The world of technology continues to face the disclosure made on Wednesday regarding the very serious vulnerabilities in central processing units (CPU) that affect almost all computer users.
Two vulnerabilities were identified by researchers: Meltdown, which is believed to affect most Intel produced in the last 20 years, and Spectre, which affects processors produced by multiple companies, including Intel, AMD, and ARM.
Now, the emergency response team (CERT), the government organization for cybersecurity based at Carnegie Mellon University, has released its report on how to fix computers affected by the widespread bugs … and it is not economical.
The underlying vulnerability is primarily caused by CPU application optimization choices. Fully eliminating the vulnerability requires replacing the vulnerable CPU hardware.
If you are truly concerned about this, the safest thing you can do is purchase a new machine that does not have one of the vulnerable processors!
As Jack Morse noted yesterday, the Meltdown vulnerability could put you at risk:
… if you are running Windows, Linux or macOS, something as simple as JavaScript in your browser could theoretically gain access to the area of your computer that protects passwords.
Not only is the CERT's proposal an accurate one, but it indicates that if you really want to be sure you are safe, the patches released by various companies will essentially not fully fix the issue. They are not entirely useless, but they are also not complete and are likely to slow down computers with older processors.
As a rule, most private users need to be up to date with patches and with changes to browser settings. There are vulnerabilities that businesses and government organizations need to watch more closely, as they are more susceptible to hacking attempts, so they must ensure that everything is in a secure environment.
