Anatomy of Meltdown – A Technical Journey

This blog reviews the details of Meltdown and discusses the inherent immunity for end users provided by Bromium’s architecture. Meltdown is an Intel CPU vulnerability leveraging speculative execution which gives an attacker-controlled process the… Continue reading Anatomy of Meltdown – A Technical Journey

What privacy/security problems occur if a userland process can read the kernel memory?

As far as I understand, with Spectre, a malicious attacker from userland (javascript from webbrowser) can read “kernel memory”.

But the question is: what is in the kernel memory, that can cause any security/privacy problem?… Continue reading What privacy/security problems occur if a userland process can read the kernel memory?

Spectre and Meltdown Haunt CPUs Everywhere – What to Know and What to Do

TL;DR – Spectre and Meltdown are two recently announced vulnerabilities that allow private data to be accessed by otherwise unauthorized applications. Patches are coming out to mitigate risks, but these may also affect the speed of your devices a… Continue reading Spectre and Meltdown Haunt CPUs Everywhere – What to Know and What to Do

Intel firmware/microcode updates that make processors "immune" to both Spectre and Meltdown?

Recently Intel has claimed the following in a press release (emphasis added):

SANTA CLARA, Calif., Jan. 4, 2018 — Intel has developed and is rapidly issuing updates for all types of Intel-based computer systems — includin… Continue reading Intel firmware/microcode updates that make processors "immune" to both Spectre and Meltdown?

Apple Releases Spectre Patches for Safari, macOS and iOS

Apple releases patches addressing the Spectre vulnerability impacting its macOS, iPhone, iPad and iPod touch. Continue reading Apple Releases Spectre Patches for Safari, macOS and iOS