By Darren Allan
Remember the Meltdown and Spectre fixes that Intel is baking into its processors to make them bulletproof to these vulnerabilities at a silicon level, and which are expected to be incorporated into new CPUs that ship later this year? Well, it’s allegedly the case that those countermeasures won’t defend these chips against a new freshly-discovered Spectre flaw.
Earlier this week came the official revelation that there is a fresh strain of Spectre – Variant 4, known as Speculative Store Bypass – which leverages similar vulnerabilities to the existing variants, although Intel noted it uses a different method to crack into the sensitive data held in your computer’s memory.
And, according to sources who spoke to Threatpost, the aforementioned safeguards which Intel is implementing may protect against Spectre Variants 2 and 3, but not this fourth incarnation.
There may also be further spins along these sort of speculative execution side channel vulnerabilities in the future, the sources further noted (which is precisely why Microsoft, for one, recently kicked off a major bug bounty program with big rewards for those who flag up these issues).
At any rate, Intel isn’t leaving processors undefended against Variant 4, of course, even if it …read more
Source:: techradar.com – Computing Components