Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Newest
  1. Anonymous
    2018-01-17T22:27:06+00:00

    Well,  It looks like my VMware VDI Infrastructure will NOT be getting the patches, simply due to the performance hit it will take.  I will have to use other means to prevent them from getting exploited.  

    On a positive note though, I did update the firmware for my dell laptops, and confirmed it patched the hardware vuln.  Steve Gibson @ Gibson research has developed a tool to test for these vulnerabilities, and I trust him far above others. 

    IE thinks the site has Malware, which it most certainly does not, so just use a different browser to download if you are interested.   The URL is https://www.grc.com/inspectre.htm.   It will check your system against Spectre and Meltdown and give you excellent specifics to help remediate if needed, along with good details to explain why your OK if that's the case.

    I ran the tool before I patched the OS, then after, then again before firmware updates, and after, and it tracked everything from start to finish.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-01-17T22:17:46+00:00

    They rushed these patches out to try to patch up the security holes but we need stable tested updates, ,which unfortunately may be a big trial and error period.. I wonder if new computers will be already patched up. I am thinking on upgrading my Windows laptop this year but may hold off for another year in light of all these problems. My Chromebook is already completely patched but I fear I may need to buy a new phone as I don't think Samsung will push an update to mine that is only a few years old. La da da da de.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-01-17T15:48:20+00:00

    Yikes.  Hopefully the firmware updates will start rolling out soon...

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-01-17T05:16:52+00:00

    Yes.  After the patch update my Haswell X99 motherboard reported that my SSD  C:\   boot drive was inaccessable.   Now working fine, as long as the patch remains uninstalled.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-01-16T22:45:09+00:00

    More Information for older Haswell  and amd chips

    Do you own an older intel cpu? Latest news on Haswell and older chips. Reboot problems 

    https://www.theverge.com/2018/1/12/16884750/meltdown-spectre-intel-patch-reboot-problems

    Latest news about AMD chips

    https://www.theverge.com/2018/1/11/16880922/amd-spectre-firmware-updates-ryzen-epyc

    Was this answer helpful?

    0 comments No comments