LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - News
User Name
Password
Linux - News This forum is for original Linux News. If you'd like to write content for LQ, feel free to contact us.
All threads in the forum need to be approved before they will appear.

Notices


Reply
  Search this Thread
Old 01-04-2018, 03:33 PM   #1
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,602

Rep: Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084Reputation: 4084
Spectre and Meltdown are massive security flaws that affect almost every PC on Earth. Here’s what you need to know


Lots of information about this is becoming available, but here's an overview from The Washington Post:

Quote:
Technology companies are working to protect their customers after researchers revealed that major security flaws affecting nearly every modern computer processor could allow hackers to steal stored data — including passwords and other sensitive information — on desktops, laptops, mobile phones and cloud networks around the globe.

The scramble to harden a broad array of devices comes after researchers found two significant vulnerabilities within modern computing hardware, one of which cannot be fully resolved as of yet. Experts say the disclosure of the critical flaws underscores the need to keep up with software updates and security patches and highlights the role independent research plays in prodding tech companies to minimize security weaknesses.

Researchers at Google’s Project Zero, academic institutions and private companies published their findings on the vulnerabilities on Wednesday.

The more pervasive flaw of the two, dubbed Spectre, leaves the world's supply of microprocessors potentially vulnerable to attack, the researchers said. Although hackers will find it harder to take advantage of Spectre, it is also more challenging for computer manufacturers to ward off, the researchers said. “As it is not easy to fix, it will haunt us for quite some time,” the researchers said, explaining why they chose to call the flaw Spectre.

There's no complete software patch for Spectre right now, said Michael Daly, chief technology officer of cybersecurity and special missions at Raytheon, a defense company. The long-term solution may rely on a hardware redesign, he said, with software patches acting to monitor and stop malicious behavior. In the meantime, criminal actors and nation states could further develop the Spectre vulnerability, making attacks easier to execute.

“Right now it's kind of tricky to take advantage of it,” Daly said. “But it's not going to stop there. They will improve on it.”

The other flaw, called Meltdown, affects most Intel processors made after 1995. And although security patches exist for devices running Linux, Windows, and OS X, the researchers said, the fix may slow down their performance by as much as 30 percent, according to some estimates.
This is an extremely widespread issue with almost unprecedented impact. See https://meltdownattack.com/ for more.

--jeremy
 
Old 01-04-2018, 07:42 PM   #2
Mr. Macintosh
Member
 
Registered: Sep 2015
Distribution: Debian
Posts: 297

Rep: Reputation: 60
Quote:
Originally Posted by jeremy View Post
Lots of information about this is becoming available, but here's an overview from The Washington Post:



This is an extremely widespread issue with almost unprecedented impact. See https://meltdownattack.com/ for more.

--jeremy
Possible firmware updates instead?

http://www.zdnet.com/article/intel-s...28094294578069
 
Old 01-04-2018, 09:58 PM   #3
Ru1138
LQ Newbie
 
Registered: Aug 2014
Distribution: Antergos
Posts: 29

Rep: Reputation: Disabled
If you're on Arch, get your kernel updated to 4.14.11-1. Here's the Arch Linux security posting: https://security.archlinux.org/AVG-552
 
Old 01-04-2018, 10:35 PM   #4
_roman_
Member
 
Registered: Dec 2017
Location: _Austro_Bavaria_
Distribution: gentoo / linux mint
Posts: 433

Rep: Reputation: 29
admins, can you please merge those 5-10 topics, including mine in security section named intel cpu bug please.
 
Old 01-04-2018, 11:14 PM   #5
nigelc
Member
 
Registered: Oct 2004
Location: Sydney, Australia
Distribution: Mageia 7
Posts: 406
Blog Entries: 4

Rep: Reputation: 80
If it hasn't been used how can it be a problem?

Or is just FUD?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Vulnerabilities such as Meltdown and Spectre caseyl Linux - Security 7 01-22-2018 09:14 PM
LXer: Canonical Will Soon Patch all Supported Ubuntu Releases Against Meltdown/Spectre LXer Syndicated Linux News 0 01-04-2018 03:10 PM
OpenBSD devs worked on Meltdown/Spectre fixes eleven years ago YesItsMe *BSD 2 01-04-2018 09:56 AM
LXer: Meltdown And Spectre CPU Flaws Put Computers, Laptops, Phones At Risk LXer Syndicated Linux News 0 01-04-2018 09:34 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - News

All times are GMT -5. The time now is 07:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration