurting your dating life? at 08:05
Bodo Menke on Ein super-schönes E-Bike at 05:52
Stephan Perthes on Is your phone hurting your dating life? at 23:23
Lucius Bobikiewicz on Is your phone hurting your dating life? at 23:12
Volker Weber on Ein super-schönes E-Bike at 22:21
Volker Weber on Is your phone hurting your dating life? at 22:09
Axel Seifried on Is your phone hurting your dating life? at 21:01
Armin Grewe on Is your phone hurting your dating life? at 20:54
Craig Wiseman on Is your phone hurting your dating life? at 19:47
Christoph-Alexander Dettmann on Eine einfache Frage at 16:36
Dirk Rose on Ein super-schönes E-Bike at 16:02

Ceci n'est pas un blog

I explain difficult concepts in simple ways. For free, and for money. Clue procurement and bullshit detection.

vowe

Contact
Publications
Stuff that works
Amazon Wish List
Frequently Asked Questions

rss feed  twitter amazon

Local time is 00:04

visitors.gif

buy me coffee