Protect Yourself Against Meltdown and Spectre CPU Flaws – by Ron Benvenisti

Part of the big news last week was the “Bomb Cyclone” blizzard of which the snow will hopefully melt as the temperatures slowly rise. Perhaps even bigger news was about the scary flaw in almost every CPU engine that powers Intel, Apple, Android and AMD computers and phones.

US-CERT, suggests that the only true patch for these issues is for chips to be replaced. This monumentally unwieldy solution is to impractical for us general users and most companies. IMHO, this type of security flaw, while some blame it on the NSA and CIA being in cahoots with the chip manufacturers to have a backdoor into systems for so called national security reasons (Thank you, Patriot Act) is likely related to the origin nations of the chip manufacturers, China being hot on the radar. Flawed Chinese chips were the reason the U.S. Army de-commissioned practically all of their drones. Chips made by hostile foreign actors are used in almost every plane, train, refrigerator, home security system, child monitors, cars and trucks and you name it. That’s a fact. Draw your own conclusions. Back to the Meltdown….

Vendors claim to have made “significant” progress rolling out fixes and firmware updates. The Meltdown flaw has already been patched by most companies like Microsoft, Apple and Google, but the Spectre is not easy to patch and will haunt people for quite some time, way after the snow melts and likely after the flowers bloom.

Here are the major tech manufacturers patch updates to date:

Windows OS (7/8/10) and Microsoft Edge/IE

Microsoft released security update (KB4056892) for Windows 10 to address the Meltdown issue and claims they will be releasing patches for Windows 7 and Windows 8 on January 9th. These are “out of band” so they will be pushed before the regular Windows Update schedules.

Be advised that some third-party antivirus software won’t let your system install patches automatically. If you do experience problems installing this Microsoft automatic security update, you may have to temporarily disable your antivirus and allow Windows to use Windows Defender or Microsoft Security Essentials. I would check your anti-virus vendor’s website first if you are having issues with the update.

Of course Microsoft blames the antivirus companies as they noted on their blog, “The compatibility issue is caused when antivirus applications make unsupported calls into Windows kernel memory, These calls may cause stop errors (also known as blue screen errors) that make the device unable to boot.” Unsupported by who? Nevermind.

Apple macOS, iOS, tvOS, and Safari Browser

Apple noted in a support advisory, “All Mac systems and iOS devices are affected, but there are no “known” exploits impacting customers at this time.” Considering that exploits can take months to discover and previous exploits usually don’t come to light until after flaws are discovered and can remain dormant and invisible on affected systems until someone pulls the trigger, that statement is unrealistic and sends an overly optimistic message to its userbase.

But to their credit, at least for the Meltdown attacks, Apple has already released mitigations in iOS 11.2, macOS 10.13.2, and tvOS 11.2, has planned to release mitigations in Safari to help defend against Spectre in the coming days.

Android OS

Android users running the most recent version of the mobile operating system released on January 5 as part of the Android January security patch update are protected, according to Google. If you own a Google-branded phone, like Nexus or Pixel, your phone will either automatically download the update, or you’ll simply need to install it. However, other Android users will have to wait for their device manufacturers to release a compatible security update. Google further noted that it’s “unaware of any successful exploitation of either Meltdown or Spectre on ARM-based Android devices”. See above comment: Considering that exploits can take months to discover and previous exploits usually don’t come to light until after flaws are discovered and can remain dormant and invisible on affected systems until someone pulls the trigger, that statement is unrealistic and sends an overly optimistic message to its userbase.

Firefox Web Browser

Mozilla, who invented the web browser (not Al Gore – he invented climate change or global warming or whatever he says)  has released Firefox version 57.0.4 which includes mitigations for both Meltdown and Spectre timing attacks. So users are advised to update their installations as soon as possible. Typically Firefox will update itself and restart and you should be good to go. “Since this new class of attacks involves measuring precise time intervals, as a partial, short-term mitigation we are disabling or reducing the precision of several time sources in Firefox,” Mozilla software engineer Luke Wagner wrote in a blog post.

Google Chrome Web Browser

Google has scheduled the patches for Meltdown and Spectre exploits on January 23 with the release of Chrome 64, which will include mitigations to protect your desktop and smartphone from web-based attacks.

In the meantime, users can hassle with an experimental feature called “Site Isolation” that can offer some protection against the web-based exploits but might also cause performance problems. “Site Isolation makes it harder for untrusted websites to access or steal information from your accounts on other websites. Websites typically cannot access each other’s data inside the browser anyway, thanks to code that enforces the Same Origin Policy.”

For the brave at heart, here’s how to turn on Site Isolation:

  • Copy chrome://flags/#enable-site-per-process and paste it into the URL field at the top of your Chrome web browser, and then hit the Enter key.
  • Look for Strict Site Isolation, then click the box labelled Enable.
  • Once done, hit Relaunch Now to relaunch your Chrome browser.

I would go with Firefox until Chrome 64 gets released.

Linux Distributions

Linux kernel developers released patches for the Linux kernel with for versions 4.14.11, 4.9.74, 4.4.109, 3.16.52, 3.18.91 and 3.2.97, which can be downloaded from Kernel.org.

VMware and Citrix

VMware a very popular application in extensive commercial use, has also released a list of its products affected by the two attacks and at least security updates for its ESXi, Workstation and Fusion products to patch against Meltdown attacks. Spectre? No one really has a handle on that.

Citrix, used heavily especially by support service providers did not release any security patches to address the issue. Instead, the company guided its customers and recommended them to check for any update on relevant third-party software. Relevant? Gee, thanks.

So, some progress has been made on Meltdown but as for Spectre you might as well watch the snow melt.

Bottom line is, patch what you can as soon as you can. We will not know the extent of problems created by these flaws or how long they have been going on for a long time.

Keep in mind the basic architecture of all the affected chips in question goes back decades.

Ron Benvenisti

 

This content, and any other content on TLS, may not be republished or reproduced without prior permission from TLS. Copying or reproducing our content is both against the law and against Halacha. To inquire about using our content, including videos or photos, email us at [email protected].

Stay up to date with our news alerts by following us on Twitter, Instagram and Facebook.
Got a news tip? Email us at [email protected], Text 415-857-2667, or WhatsApp 609-661-8668.

1 COMMENT

1 Comment
Inline Feedbacks
View all comments
BrooklynTransplant
8 years ago

I have a Winow 10 OS. There are 8 downloads for windows. Which one do I download?
Thank you