CRITICAL: Meltdown and Specter CPU Bugs

kuwanger

Well-Known Member
Member
Joined
Jul 26, 2006
Messages
1,510
Trophies
0
XP
1,783
Country
United States
I think that this scare is overblown, the likelihood of millions of people being hacked is very low.

Yes and no. Millions of people are hacked all the time. Odds are good that social engineering or other exploits will be more useful anyways--most hacking of users doesn't even need to spy on the kernel or whatever except possibly as a means to defeat ASLR or the like for the initial exploit. The real risk, IMHO, was (and still is) hackers getting access to private keys on cloud services to escalate to getting signing keys which then can be used to sign malware, forge SSL certificates, etc. Trying to clean up that mess for a lot of businesses and trying to well communicate users how to resolve it would be the worst of it. It doesn't help that most companies would pull an Intel and dissemble on what happened, be slow to acknowledge it happened, and generally try to shift blame away from the severity of it.

The real issue, IMHO, is that side-channel attacks on caches and speculation have both proved to be viable. Add in row hammer, and it seems more and more likely that some day someone will decide to write a malicious worm and do a lot of damage on the internet. Ironically, we're better off now precisely because malware writers are mostly financially interested and they want the internet to keep functioning. I don't think that's going to last forever. My gut feeling is this is going to blow over like rowhammer mostly has, people (especially in infrastructure) are going to make a half-hearted attempt to address the issue, and someone grey hat is going to decide that the world needs to be "taught a lesson".
 

sansnumen

Well-Known Member
OP
Member
Joined
Aug 4, 2017
Messages
323
Trophies
0
XP
1,362
Country
United States
Yes and no. Millions of people are hacked all the time. Odds are good that social engineering or other exploits will be more useful anyways--most hacking of users doesn't even need to spy on the kernel or whatever except possibly as a means to defeat ASLR or the like for the initial exploit. The real risk, IMHO, was (and still is) hackers getting access to private keys on cloud services to escalate to getting signing keys which then can be used to sign malware, forge SSL certificates, etc. Trying to clean up that mess for a lot of businesses and trying to well communicate users how to resolve it would be the worst of it. It doesn't help that most companies would pull an Intel and dissemble on what happened, be slow to acknowledge it happened, and generally try to shift blame away from the severity of it.

The real issue, IMHO, is that side-channel attacks on caches and speculation have both proved to be viable. Add in row hammer, and it seems more and more likely that some day someone will decide to write a malicious worm and do a lot of damage on the internet. Ironically, we're better off now precisely because malware writers are mostly financially interested and they want the internet to keep functioning. I don't think that's going to last forever. My gut feeling is this is going to blow over like rowhammer mostly has, people (especially in infrastructure) are going to make a half-hearted attempt to address the issue, and someone grey hat is going to decide that the world needs to be "taught a lesson".

I doubt that will happen. What is more concerning is foreign adversaries bringing down critical infrastructure like when hackers caused massive blackouts on the East Coast.
 

kuwanger

Well-Known Member
Member
Joined
Jul 26, 2006
Messages
1,510
Trophies
0
XP
1,783
Country
United States
I doubt that will happen. What is more concerning is foreign adversaries bringing down critical infrastructure like when hackers caused massive blackouts on the East Coast.

While I won't say that can't happen, I don't see that being something that Meltdown or Specter specifically granting. Now, using those tools to install spying software...although that too probably wouldn't likely require Meltdown or Specter.
 

sansnumen

Well-Known Member
OP
Member
Joined
Aug 4, 2017
Messages
323
Trophies
0
XP
1,362
Country
United States
While I won't say that can't happen, I don't see that being something that Meltdown or Specter specifically granting. Now, using those tools to install spying software...although that too probably wouldn't likely require Meltdown or Specter.

Spectre exploits can only read data. It's dangerous when dealing with servers and public crypto. For example, someone could steal some SSL keys and then impersonate legit https sites and steal credentials using fake sites with a legit SSL certificate. Scary stuff.

--------------------- MERGED ---------------------------

Has Microsoft released a meltdown fix on Windows update yet? Or are we still waiting on that?

Updates are rolling out now, however ancient PCs with ancient AMD chips like the Athlon 64 are bluescreening with the Meltdown/Spectre update.
 
Last edited by sansnumen,

leerpsp

Well-Known Member
Member
Joined
Feb 22, 2014
Messages
1,742
Trophies
0
Age
33
XP
1,871
Country
United States
Can this be used on game consoles to get encryption keys? Like maybe some good stuff can come out of this train wreck lol
Any things possible. But after I took the update with my laptop with an intel core i7 3.0GHz Microsoft edge stoped loading pages and windows will no longer take any more updates so I don't know what they did but i'm broke :(
 
  • Like
Reactions: Psionic Roshambo

Xzi

Time to fly, 621
Member
Joined
Dec 26, 2013
Messages
17,801
Trophies
3
Location
The Lands Between
Website
gbatemp.net
XP
8,729
Country
United States
Any things possible. But after I took the update with my laptop with an intel core i7 3.0GHz Microsoft edge stoped loading pages and windows will no longer take any more updates so I don't know what they did but i'm broke :(
Damn that sucks. Probably gonna have to format that bish and update fresh.
 

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
Spectre exploits can only read data. It's dangerous when dealing with servers and public crypto. For example, someone could steal some SSL keys and then impersonate legit https sites and steal credentials using fake sites with a legit SSL certificate. Scary stuff.

--------------------- MERGED ---------------------------



Updates are rolling out now, however ancient PCs with ancient AMD chips like the Athlon 64 are bluescreening with the Meltdown/Spectre update.

I'm wondering WTF would use those kinds of machines in 2018.
 

leerpsp

Well-Known Member
Member
Joined
Feb 22, 2014
Messages
1,742
Trophies
0
Age
33
XP
1,871
Country
United States
Damn that sucks. Probably gonna have to format that bish and update fresh.
...... man that is gonna suck i'll have to back up my files and everything... I'm gonna hold off for at lest 2 more days before i do a reinstall.
 

Armadillo

Well-Known Member
Member
Joined
Aug 28, 2003
Messages
4,290
Trophies
3
XP
5,312
Country
United Kingdom
Bios updates with the updated Microcode for spectre variant 2 have started to roll out for more boards now.

MSI have the z370 updates out now and will be rolling out updates for 100 series, 200 series, x299 and x99. Full list here
https://www.msi.com/news/detail/rKU...NhahW-TFJ96dI7K7NA9rKUsihP5smlrCseaHQstFxJw~~

Gigabyte are doing much the same and seem like they will only go back to x99.
http://www.gigabyte.eu/Press/News/1586

Gigabyte don't have anything up yet at the moment, just the press release and incomplete list.

Not seen any announcements from others. Z370 will obviously get it from everyone.
 
Last edited by Armadillo,

MasterControl90

Well-Known Member
Newcomer
Joined
Dec 18, 2017
Messages
92
Trophies
0
Age
34
Location
Italy
Website
www.capslocktech.com
XP
237
Country
Italy
Bios updates with the updated Microcode for spectre variant 2 have started to roll out for more boards now.

MSI have the z370 updates out now and will be rolling out updates for 100 series, 200 series, x299 and x99. Full list here
https://www.msi.com/news/detail/rKU...NhahW-TFJ96dI7K7NA9rKUsihP5smlrCseaHQstFxJw~~

Gigabyte are doing much the same and seem like they will only go back to x99.
http://www.gigabyte.eu/Press/News/1586

Gigabyte don't have anything up yet at the moment, just the press release and incomplete list.

Not seen any announcements from others. Z370 will obviously get it from everyone.

So no update at the moment for haswell, that's a shame :/
 

Armadillo

Well-Known Member
Member
Joined
Aug 28, 2003
Messages
4,290
Trophies
3
XP
5,312
Country
United Kingdom
Forgot Asus list.

https://www.asus.com/News/V5urzYAT6myCC1o2

Same deal as the others. Back to X99, although only two of their X99 boards listed for some reason.

X99 runs haswell-e (same architecture but 6 and up cores) CPUs, so I don't see why they shouldn't update consumer haswell as well (no pun intended)

Gigabyte might be doing z97. Someone on another forum asked them and apparently they said z97 is being worked on.

You would think haswell would get an update from most, but haswell has been off the market much longer than x99. X99 was still the current hedt platform untill the middle of last year.
 

sansnumen

Well-Known Member
OP
Member
Joined
Aug 4, 2017
Messages
323
Trophies
0
XP
1,362
Country
United States
Unfortunately Intel screwed up big because they are telling people to hold off on accepting microcode updates. Apparently drivers are behaving incorrectly with Intel's new microcode updates. You have been warned.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Plus technology cost iirc even a water jet drill is 1k per
  • cearp @ cearp:
    @K3Nv2 that's crazily expensive. how long will that take to pay off?

    Although diet is largely education, people don't need to go to university to learn what's healthy and what's not,
    it's the whole country, big corporations and advertising that is to blame for leading most of the population to believe that poptarts and froot loops are healthy to feed a child
  • mthrnite @ mthrnite:
    i would think the population knows better but with food deserts and abject poverty, sometimes a poptart gonna have to do.
  • mthrnite @ mthrnite:
    it's a big ol complicated world innit
    +1
  • Sicklyboy @ Sicklyboy:
    As someone who went through the grade school system in the US some time within the past 30 or so years, not nearly enough is done to promote and educate on how to eat healthy in a way that is feasible to do on a regular basis and also affordable. Eating healthy is, comparatively, fucking expensive. So is eating unhealthy, but in many cases eating unhealthy is more affordable than eating healthy
    +1
  • cearp @ cearp:
    90k could get you a 3 bedroom house in some poorer parts of the country
  • K3Nv2 @ K3Nv2:
    @cearp, it's like buying a new car most dentists say so $250 per the rest of your life
  • cearp @ cearp:
    Jesus
  • K3Nv2 @ K3Nv2:
    These are actual implants to dentures though
  • cearp @ cearp:
    Well once it's all done I'm sure you'll be happy with the result
  • K3Nv2 @ K3Nv2:
    Just a flappity denture would probably be 5k
  • mthrnite @ mthrnite:
    sold
  • K3Nv2 @ K3Nv2:
    I got some faith implants are going to justbe included with a crown cost
  • K3Nv2 @ K3Nv2:
    Procedures bullshit wait 4 months for graft to heal wait another four months the post to heal then get crown
  • SylverReZ @ SylverReZ:
    Only 1 tempycoin.
    +1
  • K3Nv2 @ K3Nv2:
    Got kfc for dinner fucking dinner box is a joke
  • BigOnYa @ BigOnYa:
    Just go gummy, ancientboi would like you better that way anyways, and you save money on toothbrushes/toothpaste
  • cearp @ cearp:
    @Sicklyboy I agree, but also it's about self control and realistic thinking. We wouldn't feed a dog soda, so why feed it to ourselves? Eating unhealthy food because it's cheap is one thing, but I'm sure you know people who drink soda routinely when they should be drinking water which is free.
    I get it can feel mean to say "no treat sweet beverage for you anymore" but for many people it's just in their way of life.
  • K3Nv2 @ K3Nv2:
    I drink soda twice out of the week
  • K3Nv2 @ K3Nv2:
    Plus decay can start as young as 15 tons of factors
  • cearp @ cearp:
    Even sugar free isn't good, as the acid is bad enough.
  • cearp @ cearp:
    oh earlier than 15 Ken, babies, children can get decay
  • K3Nv2 @ K3Nv2:
    So dentists give. Us these caps that'll last a few years to fight thrm
  • K3Nv2 @ K3Nv2:
    Yeah but babies get a new set
  • K3Nv2 @ K3Nv2:
    Screw godfor not giving us a new adult set after we mess up
    +1
    K3Nv2 @ K3Nv2: Screw godfor not giving us a new adult set after we mess up +1