Forum Home
Press F1
 
Thread ID: 145730 2018-01-15 19:07:00 BIOS Updates for the Meltdown and Spectre Patches Lawrence (2987) Press F1
Post ID Timestamp Content User
1444838 2018-01-15 19:07:00 Motherboard makers are updating BIOS's for boards so keep a eye out here www.bleepingcomputer.com

Surprised if any Board older than 5/7 years gets a update but still will pose a security risk
Lawrence (2987)
1444839 2018-01-15 19:13:00 The Dell Optiplex 9010 that I run here got one last week. Rather impressed. wratterus (105)
1444840 2018-01-15 22:46:00 It will be interesting to hear any reports of slow downs as has been suggested may happen.

Of course it may all be a ruse to get people to buy the latest gear.
Terry Porritt (14)
1444841 2018-01-15 23:39:00 Never mind the slowdowns....it's meant to be a hacker target too right?

So how many have been affected over the last 10 years it has been in existence?
piroska (17583)
1444842 2018-01-15 23:46:00 None because no one knew about it, if they'd have kept quiet, we'd all be sleeping soundly in our beds instead of running around like headless chickens :banana Terry Porritt (14)
1444843 2018-01-16 00:12:00 They have been all sorts of issues with rushed out patches , so may pay to wait a bit ?

All that can happen is hackers can read (only) whats in system memory or CPU cache at the time. From what Ive briefly read about it.
So, after online banking, restart the PC. :)

Disable java , install adblockers & web script blockers
Browsers will be patched by end of month
They have to have access to the ~PC~ to be able to use these vulnerabilites .
1101 (13337)
1444844 2018-01-16 00:27:00 Firefox and I think Chrome have already been patched. And probably Edge

There is also a firmware update for TPM 1.2/2 modules if you've got one. Since TPM's have a vulnerability as well. The link is in the other forum

I wont hold my breath for a BIOS update. ASUS couldnt be bothered fixing their TPM modules. I doubt they'll do anything about their mobos
Speedy Gonzales (78)
1444845 2018-01-16 03:19:00 I wont hold my breath for a BIOS update .

Im seeing reports of Chrome & FF being patched & not yet patched .
Chrome not patched ,or is it :)
. chromium . org/Home/chromium-security/ssca" target="_blank">www . chromium . org
Chrome's JavaScript engine, V8, will include mitigations starting with Chrome 64, which will be released on or around January 23rd 2018 . Future Chrome releases will include additional mitigations and hardening measures which will further reduce the impact of this class of attack . Additionally, the SharedArrayBuffer feature is being disabled by default . The mitigations may incur a performance penalty .

Firefox, yes & no
"Firefox 52 ESR does not support SharedArrayBuffer and is less at risk; the performance . now() mitigations will be included in the regularly scheduled Firefox 52 . 6 ESR release on January 23, 2018 . "

Bios updates . God, I shudder at the thought
Its bad enough with the wrong bios on the manufacturers site , now with rush rush rush will be a greater risk of bios updates bricking PC's
It happens, I've bricked a brand new HP because the bios update on HP's site was incorrect for the board (they replaced it under warranty)

I'd guess most mb's wont get patches .
Brand name PC's will get patched on newish hardware .

Most of the Androids out there NEVER get any patches or Android updates anyway, so they'll remain even more insecure .
I wonder where the CGA comes in with all this . Unpatched hardware : no longer 'fit for purpose'
1101 (13337)
1444846 2018-01-16 03:30:00 FF 57.04 fixes it

Security fixes to address the Meltdown and Spectre timing attacks
Speedy Gonzales (78)
1444847 2018-01-16 06:19:00 Wha'ts the point of BIOS updates 99% of the population either don't know or can't be bothered to install a new version gary67 (56)
1 2