Meltdown and Spectre: The recent flaws in the architecture of many processors manufactured over the past two decades are the latest security crisis to hit the IT industry.
The phenomena have come to confirm once again what many know but have difficulty admitting: no one should think of their system as secure. It is much more valid to recognize a system as “stable” and of course as potentially insecure. 
This means thinking of security as an ongoing process and not as an endpoint.
The Spectre and Meltdown flaws have been present in most Intel CPUs since 1995, and other chip manufacturers are also affected.
To many, it may seem inconceivable that such serious weaknesses have remained unpatched for so many years (the joy of the NSA). However, it is simply a function of the incredible complexity of the systems we all use. A long time ago, there was another: Remember Heartbleed? The flaw in the OpenSSL cryptographic library that was released with its own logo and caused panic in IT worldwide. Remember Shellshock? The WannaCry ransomware?
Security is a utopia and believing that your systems are completely secure is living a very dangerous illusion. Just assume that your systems are insecure, and you will start making better decisions.
Security ceased to exist with the arrival of the internet, but many of us do not seem to have realized it. Spectre and Meltdown are two good examples, because they can affect everything from the PC at your desk and the smartphone in your pocket to the cloud service you use to store your data. No matter how good you are at “security”, today you rely on a constellation of service providers and their various partners.
The code of any software, operating system, or firmware shipped by vendors is inevitably imperfect, so there will always be updates. Applying these fixes is considered a tedious and thankless job by many IT. Especially in corporate environments, where each update should be checked by IT, so that they are sure that they will not cause problems during their application. So many times updates are not the first priority, although they should be. The WannaCry ransomware was released last year, although Microsoft had released a patch.
Of course, hackers know this too. Updates exist, but there are also systems that are not updated.
So, where is the security?
If you assume that there is no security, you will have a better chance of circulating on the internet and being safe. The goal of this article is to make you suspicious.
There are no companies that can protect you, and if they promise to, they are lying. Safety means knowing that it doesn't exist, which prepares you for worst-case scenarios.
Meltdown and Spectre: They will happen again…and again
📧
Subscribe to the SecNews Newsletter
