{"id":20567,"date":"2018-01-05T13:31:29","date_gmt":"2018-01-05T11:31:29","guid":{"rendered":"https:\/\/blog.pricecheck.co.za\/?p=20567"},"modified":"2020-01-15T18:07:29","modified_gmt":"2020-01-15T16:07:29","slug":"your-devices-are-vulnerable","status":"publish","type":"post","link":"\/blog\/your-devices-are-vulnerable\/","title":{"rendered":"Your devices are vulnerable&#8230;"},"content":{"rendered":"<p>The past week has seen the entire tech world abuzz with talk of two new exploits which could be used to target every processor made in the last 20 years.<\/p>\n<p>Dubbed\u00a0<strong>Meltdown\u00a0<\/strong>and\u00a0<strong>Spectre,\u00a0<\/strong>these exploits are so severe that every major technology company is scrambling to protect themselves and their customers.<\/p>\n<p>These hardware bugs work by allowing programs to steal data which is currently processed on the computer.\u00a0 While programs usually are not permitted to read data from other programs, a malicious program could exploit Meltdown and Spectre to get hold of secrets stored in the memory of other running programs. This might include your passwords stored in a password manager or browser, your personal photos, emails, instant messages and even business-critical documents.<\/p>\n<p>Meltdown and Spectre work on personal computers, mobile devices, and in the cloud.<\/p>\n<p>Apple says that &#8220;The Meltdown and Spectre issues take advantage of a modern CPU performance feature called speculative execution. Speculative execution improves speed by operating on multiple instructions at once\u2014possibly in a different order than when they entered the CPU. To increase performance, the CPU predicts which path of a branch is most likely to be taken, and will speculatively continue execution down that path even before the branch is completed. If the prediction was wrong, this speculative execution is rolled back in a way that is intended to be invisible to software.<\/p>\n<p>The Meltdown and Spectre exploitation techniques abuse speculative execution to access privileged memory\u2014including that of the kernel\u2014from a less-privileged user process such as a malicious app running on a device.&#8221;<\/p>\n<p>Originally discovered by members of Google&#8217;s Project Zero, both Meltdown and Spectre could affect nearly every known computer, tablet and phone on the planet, regardless of operating system or manufacturer. Luckily for all of us, there has not yet been a case of either discovered in the wild (aka in the real world and not a controlled environment).<\/p>\n<h3><span style=\"text-decoration: underline;\"><strong>FAQs<\/strong><\/span><\/h3>\n<h4 id=\"faq-affected\">Am I affected by the bug?<\/h4>\n<p>Yes.<\/p>\n<h4 id=\"faq-detect\">Can I detect if someone has exploited Meltdown or Spectre against me?<\/h4>\n<p>Probably not. The exploitation does not leave any traces in traditional log files.<\/p>\n<h4 id=\"faq-antivirus\">Can my antivirus detect or block this attack?<\/h4>\n<p>While possible in theory, this is unlikely in practice. Unlike usual malware, Meltdown and Spectre are hard to distinguish from regular benign applications. However, your antivirus may detect malware which uses the attacks by comparing binaries after they become known.<\/p>\n<h4 id=\"faq-leaked\">What can be leaked?<\/h4>\n<p>If your system is affected, the exploit can read the memory content of your computer. This may include passwords and sensitive data stored on the system.<\/p>\n<h4 id=\"faq-wild\">Has Meltdown or Spectre been abused in the wild?<\/h4>\n<p>As yet, there are no reported cases.<\/p>\n<h4 id=\"faq-fix\">Is there a workaround\/fix?<\/h4>\n<p>There are patches against Meltdown for Linux, Windows and OS X. There is also work to harden software against future exploitation of Spectre, respectively to patch software after exploitation through Spectre.<\/p>\n<h4 id=\"faq-systems-meltdown\">Which systems are affected by Meltdown?<\/h4>\n<p>Desktop, Laptop, and Cloud computers may be affected by Meltdown. More technically, every Intel processor which implements out-of-order execution is potentially affected, which is effectively every processor since 1995 (except Intel Itanium and Intel Atom before 2013).<\/p>\n<h4 id=\"faq-systems-spectre\">Which systems are affected by Spectre?<\/h4>\n<p>Almost every system is affected by Spectre: Desktops, Laptops, Cloud Servers, as well as Smartphones. More specifically, all modern processors capable of keeping many instructions in flight are potentially vulnerable.<\/p>\n<p>&nbsp;<\/p>\n<h4 id=\"faq-meltdown-vs-spectre\">What is the difference between Meltdown and Spectre?<\/h4>\n<p>Meltdown breaks the mechanism that keeps applications from accessing arbitrary system memory. Consequently, applications can access system memory. Spectre tricks other applications into accessing arbitrary locations in their memory. Both attacks use side channels to obtain the information from the accessed memory location. For a more technical discussion refer to the papers (<a href=\"https:\/\/meltdownattack.com\/meltdown.pdf\">\u00a0Meltdown<\/a>\u00a0and\u00a0<a href=\"https:\/\/spectreattack.com\/spectre.pdf\">\u00a0Spectre<\/a>)<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h4 id=\"faq-advisory\"><strong><a href=\"https:\/\/meltdownattack.com\/#faq-advisory\">Where can I find official infos\/security advisories of involved\/affected companies?<\/a><\/strong><\/h4>\n<table id=\"logos\" style=\"width: 729px;\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 81px;\"><\/td>\n<th style=\"width: 634px; text-align: center;\">Link<\/th>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Intel<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/security-center.intel.com\/advisories.aspx\" target=\"_blank\" rel=\"noopener\">\u00a0Security Advisory<\/a>\u00a0\u00a0\u00a0 \/ \u00a0\u00a0\u00a0<a href=\"https:\/\/newsroom.intel.com\/news\/intel-responds-to-security-research-findings\/\" target=\"_blank\" rel=\"noopener\">\u00a0Newsroom<\/a>\u00a0\u00a0\u00a0 \/ \u00a0\u00a0\u00a0<a href=\"https:\/\/newsroom.intel.com\/wp-content\/uploads\/sites\/11\/2018\/01\/Intel-Analysis-of-Speculative-Execution-Side-Channels.pdf\" target=\"_blank\" rel=\"noopener\">\u00a0Whitepaper<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">ARM<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/developer.arm.com\/support\/security-update\" target=\"_blank\" rel=\"noopener\">\u00a0Security Update<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">AMD<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/www.amd.com\/en\/corporate\/speculative-execution\" target=\"_blank\" rel=\"noopener\">\u00a0Security Information<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Microsoft<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180002\" target=\"_blank\" rel=\"noopener\">\u00a0Security Guidance<\/a>\u00a0\u00a0\u00a0 \/ \u00a0\u00a0\u00a0<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4072699\/important-information-regarding-the-windows-security-updates-released\" target=\"_blank\" rel=\"noopener\">\u00a0Information regarding anti-virus software<\/a>\u00a0\u00a0\u00a0 \/ \u00a0\u00a0\u00a0<a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/securing-azure-customers-from-cpu-vulnerability\/\" target=\"_blank\" rel=\"noopener\">\u00a0Azure Blog<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Amazon<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/aws.amazon.com\/de\/security\/security-bulletins\/AWS-2018-013\/\" target=\"_blank\" rel=\"noopener\">\u00a0Security Bulletin<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Google<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/googleprojectzero.blogspot.co.at\/2018\/01\/reading-privileged-memory-with-side.html\" target=\"_blank\" rel=\"noopener\">\u00a0Project Zero Blog<\/a>\u00a0\u00a0\u00a0 \/ \u00a0\u00a0\u00a0<a href=\"https:\/\/blog.google\/topics\/google-cloud\/what-google-cloud-g-suite-and-chrome-customers-need-know-about-industry-wide-cpu-vulnerability\/\" target=\"_blank\" rel=\"noopener\">\u00a0Need to know<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Apple<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/support.apple.com\/en-us\/HT208394\" target=\"_blank\" rel=\"noopener\">\u00a0Apple Support<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Mozilla<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/blog.mozilla.org\/security\/2018\/01\/03\/mitigations-landing-new-class-timing-attack\/\" target=\"_blank\" rel=\"noopener\">\u00a0Security Blog<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Red Hat<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/speculativeexecution\" target=\"_blank\" rel=\"noopener\">\u00a0Vulnerability Response<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Debian<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2017-5754\" target=\"_blank\" rel=\"noopener\">\u00a0Security Tracker<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Ubuntu<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/KnowledgeBase\/SpectreAndMeltdown\" target=\"_blank\" rel=\"noopener\">\u00a0Knowledge Base<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">SUSE<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/www.suse.com\/c\/suse-addresses-meltdown-spectre-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">\u00a0Vulnerability Response<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Fedora<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/fedoramagazine.org\/protect-fedora-system-meltdown\/\" target=\"_blank\" rel=\"noopener\">\u00a0Kernel update<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Qubes<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/www.qubes-os.org\/news\/2018\/01\/04\/xsa-254-meltdown-spectre\/\" target=\"_blank\" rel=\"noopener\">\u00a0Announcement<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">LLVM<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"http:\/\/lists.llvm.org\/pipermail\/llvm-commits\/Week-of-Mon-20180101\/513630.html\" target=\"_blank\" rel=\"noopener\">\u00a0Spectre (Variant #2) Patch<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">CERT<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/584653\" target=\"_blank\" rel=\"noopener\">\u00a0Vulnerability Note<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">MITRE<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=2017-5715\">\u00a0CVE-2017-5715<\/a>\u00a0\u00a0\u00a0\/\u00a0\u00a0\u00a0<a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=2017-5753\">\u00a0CVE-2017-5753<\/a>\u00a0\u00a0\u00a0 \/ \u00a0\u00a0\u00a0<a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=2017-5754\">\u00a0CVE-2017-5754<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">VMWare<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/www.vmware.com\/us\/security\/advisories\/VMSA-2018-0002.html\" target=\"_blank\" rel=\"noopener\">\u00a0Security Advisory<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Citrix<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/support.citrix.com\/article\/CTX231399\" target=\"_blank\" rel=\"noopener\">\u00a0Security Bulletin<\/a><\/td>\n<\/tr>\n<tr>\n<th style=\"width: 81px;\">Xen<\/th>\n<td style=\"width: 634px; text-align: center;\"><a href=\"https:\/\/xenbits.xen.org\/xsa\/advisory-254.html\" target=\"_blank\" rel=\"noopener\">\u00a0Security Advisory (XSA-254)<\/a>\u00a0\u00a0\u00a0\/\u00a0\u00a0\u00a0<a href=\"https:\/\/blog.xenproject.org\/2018\/01\/04\/xen-project-spectremeltdown-faq\/\" target=\"_blank\" rel=\"noopener\">\u00a0FAQ<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>The past week has seen the entire tech world abuzz with talk of two new exploits which could be used to target every processor made in the last 20 years. Dubbed\u00a0Meltdown\u00a0and\u00a0Spectre,\u00a0these exploits are so severe that every major technology company is scrambling to protect themselves and their customers. These hardware bugs work by allowing programs<\/p>\n<div class=\"read-more\"><a href=\"\/blog\/your-devices-are-vulnerable\/\" title=\"Read More\">Read More<\/a><\/div>\n","protected":false},"author":1,"featured_media":20569,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false,"amp_status":"","footnotes":""},"categories":[2850],"tags":[152,153,166,179,441,2713,530,2714,826],"jetpack_featured_media_url":"\/blog\/wp-content\/uploads\/2018\/01\/hacker-1944688_960_720-1.jpg","_links":{"self":[{"href":"\/blog\/wp-json\/wp\/v2\/posts\/20567"}],"collection":[{"href":"\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"\/blog\/wp-json\/wp\/v2\/comments?post=20567"}],"version-history":[{"count":2,"href":"\/blog\/wp-json\/wp\/v2\/posts\/20567\/revisions"}],"predecessor-version":[{"id":20570,"href":"\/blog\/wp-json\/wp\/v2\/posts\/20567\/revisions\/20570"}],"wp:featuredmedia":[{"embeddable":true,"href":"\/blog\/wp-json\/wp\/v2\/media\/20569"}],"wp:attachment":[{"href":"\/blog\/wp-json\/wp\/v2\/media?parent=20567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"\/blog\/wp-json\/wp\/v2\/categories?post=20567"},{"taxonomy":"post_tag","embeddable":true,"href":"\/blog\/wp-json\/wp\/v2\/tags?post=20567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}