New Spectre-like CPU vulnerability discovered

Microsoft Windows is patched for Meltdown and Spectre, iirc since May/June if your supported OS is up to date. Several motherboard manufacturers also released firmware for patching.
MS patched Windows many times and destabilized many systems on the occasion. No, MS has no cure against Spectre/Meltdown, there are only workarounds decreasing probability. And Windows is running slower.
 
Oh for peet's sake when are we going to stop with this sensationalism. CPU exploits are nothing new but you need access to a system first. Once you're there you can execute whatever you want anyway. This is like drilling a hole in a bathtub when you can simply pull the plug.

Yes, and? How secure are you when you are connected to a LAN, WAN or the internet?

Many believe that they are secured, they believe that they are without error, they have AV, they have anti-malware and whatnot.

Many are unaware whether there is an open window, an opportunity to exploit or attack, many don’t know what a zero-day is.

It is best to have these articles published, to make people (and users) aware.

I honestly don't know why you regard awareness as sensationalism.
 
MS patched Windows many times and destabilized many systems on the occasion. No, MS has no cure against Spectre/Meltdown, there are only workarounds decreasing probability. And Windows is running slower.

They and others are patching accordingly. However, I don't want to be the Chief Security Officer of a cloud infrastructure whilst these hardware level exploits are looming about...
 
Yes, and? How secure are you when you are connected to a LAN, WAN or the internet?

Many believe that they are secured, they believe that they are without error, they have AV, they have anti-malware and whatnot.

Many are unaware whether there is an open window, an opportunity to exploit or attack, many don’t know what a zero-day is.

It is best to have these articles published, to make people (and users) aware.

I honestly don't know why you regard awareness as sensationalism.
Then publish articles on those issues. Exactly how many exploits have there been employing this? None because it's not needed once you've found an exploit that enables you to use it. This is most likely some dodgy person releasing this info in time for shorting Intel/AMD stocks. Meanwhile uninformed people are reading the headlines and running around like headless chickens thinking they're now vulnerable 24/7 with nothing they can do about it because few articles actually state that systems are still just as secure as before.
 
Then publish articles on those issues. Exactly how many exploits have there been employing this? None because it's not needed once you've found an exploit that enables you to use it. This is most likely some dodgy person releasing this info in time for shorting Intel/AMD stocks. Meanwhile uninformed people are reading the headlines and running around like headless chickens thinking they're now vulnerable 24/7 with nothing they can do about it because few articles actually state that systems are still just as secure as before.
Hats off to Snowden, please. Western systems are perceived secure as long backdoors developed by MOSAD are not known yet. When these backdoors are unveiled, they are marginalized. On the other side some China brands like Huawei are not allowed to be deployed in US even there is no proof for vulnerability.
 
Oh for peet's sake when are we going to stop with this sensationalism. CPU exploits are nothing new but you need access to a system first. Once you're there you can execute whatever you want anyway. This is like drilling a hole in a bathtub when you can simply pull the plug.

It goes beyond this. With the original spectre exploit, you could potentially go into a VM your rented somewhere, and exploit your way to another VM owned by somebody else, as long as they share the same physical CPU.
It's by no means easy, but it's a pretty damn big deal.
 
Top
Sign up to the MyBroadband newsletter
X