Recently, four different teams of
researchers found significant vulnerabilities which affect nearly all
computers, Windows and Macs, iPhone, and iPad. This gap has to do with what is
called "speculative execution" (Peter Bright, 2018) by the processor
within the machine. What speculative execution is the processor trying to
"maximize performance, they try to execute instructions even before it is
certain that those instructions need to be executed. (Peter Bright, 2018)" How this
present a security gap is it allows potentially malicious code to see these
instructions before they are needed. Additionally, the code can bypass any
security checks due to the fact it is trying to queue the instructions before
it really needs to execute it.
As mentioned before, this
vulnerability has affected all major computer and smartphone companies. They
have all responded in various ways. Intel which is the company most impacted by
this discovery has recommended operations system fix in order to remediate this
situation. Microsoft has a variety of fixes since this was disclosed to them
back in the fall of 2017, which are out or will be coming out soon. Apple has
announced all current machines and devices as long as they are up to date on
the patches are safe.
To be clear, I selected some of the
more recognizable brand names who are having to deal with this situation. This
is affecting everyone. Major processors manufacturers such AMD and ARM, who
compete with Intel, are having to figure this out as well. Two well-written
articles I would recommend are "Meltdown and Spectre: Here’s what Intel,
Apple, Microsoft, others are doing about it" on the Ars Technica site and
"Triple Meltdown: How so Many Researchers found a 20-year-old chip Flaw at
the Same Time" on Wired site. We'll continue to write about this as more
information is released.
Research
Greenberg, A. (2018, January 07). How So Many Researchers
Found a 20-Year-Old Chip Flaw At Once. Retrieved January 07, 2018, from https://www.wired.com/story/meltdown-spectre-bug-collision-intel-chip-flaw-discovery/
Peter Bright - Jan 5, 2018 1:52 pm UTC. (2018, January 05).
Meltdown and Spectre: Here’s what Intel, Apple, Microsoft, others are doing
about it. Retrieved January 07, 2018, from
https://arstechnica.com/gadgets/2018/01/meltdown-and-spectre-heres-what-intel-apple-microsoft-others-are-doing-about-it/
Comments
Post a Comment