Forum Moderators: open

Message Too Old, No Replies

Intel ZombieLoad Vulnerability Bug Fix May Slow Computers and Datacenters

         

engine

10:28 am on May 15, 2019 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



The latest problem to hit Intel processors is the ZombieLoad vulnerability which could allow an attacker access to sensitive information.
According to the researchers, desktop, laptop, and Cloud computers may be affected, and is referenced as CVE-2018-12130
The ZombieLoad attack allows stealing sensitive data and keys while the computer accesses them.

While programs normally only see their own data, a malicious program can exploit the fill buffers to get hold of secrets currently processed by other running programs. These secrets can be user-level secrets, such as browser history, website content, user keys, and passwords, or system-level secrets, such as disk encryption keys.


[zombieloadattack.com...]

Intel has released a patch for vulnerable chips, along with Apple and Microsoft. Google and Mozilla (Firefox) have also released patches.
Microsoft advisory [portal.msrc.microsoft.com...] and [support.microsoft.com...]
Amazon Web Services [aws.amazon.com...]

Earlier stories
Google Engineers Say, Spectre Vulnerability is Here to Stay [webmasterworld.com]
Intel Says, Stop Deploying Current Spectre Patch [webmasterworld.com]
Linus Torvalds Criticises Intel's "Patches" for Meltdown and Spectre [webmasterworld.com]
CPU Vulnerabilities Named Meltdown and Spectre [webmasterworld.com]

graeme_p

5:21 pm on May 15, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



These issues are making me think again about VPSs: they clearly cannot match the security of having a physically separate dedicated server.

We always knew a VPS might have vulnerabilities, but thanks to Intel's mistakes it looks like they do, and lots of them.

Dimitri

8:41 pm on May 15, 2019 (gmt 0)

WebmasterWorld Senior Member 5+ Year Member Top Contributors Of The Month



Even before Intel 's cpu vulnerabilities I had always been avoiding VPS or shared hosts... I am paranoiac and never trust in guaranteed isolation :)

Patch after patch, Intel's CPU are loosing all the performances gained over the years ...

tangor

8:55 pm on May 15, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Just applied the patch ... for most things ended up with a minor increase in speed in all things EXCEPT (oddly) MS Access ... certain lookup functions are now slower than molasses in January. Will have to spend a little more time exploring things to see what else might be affected.

That said, the "lightning" is still there. :)

JS_Harris

2:14 am on May 16, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



The real problem is that when I just want to log on and check my email my computer wants to call home for a bazillion reasons I really don't need or want it to. `When everything your computer does is a potential weak point it's best it does very little beyond the absolute basics, imo. Less is indeed more.

Dimitri

11:26 am on May 16, 2019 (gmt 0)

WebmasterWorld Senior Member 5+ Year Member Top Contributors Of The Month



Without forgetting those motherboards which are also generating network activity, even before any OS is loaded ...