Close

Results 1 to 5 of 5
  1. #1
    DF VIP Member JonEp's Avatar
    Join Date
    Oct 2007
    Location
    uk
    Posts
    2,250
    Thanks
    1,112
    Thanked:        875
    Karma Level
    394

    Default Meltdown and Spectre vulnerabilities.

    Meltdown and Spectre are serious vulnerabilities built into the chip set of nearly all the computers including brand new ones on sale in the stores.

    I have been trying to get all my kit patched, Most windows 10 patched Meltdown with an update but not Spectre which is apparently more difficult to fix.

    My servers refused to take any of the MS patches despite running Server 2016.

    I know there was problems with the patch, AV and a required registry key needed to be present for the patch to run. In the end the only way I got Meltdown protection was a re image and ran updates before install anything else.

    You can check the status of a computer using the free InSpectre tool https://www.grc.com/inspectre.htm

    Has anyone else had any problems with this ?
    Last edited by JonEp; 7th May 2018 at 09:47 AM.

    Thanks to JonEp

    evilsatan (8th May 2018)  


  2. #2
    DF VIP Member c0axial's Avatar
    Join Date
    Feb 2002
    Location
    M44
    Posts
    1,493
    Thanks
    159
    Thanked:        188
    Karma Level
    381

    Default Re: Meltdown and Spectre vulnerabilities.

    2 Thanks given to c0axial

    evilsatan (8th May 2018),  JonEp (7th May 2018)  


  3. #3
    DF VIP Member JonEp's Avatar
    Join Date
    Oct 2007
    Location
    uk
    Posts
    2,250
    Thanks
    1,112
    Thanked:        875
    Karma Level
    394

    Default Re: Meltdown and Spectre vulnerabilities.

    The reality is almost every laptop, PC, server and phone on sale in the likes of PCWorld etc is vulnerable to the attacks out of the box, never mind legacy kit.

    I wonder what the fall out will be longterm. Medical records, credit history and criminal records are are all for the taking if the vulnerabilities are able to be exploited as there appears to be no real fix and no secure hardware to replace?
    Last edited by JonEp; 8th May 2018 at 02:12 AM.

  4. #4
    DF Super Moderator
    evilsatan's Avatar
    Join Date
    Jul 2004
    Location
    Essex
    Posts
    20,078
    Thanks
    1,105
    Thanked:        3,241
    Karma Level
    1540

    Default Re: Meltdown and Spectre vulnerabilities.

    The "fixes" can have double digit impact on performance, reported to mainly affect processors over 4 years old such as Intel Ivy Bridge and earlier so that alone will put off some from patching. From what I've read the fixes so far require a Windows patch, Intel ME firmware upgrade (if on your system) and BIOS updates so most normal users won't have installed anything other then the Windows patch and depending on their AV that may not even install, let alone older systems where the BIOS won't be updated by the manufacturer.


  5. #5
    DF Super Moderator
    evilsatan's Avatar
    Join Date
    Jul 2004
    Location
    Essex
    Posts
    20,078
    Thanks
    1,105
    Thanked:        3,241
    Karma Level
    1540

    Default Re: Meltdown and Spectre vulnerabilities.

    My laptop is fully patched with little-no speed penalty according to Jons tool (coaxials tool was blocked by Chrome and Eset - presumably a false positive if it runs code to dummy exploit the vulns), but my main PC (i5-2500k) needs a microcode patch and this will affect the speed. This PC still powers through everything like a trooper, it's overclocked so will read up about real-world performance as this was such a popular proc. I read the blurb and it seems that if the BIOS won't be updated by the board manufacturer then Microsoft have released some patches if the processors have had the microcode patched by Intel:
    https://support.microsoft.com/en-gb/...rocode-updates

    Thanks to evilsatan

    c0axial (8th May 2018)  


Similar Threads

  1. [NEW] WDMyCloud Multiple Vulnerabilities
    By c0axial in forum Home Audio/Video, Electronic Toys & Gadgets
    Replies: 0
    Last Post: 8th January 2018, 01:59 PM
  2. Trailer - SPECTRE
    By TJB in forum Movie Talk
    Replies: 0
    Last Post: 3rd October 2015, 08:11 AM
  3. Recommend a Windows Tool for checking your site for vulnerabilities
    By macmilm in forum Website Coding & Graphics
    Replies: 2
    Last Post: 17th October 2013, 04:17 PM
  4. good resource site to vulnerabilities
    By unclex in forum System Security
    Replies: 0
    Last Post: 22nd May 2006, 11:04 AM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •