Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New Spectre, Meltdown variants leave victims open to side-channel attacks <p>
TechRepublic ^ | February 15, 2018 | By Conner Forrest

Posted on 02/19/2018 3:53:27 PM PST by Swordmaker

MeltdownPrime and SpectrePrime, found by Princeton and NVIDIA researchers, may require significant hardware changes to be mitigated.

Security researchers from NVIDIA and Princeton have discovered new variants of the Meltdown and Spectre flaws that may be more difficult to tackle than the originals. Dubbed MeltdownPrime and SpectrePrime, these flaws were further detailed in a recent research paper.

The software changes already underway will likely take care of these two exploits, but the coming hardware fixes won't, the researchers noted in the paper. The researchers said they believe the "hardware protection against them will be distinct," which means that chip makers may need to further change their designs to mitigate the threats.

After creating their own tool to synthesize the Spectre and Meltdown flaws, the researchers were able to use their findings to conduct side-channel attacks, or attacks that take advantage of the physical hardware related to a system's security. The side-channel attacks in this exploit are cache-based and rely on the timing of cache activity to glean information, the report said.

(Excerpt) Read more at techrepublic.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: applepinglist; malware; meltdown; spectre; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-2021 last
To: rarestia
No troll intended here, Sword, but do you know why they would have used a Mac to test the POC? Says in the article the exploit was tested on a Mac. Just curious if Apple’s platform is “better” for this test vs. Windows or Linux.

I suspect it is because a lot of programmers use Macs for development because you can run every operating system simultaneously on a fast Mac. . . Windows, Mac, Linux, Android, iOS, essentially everything you are going to develop for.

21 posted on 02/20/2018 12:55:41 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 4 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson