This tag is for questions specific to the so-called "spectre" processor vulnerability and its mitigation.
Questions tagged [spectre]
24 questions
13
votes
2 answers
can the spectre security vulnerability be in a virtual machine?
Is it possible that a virtual machine like VirtualBox has the security vulnerability "spectre"?
I think the VM maybe does out-of-order execution, but in my opinion it is not possible to peek at the cache to read the result.
Is there any explanation…
user521153
4
votes
2 answers
If Spectre and Meltdown OS patches are not applied on a Windows system, can other new Microsoft patches be applied?
In this Information Security QA, we thoughtfully discuss whether or not patching for Spectre and Meltdown are necessary on Windows boxes.
Some will undoubtedly decide they want to patch certain Windows boxes, while others will decide they don't want…
RockPaperLz- Mask it or Casket
- 7,741
- 30
- 73
- 122
2
votes
1 answer
How to install macOS software from source to mitigate Spectre 2?
I attended a presentation on Spectre and Meltdown by a UCL professor. He suggested several ways to mitigate Spectre 2 (Branch Target Injection) by upgrading to High Sierra and installing all software from source with the switch --mretpoline (already…
miguelmorin
- 1,817
- 4
- 15
- 26
2
votes
3 answers
Do Spectre&Meltdown microcode updates slow down the computer?
I have a question about Meltdown and Spectre.
As far as I understood, the Windows patches are just workarounds and what really needs to be done are microcode updates
Microsoft says that the computers will get slower due to the windows patch.
My…
Daniel Marschall
- 317
- 2
- 5
- 17
1
vote
0 answers
What versions of Windows use the PCID feature to speed up Meltdown patch?
I have Windows 7 Enterprise SP1 64 bit with an Intel i7-6820HQ (with latest microcode rev 0xC6) and InSpectre #8 says I have both protections, but SLOWER.
Is it because Windows 7 does not use the PCID feature? Which versions do use it?
Pictures:
PS…
David Balažic
- 1,844
- 3
- 31
- 58
1
vote
1 answer
How can I set "generic retpoline" as default because LFENCE does not serialize on my PC?
I have Fedora 27 installed on my laptop with an older AMD CPU (AMD Turion X2 mobile processor RM-75 / 2.2 GHz). The following error message appears every time I boot:
Spectre V2: Spectre mitigation: LFENCE not serializing, switching to generic…
Sbalian
- 11
- 1
- 3
1
vote
1 answer
What to do with a i5-5200U CPU running Win 8.1 in regards to Spectre and Meltdown?
I have a Lenovo g50-80 with an Intel i5-5200U CPU running Windows 8.1 64bits with all updates installed and no new updates available (only 2 optional ones that are irrelevant here). I just ran InSpectre and I am not protected whatsoever! :-( I'd…
ASR
- 11
- 1
1
vote
0 answers
Spectre/Meltdown- Lenovo M800 BIOS update does not appear to work
So I've got a Lenovo ThinkCentre M800, running Windows 10 x64, 1709. I've applied their latest BIOS Update which is version FWKT86A, and then ran Get-SpeculationControlSettings (From the Speculation Control PS module which determines if your PC is…
ztnd13
- 121
- 2
- 7
1
vote
1 answer
My BIOS is outdated. Will I be affected by Meltdown and Spectre?
I had made the mistake of buying a Lenovo Laptop. The model is Lenovo Flex 2-14.
This laptop has a bios from 2014 and Lenovo never issued an update.
I've been reading on some major sites that BIOS must also be up to date to prevent the latest…
Sameer M
- 11
- 2
1
vote
0 answers
What should I do about Meltdown and Spectre vulnerabilities with my Linux system?
I have GNU/Linux running on an (obviously recent enough) Intel CPU. I've heard about the grave security flaws which have surfaced, Spectre and Meltdown, although I haven't read the details yet.
I've read there's been work done to patch kernels and…
einpoklum
- 8,783
- 20
- 84
- 153
0
votes
0 answers
Does Windows 8.1 contain updates when downloaded with the Media Creation Tool?
If I download Windows 8.1 (to install on another PC) using Microsoft's Media Creation Tool would it include many recent updates, and of what kind? (I can find no recent answers). I'm presuming that it would the most recent build number.
Are there…
Eric
- 87
- 1
- 8
0
votes
0 answers
Trying to enter the BIOS setup with the F10 key hangs my HP Spectre x360 13
This question is not about how to get into the BIOS but a slightly different problem: to make the story short (TL;DR): when I hit F10, the machine does not go to BIOS setup but is stuck.
Long version: on my HP Spectre x360 laptop (mid-2018), with a…
David Bellot
- 101
- 1
0
votes
0 answers
Should I still worry about spectre in 2020?
I use a laptop that has a 4th gen Intel CPU. I may soon beginn working on sensitve data.
Is Spectre something I should still worry about? Should I upgrade my laptop?
user2741831
- 363
- 2
- 15
0
votes
0 answers
How to disable user pointer sanitization
I’ve got a python (so single threaded) intensive process performing a lot of context switches that need to run during days.
Despite using nopti noibrs noibp nospec_store_bypass_disable spectre_store_bypass_disable=off pti=off nospectre_v2…
user2284570
- 1,799
- 7
- 35
- 62
0
votes
0 answers
MacBook Pro 2018 Spectre/Meltdown
I have a question about the Spectre/Meltdown security on Mac.
To mitigate the problem I guess also the microcode update of the processor is needed.
How does Apple handle this? Do I need to update BIOS manually or is everything done…
Alex
- 21
- 2