Meltdown (cybersecurity vulnerability)

From Conservapedia
This is an old revision of this page, as edited by DavidB4 (talk | contribs) at 19:59, January 9, 2018. It may differ significantly from current revision.
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Meltdown is the name given to a cybersecurity vulnerability in the processors of computers, tablets, phones, and other such electronic devices. It enables code to be executed on a machine which "breaks" certain "isolation walls" in the processor, enabling user applications to access core operating system information. In this way, software can steal passwords, hashes, and other sensitive information from the operating system itself, and even other programs which are running on the device.[1] This vulnerability affects Intel x86 microprocessors and some ARM-based microprocessors.[2][3]

Discovery

This vulnerability was reported by Jann Horn (Google Project Zero), Werner Haas, Thomas Prescher (Cyberus Technology), Daniel Gruss, Moritz Lipp, Stefan Mangard, and Michael Schwarz (Graz University of Technology).[4] This "rogue data cache load" vulnerability has been assigned the Common Vulnerabilities and Exposures identifier CVE-2017-5754. There are also two other variants of this threat: "bounds check bypass" (CVE-2017-5753) and "branch target injection" (CVE-2017-5715).[2]

Process

With the push for electronics to operate at ever greater speeds, processors have begun using "speculative execution" in which they begin computing an expected task before the task has actually been assigned. Once started, it will be determined whether the expected task was correct or not. If the task was predicted properly, time is saved in the operation. If not, the thread must be dropped and it must start over, working on the task which was actually assigned. Although this may sound inefficient, predictions are often correct, so the management agent is able to complete tasks more quickly.
Unfortunately, but abusing the out-of-order processing of this "speculative execution," software is able to circumvent the system's protection of the kernel's memory addresses and gain direct access to the system's kernel. Once this access is gained, it can gather protected and sensitive information on what the operating system itself is doing, and on what some other programs are also doing. Almost anything processed by the computer could be potentially stolen.[1][5]

Solution

This vulnerability can be patched, by forcing the processor to execute operations in the proper order. This would restore the originally intended processing method and once again prevent access the the kernel's protected memory.[1] However, this comes at a cost. Since "speculative execution" was being used to increase processing speed, the removal of this feature will cause the devices to operate more slowly. Although Intel initially stated that this change probably would not have a noticeable impact on performance, Microsoft disagrees. They report that anyone using processors manufactured in or before 2015 will see a drop in speed.[6]
There were also some problems when the patch was first released, which were reportedly preventing some computers from turning on. This interrupted the patching process.[7]

References