Intel Meltdown, Spectre Updates Roll Out for Older CPUs, Including Ivy, Sandy Bridge

Intel Meltdown, Spectre Updates Roll Out for Older CPUs, Including Ivy, Sandy Bridge

Intel has released a new set of updates for the Meltdown and Spectre bugs that we first learned about in early January. It’s critically important to patch and update systems to avoid exposure to these flaws.

Intel’s strategy has been to fix its newest systems first, followed by the earlier models. The fix rollout hasn’t been smooth; Intel had to pull back an entire set of updates and fixes at one point because they caused frequent reboot issues. Those problems have been resolved to the best of our knowledge, and anyone with an Intel CPU from any generation should be updating as soon as possible.

Intel has been steadily updating its microcode document as new fixes roll out. This time around, we’ve got patches for the Ivy Bridge and Sandy Bridge families, plus various server variants of both chips, as well as some Haswell cores that weren’t previously covered. The chips that still need to be patched are all older than Sandy Bridge, including Intel’s 32nm Westmere parts (the first six-core CPUs based on Nehalem), the quad-core Nehalem architecture (Bloomfield, Lynnfield), and several mobile 32nm chips like Arrandale and Clarkdale.

Intel Meltdown, Spectre Updates Roll Out for Older CPUs, Including Ivy, Sandy Bridge

In addition to patching up the entire Nehalem family tree, Intel will also be delivering patches for some older Core 2 Quad and Core 2 Duo processors, though these patches are still in the early stages of production. The company has taken heat for how it handled the unveil and rollout, but at least as far as the technical side of things, Intel seems to have the problem well in-hand with fixes dropping on a regular basis.

That’s a good thing, seeing as Spectre can be used to break the protections Intel offers with SGX (Software Guard Extensions). This latest research paper doesn’t identify a new attack in addition to the two Spectre variants, it just (“just”) illustrates how those two flaws can be used to crack into other secure repositories to give would-be thieves access to yet more information. That’s part of what makes Spectre and Meltdown serious. They’re not just flaws in and of themselves; they’re flaws that can be exploited to exfiltrate data out of other supposedly secure repositories.

If your motherboard manufacturer hasn’t issued any updates for your system, keep an eye on Windows Update. Microsoft has been delivering microcode updates for Intel systems, including through KB4090007. That update only runs through the end of February; it’s not clear if MS will create a new update to patch up Haswell and previous processors, or if it’ll keep the same KB number but roll up the latest changes. The performance impact of these patches on Sandy and Ivy Bridge still hasn’t been tested; newer CPUs have seen modest declines on the order of 5-7 percent, with a few outliers as high as 13 percent

Continue reading

Report: Stadia Missed Active User Targets by Hundreds of Thousands
Report: Stadia Missed Active User Targets by Hundreds of Thousands

According to a report in Bloomberg, Google blew millions of dollars to get games like Red Dead Redemption 2, but it still missed active user targets by hundreds of thousands of units.

States Claim Google’s ‘Privacy Sandbox’ Violates Antitrust Law
States Claim Google’s ‘Privacy Sandbox’ Violates Antitrust Law

Google finds itself in an impossible position. Privacy advocates have long demanded Google follow Microsoft and Mozilla's lead in purging tracking cookies from Chrome. Now that it's doing so, state attorneys general have filed an amended antitrust complaint that uses the so-called "Privacy Sandbox" as ammunition against the company.

NASA’s Mars Lander Cleaned Sand Off Its Solar Panels Using More Sand
NASA’s Mars Lander Cleaned Sand Off Its Solar Panels Using More Sand

NASA's InSight lander has been on the red planet since 2018, and it relies on solar panels for power, which means there's the potential for dust build-up. Luckily, JPL engineers devised an ingenious way to get the sand off the panels.

NASA: Mars Was Rocked By Thousands of Gigantic Volcanic Explosions
NASA: Mars Was Rocked By Thousands of Gigantic Volcanic Explosions

NASA scientists have uncovered evidence of explosive supervolcanoes in Arabia Terra, a battered upland region that we think is one of the oldest terrains on the planet.