Researchers discover vulnerabilities, dubbed Meltdown and Spectre, that let hackers steal data from running apps on most Intel chips, some ARM and AMD chips
Zack Whittaker / ZDNet :
ZDNet Zack Whittaker
Related Coverage
- Intel Says Range of Chips Vulnerable to Hack, Denies ‘Bug’ Bloomberg
- Microsoft issues an emergency fix for Windows 10 to address processor bug BetaNews
- Intel CPU Bug Performance Loss Reports Are Premature Tom's Hardware
- View article Phoronix
- View article CNET
- Google reveals trio of speculative execution flaws, says AMD affected ZDNet
- Massive Security Flaw Could Affect Almost Every Computer NBC Bay Area
- View article CNNMoney
- Meltdown and Spectre CPU flaws threaten PCs, phones and servers Engadget
- View article Quartz
- Some notes on Meltdown/Spectre Errata Security
- heads up: Fix for intel hardware bug will lead to performance regressions PostgreSQL news
- Rush to fix ‘serious’ computer chip flaws BBC
- Intel, ARM, and AMD processors all impacted by new Meltdown and Spectre exploits iMore
- Microsoft to release emergency Windows Update to address Intel, AMD processors security concerns On MSFT
- Microsoft just issued a fix for that big Intel processor vulnerability Mashable
- Meltdown and Spectre: Chip hack gets a name, emergency patch and official statement from Microsoft MSPoweruser
- New details emerge on severe processor flaw affecting Windows, macOS, and Linux The Verge
- Intel Claims Security Flaw Also Impacts Non-Intel Chips, Exploits Can't Corrupt, Modify or Delete Data [Updated] MacRumors
Discussion
-
Phoronix
Michael Larabel
on x
Linux Gaming Performance Doesn't Appear Affected By The x86 PTI Work
-
@k8em0
Katie Moussouris
on x
Today, infosec Twitter (re)learned the following are hard: 1. Fixing design bugs in chips 2. Multiparty Coordinated Vuln Disclosure 3. Differentiating authoritative fact vs speculative hype 4. Holding embargoes 5. Naming things so they don't sound goofy #Meltdown #Spectre pic.twi…
-
@internetofs**t
Internet of S**t
on x
Apple: we're slowing down processors cause your battery might be bad Intel: pic.twitter.com/qBR1MpcNXz
-
@nicoleperlroth
Nicole Perlroth
on x
2. Christmas didn't come for the computer security industry this year. A critical design flaw in virtually all microprocessors allows attackers to dump the entire memory contents off of a machine/mobile device/PC/cloud server etc.
-
@swiftonsecurity
@swiftonsecurity
on x
The CPU issues today are immensely interesting and consequential, but I hesitate hyping this to the public. Same as always: Make sure autoupdates are on and working. People have been working on addressing this for six months. It's not a surprise to the people defending you.
-
@nicoleperlroth
Nicole Perlroth
on x
6) Now, Meltdown and Spectre, show that it is possible for attackers to exploit these design flaws to access the entire memory contents of a machine. The most visceral attack scenario is an attacker who rents 5 minutes of time from an Amazon/Google/Microsoft cloud server and
-
@nicoleperlroth
Nicole Perlroth
on x
17. Google says its systems have been updated to defend against Meltdown https://security.googleblog.com/ ... . Microsoft issued an emergency update today. Amazon said it protected AWS customers running Amazon's tailored Linux version, and would roll out the MSFT patch for other …
-
@gossithedog
Kevin Beaumont
on x
If you're a business relying on virtualisation security for boundaries, eg you're a cloud provider, drop everything and patch. If you're a regular business, follow your regular patching process when patches are available. If you're a consumer, let OS apply usual patches.
-
@nicoleperlroth
Nicole Perlroth
on x
15. The flaws were originally discovered last June by a researcher at Google Project Zero (shout out @ Jann Horn) and then separately by Paul Kocher and a crew of highly impressive researchers at Rambus and academic institutions. Originally public disclosure was set for next week
-
@zackwhittaker
Zack Whittaker
on x
This is a crazy bad bug, affecting two-decades worth of Intel chips and some ARM chips, that can let an attacker steal data from the memory of running apps, such as data from password managers, browsers, emails, and photos and documents. http://zd.net/2lSEtKF pic.twitter.com/5YEU…
-
@erratarob
@erratarob
on x
So the #meldown steps are: 1. Load a byte of memory from kernel. This crashes. 2. Use that byte to load one of 256 cache-lines. This happens before the crash is registered, so while the data is discarded, the data is still cached. 3. Measure which of the 256 cache-lines are fast
-
@aallan
Alasdair Allan
on x
So that's proof of concept for the #IntelBug. That's potentially game over for every Intel processor manufactured in the last 10 years, slowdowns could be between 5 and 30% after patching, http://www.theverge.com/.... http://twitter.com/...
-
@tomwarren
Tom Warren
on x
It constantly feels like we're edging closer to a tech doomsday scenario. The Wi-Fi attack vulnerability was less than 3 months ago, and now we have two major flaws in processors. What's next?
-
@kimzetter
Kim Zetter
on x
For those looking for basic info about whether they're affected by the Intel bug, scroll to bottom of this page put together by the researchers who discovered it - https://meltdownattack.com/ pic.twitter.com/JTRykdSbjv
-
@mattblaze
Matt Blaze
on x
Meltdown and Spectre are serious problems. I look forward to seeing the innovative ways in which their impact will be both wildly exaggerated and foolishly dismissed over the coming weeks.
-
@pwnallthethings
@pwnallthethings
on x
The Intel bug is a really cool bug that took a lot of work to find, exploit and fix, but most folks don't need to do anything other than install OS updates when they arrive.
-
@nicoleperlroth
Nicole Perlroth
on x
4. We're dealing with two serious threats. The first is isolated to #IntelChips, has been dubbed Meltdown, and affects virtually all Intel microprocessors. The patch, called KAISER, will slow performance speeds of processors by as much as 30 percent.
-
@martinsfp
Martin Bryant
on x
Well this is a hot mess. http://twitter.com/...
-
@tomwarren
Tom Warren
on x
Google was planning to disclose next week with the rest of the industry, but “existing public reports and growing speculation in the press and security research community about the issue” pushed them to publish today.
-
@internetofs**t
Internet of S**t
on x
Every Intel processor since 1995 has a critical security flaw. Good news: - it's kinda sorta patched Bad news: - the patch slows down your machine - you can't avoid the patch http://www.zdnet.com/...
-
@ow
@ow
on x
Oof. Critical Intel bug affects processors all the way back to 1995. Patches out today. http://www.zdnet.com/...