Windows 10: Do we know the actual risk of Meltdown and Spectre?

Discus and support Do we know the actual risk of Meltdown and Spectre? in AntiVirus, Firewalls and System Security to solve the problem; There has been a lot discussion about Meltdown and Spectre on this forum and others, but I'm still confused. And I have 2 computers, and possibly 3,... Discussion in 'AntiVirus, Firewalls and System Security' started by pokeefe0001, Jan 10, 2018.

  1. Do we know the actual risk of Meltdown and Spectre?


    There has been a lot discussion about Meltdown and Spectre on this forum and others, but I'm still confused. And I have 2 computers, and possibly 3, that are old enough that no BIOS remedy will be forthcoming so I'm going to be vulnerable to Spectre for the foreseeable future. But how vulnerable is that? I realize that no AV product is going to have AV signatures of malware exploiting Spectre until such programs are discovered and reported, and I've heard that there is no obvious identifying characteristic of programs exploiting the vulnerabilities.

    On the other hand, common web hygiene will be just as good at preventing infection by Meltdown and Spectre exploiters as it is for any other malware, won't it? Somewhere I read that the most likely route for exploitation is via browsers. Is there any truth to that? Some common browsers (such as Firefox) have already released fixes.

    Bottom line: how dangerous is it to run computers that will not have BIOS fixes?

    :)
     
    pokeefe0001, Jan 10, 2018
    #1
  2. NoRender Win User

    Windows 10 stutters / lag when opening UWP apps

    I'm not referring to the Meltdown / Spectre SECURITY issues at all, i'm reporting an actual bug that have nothing to do with this, i think it's pretty clear.
     
    NoRender, Jan 10, 2018
    #2
  3. ganesh1209, Jan 10, 2018
    #3
  4. eLPuSHeR Win User

    Do we know the actual risk of Meltdown and Spectre?

    It's probably dangerous. These vulnerabilities cannot be 100% fixed unless software+firmware updates are in effect. So far, no bios update for my gigabyte motherboard, so I am mitigating the issue at best.
     
    eLPuSHeR, Jan 10, 2018
    #4
  5. Steve C Win User
    I support two home built PCs from 2004 having Gigabyte motherboards and there is no sign of a BIOS update yet. I don't really want to ditch two perfectly good PCs. I wonder how long the intelligence agencies have been aware of the Spectre and Meltdown vulnerabilities and have been exploiting them?
     
    Steve C, Jan 10, 2018
    #5
  6. dinosaur Win User
    I'm not devoting energy to concern over the *latest* "crisis". As I have noted in other postings here, i was recently forced into windows 10 because my ancient XP machine cratered and was not worth fixing. Worked diligently to tame win 10 (shut down ALL updating. Period. And trimmed down all the bloat that I could.)

    Have been around computers for some time...learned programming when IBM punch cards were the tools of the day.

    Have not used virus protection software since 2000 or so (have my own methods for avoiding crud)

    As computing/technology has progressed, I have become increasingly cautious of the tech/socio-political environment. Just look at all the authorized snooping that has evolved in the name of "keeping us safe".

    Sad....and my career was as one of the "good guys"

    Anywho....make your own mind up and do what you think is best. One of my buddies that I worked with latched on to a security patch (for the current crisis) for his win 10 pro machine and the patch gummed up his set-up. Took him a significant amount of time to undo it.
     
    dinosaur, Jan 10, 2018
    #6
  7. Meltdown can be fully mitigated at the OS-layer if separate kernel/userspace page tables are used, which looks like the route the major OSes are moving. So this shouldn't be a concern as long as you have an updated OS.

    Spectre is the hard one. Assuming no hardware/microcode or OS fixes, individual apps would have to block the exploits.

    Recall that these speculative execution attacks require attacker code to be running on your system. This could be in an infected executable, in which case Spectre is the least of your problems.

    Or, more likely, the attack code uses some embedded scripting language like Javascript. The script compilation/execution engine in each app would have to implement the mitigations. For Javascript you can be sure that Firefox/Edge/Chrome will be updated. But for proprietary engines like Flash or VBA, or for software that uses an old version of a scripting library and won't update it, you may be out of luck. In those cases you may get some OS-level mitigations that can partially block Spectre. Aside from that you'll have to relay on anti-malware detection.

    That said, you don't need to throw out your computers and go live in the woods. There are thousands of exploits found every year (~17000 CVE entries in 2017) that don't use Spectre. As long as you use standard browsing precautions, you are not really at any significantly greater risk than before.
     
    PolarNettles, Jan 10, 2018
    #7
  8. danielson Win User

    Do we know the actual risk of Meltdown and Spectre?

    And with AI on an un-stoppable ride, who knows what they'll come up with next?!
    Don't think they'll use it to find solutions that would require no money spending.
    To keep us worried and to corner us even more maybe...
     
    danielson, Apr 5, 2018
    #8
Thema:

Do we know the actual risk of Meltdown and Spectre?

Loading...
  1. Do we know the actual risk of Meltdown and Spectre? - Similar Threads - actual risk Meltdown

  2. Spectre and Meltdown not enabling.

    in Windows 10 Gaming
    Spectre and Meltdown not enabling.: Hi, a couple of days ago I disabled Spectre and Meltdown on my Windows 11 22H2 Laptop and now I am trying to enable it again but I can't seem to get it to work. I have tried using a app called "InSpectre" to enable it but it didn't work and i also changed a couple of registry...
  3. Spectre and Meltdown not enabling.

    in Windows 10 Software and Apps
    Spectre and Meltdown not enabling.: Hi, a couple of days ago I disabled Spectre and Meltdown on my Windows 11 22H2 Laptop and now I am trying to enable it again but I can't seem to get it to work. I have tried using a app called "InSpectre" to enable it but it didn't work and i also changed a couple of registry...
  4. Spectre and meltdown test

    in Windows 10 Ask Insider
    Spectre and meltdown test: Is there a way I can test for recent spectre vulnerabilities on win 10? All the tools I find online do not test for more recent issues submitted by /u/nocturnal_complex90 [link] [comments] https://www.reddit.com/r/Windows10/comments/k4un5t/spectre_and_meltdown_test/
  5. spectre and meltdown

    in AntiVirus, Firewalls and System Security
    spectre and meltdown: After installed windows 10 1809 from 1709. I haven't perform any bios/uefi update except windows update. But inspectre program says microcode update available: yes instead of no. not to mention last time I performed bios/uefi update about 2 years ago. I'm...
  6. Question about Spectre and Meltdown

    in AntiVirus, Firewalls and System Security
    Question about Spectre and Meltdown: I recently updated windows 10 1809 from 1709. on topic, is my laptop spectre or meltdown proof. please explain this picture [ATTACH] https://answers.microsoft.com/en-us/windows/forum/all/question-about-spectre-and-meltdown/20b0315e-d783-4364-8721-91f662c97fb0"
  7. Spectre / Meltdown Looms?

    in AntiVirus, Firewalls and System Security
    Spectre / Meltdown Looms?: Maybe arriving soon? See http://www.securityweek.com/malware-...-flaws-emerges 103802
  8. Meltdown, spectre and old motherboard and CPU.

    in Windows 10 Drivers and Hardware
    Meltdown, spectre and old motherboard and CPU.: I am running FCU Win 10 Pro on a MSI P35 Neo F v1 motherboard with Core 2 Duo E8400 CPU. I have ran the MS controlsettings script which informs me I am protected from Spectre by Windows Update but not Meltdown without a BIOS/Microcode update. As this is a 2008 motherboard...
  9. Spectre and Meltdown: Cheat sheet

    in Windows 10 News
    Spectre and Meltdown: Cheat sheet: What are the Spectre and Meltdown vulnerabilities, and how do they affect you? This essential guide will tell you everything you need to know about Spectre and Meltdown. Spectre and Meltdown: Cheat sheet - TechRepublic 103219
  10. Meltdown and Spectre: what you need to know

    in Windows 10 News
    Meltdown and Spectre: what you need to know: Overview If you’ve been keeping up with computer news over the last few days, you might have heard about Meltdown and Spectre, and you might be wondering what they are and what they can do. Basically, Meltdown and Spectre are the names for multiple new vulnerabilities...