Now that patches for the recently discovered Spectre and Meltdown have been widely deployed across various platforms, Google has broken down how it managed to address these threats in cloud services like Gmail and Search before the public learned about them. And it wasn't easy.
In a massive blog post on Thursday, Google's vice president of 24/7 operations, Ben Treynor Sloss, explains how tough these security holes are to patch and how long it took Google to fully fix them, even though it was Google's Project Zero team that discovered them in the first place.
According to Sloss, Spectre and Meltdown are actually three separate vulnerabilities, one of which – a variant of Spectre – was particularly difficult to address. One solution involved disabling certain CPU functions, which would inevitably lead to slower performance on devices.
"For months, hundreds of engineers across Google and other companies have been working tirelessly to understand these new vulnerabilities and find mitigations for them," he wrote.
Finally, software engineer Paul Turner created Retpoline, a software that does this job without slowing down the machines on which it is applied.
Sloss said that by December, all Google Cloud Platform services were protected against all variants of these vulnerabilities. The company implemented this solution across its entire infrastructure and opened it up so that others could benefit from it.
“This series of vulnerabilities was perhaps the most difficult to address in the last decade, requiring changes at multiple layers of the software stack and also requiring broad collaboration from the tech industry, as the scope of the vulnerabilities was so widespread,” Sloss writes.
