kemical

Essential Member
Joined
Aug 28, 2007
Messages
36,176
New vulnerabilities have recently been discovered with modern cpu's:

It would seem Intel are more prone to attack than AMD:

Meltdown and Spectre

Microsoft have released patches which will be available via Windows update. If like me yours hasn't arrived then download the standalone version here:

Windows 10:
https://support.microsoft.com/en-us/help/4056892windows-10-update-kb4056892

Windows 8.1:
https://support.microsoft.com/en-us/help/4056898windows-81-update-kb4056898

Windows 7:
https://support.microsoft.com/en-us/help/4056897windows-7-update-kb4056897

(To access the standalone download, scroll down the changelog to 'How to get this update' and click the link)
 
Solution
Process to verify your system is properly patched.
Patching requires both a patch from Microsoft and a firmware update from your system or motherboard manufacturer (for self built)

  • Open an elevated powershell prompt (Right click, 'Run As Administrator')
  • Type Install-Module SpeculationControl
  • Press A to install all/any modules
  • Type Get-SpeculationControlSettings
If you have any red you are not fully patched. CVE-2017-5754 is the OS patch and CVE-2017-5715 is handled by the firmware update covering install. There is a third CVE which may also be present. As a side note not all vendors have a firmware patch avaliable yet.
Microsoft go into more detail regarding performance deficits with the patching of Meltdown and spectre.

It would seem if your using a CPU which is pre 2016 then you may see a significant performance hit especially using Windows 7/8.1:

Understanding the performance impact of Spectre and Meltdown mitigations on Windows Systems

Reference:
Link Removed
 
The chips have always had the ability to call home, the Intel Management Engine I think it's called. I know this is a vulnerability but let's be honest if you've been following the tech industry for a long time, especially security, this really isn't surprises. However, there's A TON of scary hype articles about this. I saw that Infowars link and yeah I'm not watching that. Any article/video that just supports one's bias should make one question the article/video.

I tend to look at tech journalists and security experts like the following for information about such topics.
Schneier on Security
Link Removed
Krebs on Security
GRC | Gibson Research Corporation Home Page <----- lots of great resources on his website about locking down your computer here. And of course the SecurityNow! podcast
 
But they're not calling home, this is a flaw with speculative execution. As for Infowars best I keep my thoughts on them to myself.
 
Link Removed have posted a new blog detailing progression on how the chipmaker is addressing the Meltdown/Spectre situation. AMD is working closely with Microsoft to re release recent patches which bricked some AMD based systems as well as releasing new bios updates in the coming days/weeks.
An Update on AMD Processor Security
 
Guru3D has been hard at it benching Windows 10 to see what the recent patch means in terms of performance loss:
Windows Vulnerability CPU Meltdown Patch Benchmarked
 
I went and got the patches too. I also went to Dell Support and got the available driver updates including the BIOS. My laptop was built in 2017 and came with Win10. Hopefully any performance hit won't be noticeable. I also updated my hosts file. Hopefully they can stay ahead of any malicious websites there.

Thanks for posting this info. I feel like I need to express how grateful I am to yall for helping me stay ahead of all the vulnerabilities they find. I'm such a bad internet junkie I could get into real trouble if it wasn't for yall.
 
Last edited:
Glad to hear your all patched up Stuey!

Still waiting on a bios release my end but the os is patched and currently running AMD so hopefully things are covered.
 
AMD released new microcode yesterday so if we go with the bios release schedule of Gigabyte and MSI we should get it sometime in the next 6 months or so.
 
Yall are being pessimistic. I'm sure something good will come soon. [emoji106]

Sent from my SM-N910T using Tapatalk
 
Meltdown and Spectre Check tool for Windows:


Download

Reference:
Download: inSpectre Meltdown and Spectre Check tool for Windows
 
Last edited by a moderator: