It seemed that after the vulnerabilities Meltdown and Spectre were discovered over a year ago, nothing could scare Intel processor fans and users anymore. Yet, the company managed to surprise us again. More precisely, vulnerability researchers in Intel's microarchitecture caught our attention. A package under the collective name microarchitectural data sampling (MDS) threatens to put an end to multi-threaded computing technology or Hyper-Threading (more generally — simultaneous multithreading, SMT). It turned out that an attack using one of the MDS variants could break the isolation of one of the Hyper-Threading threads and facilitate access to sensitive data in buffers and ports of processors (one level below Level 1 cache). What should be done about this? The first thought is to disable Hyper-Threading, which is exactly what the ChromeOS developers did. What will happen to the performance of processors? It will decrease. The degree of slowdown can reach 40%, or even more.

So far, not many operating system and application developers have followed in the footsteps of ChromeOS, but patches and updates . Apple released updates for its branded computers and laptops sold since 2011. According to the company, all systems running macOS Mojave 10.14 have already been . This will prevent attacks through Safari and other applications. Meanwhile, most users should not feel a drop in performance. Complete threat prevention, however, implies disabling Hyper-Threading, which could reduce performance by up to 40%. Patches for Sierra and High Sierra will also be released. The vulnerabilities do not affect iPhone, iPad, and Watch products.
Google is preparing patches for Android and will update Chrome. It should be noted that Android needs to be protected from MDS vulnerabilities only on x86-compatible platforms (a specific thanks to Intel for Atom processors). Device manufacturers should release patches for smartphones and tablets on Intel platforms, while Google is ready to distribute the necessary corrected code. Chromebooks (Chrome OS) are already patches against new vulnerabilities, and in the future, the operating system itself will be fixed for this purpose. At the same time, Google urges users to ensure that device manufacturers have released the necessary patches and/or that these patches have been provided to Microsoft and Apple as the operating system developers. For cloud platforms and data centers, Google has already patches to protect server processors from MDS.
Mozilla, the developer of the Firefox browser, will present patched versions of the application on May 21. These will be Firefox versions 67 and Extended Support Release version 60.7. Firefox Beta and Firefox Nightly browsers already include the necessary fixes to protect against the new vulnerability.

Microsoft has also released patches for operating systems and cloud platforms. However, the company recommends obtaining the corrected microcode from device manufacturers, although it has also created for manual download of fixes. The patch has also been included in the automatic update package via the Windows Update service and will be distributed starting Thursday. Microsoft Azure is already protected against new vulnerabilities. The Amazon AWS cloud service has also .
Finally, patches for Linux operating systems such as and . Stay tuned.
Source: 3dnews.ru
