Tuesday, June 18 2019

Meltdown And Spectre Two Major CPU Security Bugs Effect CPU, Phones 'Apple'

Last Upadte July 1, 2018


In this era of technology, Apple Announced Meltdown and Spectre are the major vulnerabilities that can affect all Mac, iOS devices. So, don’t think your data is 100% safe on your computer!

What are Meltdown and Spectre and how they affect computer chips?

Meltdown and Spectre are the security flaws that are found in computer processors through which hackers can steal sensitive information without the users' knowledge. Through Meltdown, hackers can bypass hardware barriers between the running application and computer’s core memory (kernel).

On the other hand, Spectre is slightly different as it is used to trick the application into giving up secret information.

According to Daniel Gruss, Meltdown is one of worst CPU bugs hence immediate action is needed to fix its impact on the operating system.

Who discovered Meltdown and Spectre?

Meltdown was discovered by three teams i.e., Jann Horn from Google’s Project Zero, Werner Hass &Thomas Prescher from Cyberus and Daniel Gruss, Moritz Lipp, Stefan Mangard and Michael Schwarz from Graz University of Technology (Austria).

Spectre was mainly discovered by Horn Kocher, Paul Kocher but they also worked in collaboration with Daniel Grenkin, Mike Hamburg, Lipp and Yuval Yarom.

Which type of devices are affected by Meltdown and Spectre security flaws?

Although every computing device is affected by these two major security flaws. Some of them are -





5.Cloud Computing Systems

Do Spectre and Meltdown affect Intel Processors?

Processor - As we all know a processor is a primary chip that carries out instructions of a computer program and hence this is also known as the brain of a computer.

Although Meltdown affects only Intel chips but Spectre effect all modern processors that are designed by Intel, ARM, AMD.

What kind of information is stolen?

Kernel, the core system, store all sensitive information either it is banking records, logins, passwords but everything is at risk due to Meltdown.As Spectre is used to trick normal applications that means the data that is processed by the application can be stolen either it is the password or other valuable information.

What can users do to avoid these security flaws?

Apart from updating your operating system, you can also perform these little things to escape from cyber attack -

1.If you are using Chromebooks then update it to Chrome OS 63.

2.As these security flaws can steal the javascript from the web pages so if you are using Firefox 57 then update it to the latest version.

3.If you are using Windows 10 OS then confirm that you have installed KB4056892 on it.

4.If you require support information then check your computer OEM website.

5. Microsoft and Intel have designed a simple tool i.e., Powershell to check the protection of Windows and firmware updates.

6. Apple also advised its users to update the operating system and download software from the trusted sources such as App Store.

Although the fixes for Linux and Windows are currently available and users of other devices such as Samsung, Huawei, OnePlus have to wait for some time because updates are not released till now.

According to security researchers, Spectre is more difficult to exploit than Meltdown as they need hardware changes and a redesign of the processor.

Impact on computer’s performance

Some researchers concluded that there will be 30% degradation in system performance after applying fixes but performance will mainly depend on the task.

