ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Major Intel CPU vulnerability

    IT Discussion
    29
    260
    26.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jimmy9008
      last edited by

      Do we have to patch for this?

      I can see cloud/providers patching of course, as its shared infrastructure. However, we run everything on our own completely owned hardware, in the office. The host/VMs running on our local servers are our hosts and VMs.

      We run a risk that if somebody gains access to a VM or a host that they can do a range of unwanted things, however, with access they could do many things, not just this attack, and we would have far bigger problems...

      So, is it worth patching for this on 'private' servers and potentially losing 30% of performance, or leave unpatched...

      I will of course patch as i'd feel like an idiot for not patching should something happen; just curious as to whether leaving this patch off is valid in any way...

      What do ya'll think? I'm currently live migrating a load of VMs off of one of our T630s to apply the patch and do some testing.

      1 Reply Last reply Reply Quote 0
      • J
        Jimmy9008 @Dashrender
        last edited by

        @dashrender said in Major Intel CPU vulnerability:

        @jimmy9008 said in Major Intel CPU vulnerability:

        Does anybody know if Dell have released firmware for T630 server for the hardware? I cant seem to find that info on Dells site...

        -its ok, think I've found it, and its this... Update

        Damn, on the bleeding edge on that one.

        I looked for some HP things yesterday - nada.

        I'm guessing by the end of January, we'll start seeing more firmware updates.

        Now the question is, how far back are the vendors going to go?

        I've applied the patch. Now Microsoft shows protection enabled for 'rogue data cache load', but shows as 'False' for 'branch target injection'.

        I'm guessing that Dell will be sending out another update for their systems to address that. Anybody able to confirm?

        I have opened a call with Dell Support to verify.

        J 1 Reply Last reply Reply Quote 0
        • J
          Jimmy9008 @Jimmy9008
          last edited by

          @jimmy9008 said in Major Intel CPU vulnerability:

          @dashrender said in Major Intel CPU vulnerability:

          @jimmy9008 said in Major Intel CPU vulnerability:

          Does anybody know if Dell have released firmware for T630 server for the hardware? I cant seem to find that info on Dells site...

          -its ok, think I've found it, and its this... Update

          Damn, on the bleeding edge on that one.

          I looked for some HP things yesterday - nada.

          I'm guessing by the end of January, we'll start seeing more firmware updates.

          Now the question is, how far back are the vendors going to go?

          I've applied the patch. Now Microsoft shows protection enabled for 'rogue data cache load', but shows as 'False' for 'branch target injection'.

          I'm guessing that Dell will be sending out another update for their systems to address that. Anybody able to confirm?

          I have opened a call with Dell Support to verify.

          I restarted around 4 times, then ran 'Install-Module SpeculationControl' again and it worked.

          DustinB3403D 1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @Jimmy9008
            last edited by

            @jimmy9008 You absolutely need to be patching, for the very reasons you've mentioned questioning whether patching is worth it for private industries.

            1 Reply Last reply Reply Quote 0
            • EddieJenningsE
              EddieJennings
              last edited by

              In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

              DashrenderD 1 Reply Last reply Reply Quote 3
              • DanpD
                Danp
                last edited by

                https://www.theregister.co.uk/2018/01/08/microsofts_spectre_fixer_bricks_some_amd_powered_pcs/

                1 Reply Last reply Reply Quote 0
                • ObsolesceO
                  Obsolesce
                  last edited by

                  In a cloud hosting scenario, VPS...

                  If the host is patched, and guest1 VM is patched, but guest2 VM is not patched... are there still meltdown or spectre vulnerabilities for guest1?

                  How exactly does this work?

                  1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @EddieJennings
                    last edited by

                    @eddiejennings said in Major Intel CPU vulnerability:

                    In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                    I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                    EddieJenningsE 1 Reply Last reply Reply Quote 0
                    • EddieJenningsE
                      EddieJennings @Dashrender
                      last edited by

                      @dashrender said in Major Intel CPU vulnerability:

                      @eddiejennings said in Major Intel CPU vulnerability:

                      In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                      I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                      The question then is whether or not the OS patching will be sufficient.

                      DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @EddieJennings
                        last edited by

                        @eddiejennings said in Major Intel CPU vulnerability:

                        @dashrender said in Major Intel CPU vulnerability:

                        @eddiejennings said in Major Intel CPU vulnerability:

                        In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                        I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                        The question then is whether or not the OS patching will be sufficient.

                        While these are some pretty nasty vulnerabilities, I don't currently consider them that horrible. As I understand it (and I leave TONS of room to learn new things about these) you can only be affected if you run untrusted code on your system. Assuming that webpages can't take advantage, this amounts to the same level of issue as a typical virus.

                        Assuming hardware vendors don't produce updates for hardware more than say 3 years old - how many here are going to be replacing their machines/devices (don't forget your android phones are affected too - last I heard)?

                        scottalanmillerS 2 Replies Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @EddieJennings
                          last edited by

                          @eddiejennings said in Major Intel CPU vulnerability:

                          @dashrender said in Major Intel CPU vulnerability:

                          @eddiejennings said in Major Intel CPU vulnerability:

                          In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                          I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                          The question then is whether or not the OS patching will be sufficient.

                          Depends if it is Intel based or from a more security-minded vendor.

                          EddieJenningsE 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Dashrender
                            last edited by

                            @dashrender said in Major Intel CPU vulnerability:

                            @eddiejennings said in Major Intel CPU vulnerability:

                            @dashrender said in Major Intel CPU vulnerability:

                            @eddiejennings said in Major Intel CPU vulnerability:

                            In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                            I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                            The question then is whether or not the OS patching will be sufficient.

                            While these are some pretty nasty vulnerabilities, I don't currently consider them that horrible. As I understand it (and I leave TONS of room to learn new things about these) you can only be affected if you run untrusted code on your system. Assuming that webpages can't take advantage, this amounts to the same level of issue as a typical virus.

                            Assuming hardware vendors don't produce updates for hardware more than say 3 years old - how many here are going to be replacing their machines/devices (don't forget your android phones are affected too - last I heard)?

                            In a desktop or laptop case, the risk is tiny compared to the big fear of shared computing environments.

                            1 Reply Last reply Reply Quote 1
                            • EddieJenningsE
                              EddieJennings @scottalanmiller
                              last edited by

                              @scottalanmiller said in Major Intel CPU vulnerability:

                              @eddiejennings said in Major Intel CPU vulnerability:

                              @dashrender said in Major Intel CPU vulnerability:

                              @eddiejennings said in Major Intel CPU vulnerability:

                              In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                              I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                              The question then is whether or not the OS patching will be sufficient.

                              Depends if it is Intel based or from a more security-minded vendor.

                              All Dell and all Intel.

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @Dashrender
                                last edited by

                                @dashrender said in Major Intel CPU vulnerability:

                                ... (don't forget your android phones are affected too - last I heard)?

                                The risk is not based on OS, so can't be determined by something like "Android phone." Some Androids are affected, some are not.

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @EddieJennings
                                  last edited by

                                  @eddiejennings said in Major Intel CPU vulnerability:

                                  @scottalanmiller said in Major Intel CPU vulnerability:

                                  @eddiejennings said in Major Intel CPU vulnerability:

                                  @dashrender said in Major Intel CPU vulnerability:

                                  @eddiejennings said in Major Intel CPU vulnerability:

                                  In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                                  I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                                  The question then is whether or not the OS patching will be sufficient.

                                  Depends if it is Intel based or from a more security-minded vendor.

                                  All Dell and all Intel.

                                  Then an OS patch cannot fix it.

                                  EddieJenningsE 1 Reply Last reply Reply Quote 0
                                  • EddieJenningsE
                                    EddieJennings @scottalanmiller
                                    last edited by

                                    @scottalanmiller said in Major Intel CPU vulnerability:

                                    @eddiejennings said in Major Intel CPU vulnerability:

                                    @scottalanmiller said in Major Intel CPU vulnerability:

                                    @eddiejennings said in Major Intel CPU vulnerability:

                                    @dashrender said in Major Intel CPU vulnerability:

                                    @eddiejennings said in Major Intel CPU vulnerability:

                                    In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                                    I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                                    The question then is whether or not the OS patching will be sufficient.

                                    Depends if it is Intel based or from a more security-minded vendor.

                                    All Dell and all Intel.

                                    Then an OS patch cannot fix it.

                                    While I understand the problem itself is with the chip, aren't the OS patches being released supposed to alter how memory is handled, which doesn't fix, but rather mitigates the problem (and potentially lowers performance)?

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • ObsolesceO
                                      Obsolesce
                                      last edited by

                                      I want to know how this effects hosts... does just the host need patched, or every VM?

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @Obsolesce
                                        last edited by

                                        @tim_g said in Major Intel CPU vulnerability:

                                        I want to know how this effects hosts... does just the host need patched, or every VM?

                                        Every VM.

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @EddieJennings
                                          last edited by

                                          @eddiejennings said in Major Intel CPU vulnerability:

                                          @scottalanmiller said in Major Intel CPU vulnerability:

                                          @eddiejennings said in Major Intel CPU vulnerability:

                                          @scottalanmiller said in Major Intel CPU vulnerability:

                                          @eddiejennings said in Major Intel CPU vulnerability:

                                          @dashrender said in Major Intel CPU vulnerability:

                                          @eddiejennings said in Major Intel CPU vulnerability:

                                          In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                                          I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                                          The question then is whether or not the OS patching will be sufficient.

                                          Depends if it is Intel based or from a more security-minded vendor.

                                          All Dell and all Intel.

                                          Then an OS patch cannot fix it.

                                          While I understand the problem itself is with the chip, aren't the OS patches being released supposed to alter how memory is handled, which doesn't fix, but rather mitigates the problem (and potentially lowers performance)?

                                          That handles the one issue, not the other.

                                          EddieJenningsE 1 Reply Last reply Reply Quote 0
                                          • EddieJenningsE
                                            EddieJennings @scottalanmiller
                                            last edited by

                                            @scottalanmiller said in Major Intel CPU vulnerability:

                                            @eddiejennings said in Major Intel CPU vulnerability:

                                            @scottalanmiller said in Major Intel CPU vulnerability:

                                            @eddiejennings said in Major Intel CPU vulnerability:

                                            @scottalanmiller said in Major Intel CPU vulnerability:

                                            @eddiejennings said in Major Intel CPU vulnerability:

                                            @dashrender said in Major Intel CPU vulnerability:

                                            @eddiejennings said in Major Intel CPU vulnerability:

                                            In addition to OS patches, I assume we ought to be looking for BIOS updates as well, which, with many of our ancient desktops, there will probably be none.

                                            I don't expect any for my 3 year old laptops, let alone my 5-7 year old desktops.

                                            The question then is whether or not the OS patching will be sufficient.

                                            Depends if it is Intel based or from a more security-minded vendor.

                                            All Dell and all Intel.

                                            Then an OS patch cannot fix it.

                                            While I understand the problem itself is with the chip, aren't the OS patches being released supposed to alter how memory is handled, which doesn't fix, but rather mitigates the problem (and potentially lowers performance)?

                                            That handles the one issue, not the other.

                                            The "other" being the chip design flaw itself?

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 6
                                            • 7
                                            • 8
                                            • 9
                                            • 10
                                            • 11
                                            • 12
                                            • 13
                                            • 8 / 13
                                            • First post
                                              Last post