Meltdown and Spectre vulnerabilities Intel (and AMD) Chip Bug

Anonymous
2018-01-04T01:54:57+00:00

A lot of noise on the internet, after Intel confirm that chips have a bug:

https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ 

This post is to bring some light on this.

1- Intel says is not only their chips affected

2- PCID (Process-Context Identifiers), a chip feature,  has a bug that allow apps (malware) to read data

3- Process-context identifiers (PCIDs) are a facility by which a logical processor may cache information for multiple linear-address spaces. The processor may retain cached information when software switches to a different linear address space with a different PCID.

4- Macintosh and Linux OS are also affected.

Rumors:

1- If you have Haswell (4th-gen) or newer, PCID (Process-Context Identifiers) is enabled. 

2- After apply the patch, performance is going to be slower on newer CPU. Around 5 to 10%.

2- Still if you have older CPU, performance will be affected worse than newer CPUs.

3- To be affected you must have a OS 64 bits. {Correction: 32bits has vulnerability, MS still working on this)

Just as I'm writing this, Linus Torvalds and his team are working on this too:

https://lkml.org/lkml/2018/1/2/703

https://www.postgresql.org/message-id/20180102222354.qikjmf7dvnjgbkxe%40alap3.anarazel.de

Can we get a word from Microsoft?

For windows, What patch is going to address this? (Update: Patch links and KB are listed on postings)

Is that is going to be on the Montly Rollup and/or Security only patches? (Update: See the links posted)

If performance is going to suffer, can we be able to uninstall such patch? (Update: Microsoft published a document about it, See the links posted)

Please, any info will be appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

77 answers

Sort by: Most helpful
  1. Anonymous
    2018-02-03T16:28:25+00:00

    Also found that AMD finally respond to this bug.

    At the beginning, only Intel supposedly was the only one that had this bug, but AMD finally accept (somewhat) that is suffering less pain, but still is affected.

    An Update on AMD Processor Security:

    https://www.amd.com/en/corporate/speculative-execution

    Variant One Bounds Check Bypass Resolved by software / OS updates to be made available by system vendors and manufacturers. Negligible performance impact expected.
    Variant Two Branch Target Injection Differences in AMD architecture mean there is a near zero risk of exploitation of this variant. Vulnerability to Variant 2 has not been demonstrated on AMD processors to date.
    Variant Three Rogue Data Cache Load Zero AMD vulnerability due to AMD architecture differences.

    If I understand correctly, they are saying 1 security issue is fixed by an OS patch, other security issue do not apply to AMD, and the third will be difficult to exploit.

    So, what that means? that AMD is going to wait and see if someone can exploit the 3rd security issue, and then do something?

    That's it? What gives?

    It looks like they are again claiming that AMD is not vulnerable. Hmm.. Thought they  admitted that it is vulnerable too. Looks like they are taking the wait and see attitude. I think that is a bad move and will give the customer a false sense of security. Maybe it is harder to exploit than the Intel chip but I think if they think it has a chance, (even a small chance) to be exploited they should be working on the fix. Looks as if they're saying zero for variant 3 and near zero for 2 (which means there is a chance but they don't think so ?) 

     https://www.networkworld.com/article/3253285/hardware/amd-plans-silicon-fix-for-spectre-vulnerability.html

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-02-02T23:23:57+00:00

    Also found that AMD finally respond to this bug.

    At the beginning, only Intel supposedly was the only one that had this bug, but AMD finally accept (somewhat) that is suffering less pain, but still is affected.

    An Update on AMD Processor Security:

    https://www.amd.com/en/corporate/speculative-execution

    Variant One Bounds Check Bypass Resolved by software / OS updates to be made available by system vendors and manufacturers. Negligible performance impact expected.
    Variant Two Branch Target Injection Differences in AMD architecture mean there is a near zero risk of exploitation of this variant. Vulnerability to Variant 2 has not been demonstrated on AMD processors to date.
    Variant Three Rogue Data Cache Load Zero AMD vulnerability due to AMD architecture differences.

    If I understand correctly, they are saying 1 security issue is fixed by an OS patch, other security issue do not apply to AMD, and the third will be difficult to exploit.

    So, what that means? that AMD is going to wait and see if someone can exploit the 3rd security issue, and then do something?

    That's it? What gives?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-02-02T19:01:48+00:00

    Some Bad news, Intel is still to release updates, and 

    Meltdown-Spectre: Malware is already being tested by attackers

    http://www.zdnet.com/article/meltdown-spectre-malware-is-already-being-tested-by-attackers/

    If Intel hadn't messed up the code for OEM's Many of us would already have BIOS updates in place. They better scoot their butts on this. Instead of showing off their latest (also vulnerable) and greatest.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-02-02T16:10:18+00:00

    Some Bad news, Intel is still to release updates, and 

    Meltdown-Spectre: Malware is already being tested by attackers

    http://www.zdnet.com/article/meltdown-spectre-malware-is-already-being-tested-by-attackers/

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-01-27T23:35:56+00:00

    Have a feeling the end won't be in sight anytime soon. Even with proper Bios  updates. this vulnerability has far reaching roots. Hardware, software . Just a mess . I have my Acer laptop sitting in a faraday cage because it has the AMT. . It was just a very cheap laptop with Windows 10 home to use with my printer . No updates for it until middle of March. Geez.

    Was this answer helpful?

    0 comments No comments