Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Spectre And Meltdown Vulnerabilities Affect Processors In Wide Range of Computing Devices

By Kathleen Porter on January 11, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

This week, the world learned of widespread and serious vulnerabilities in most central processing units (CPU). CPUs manage the instructions received from the hardware and software running on a computer.  The vulnerabilities, named Meltdown and Spectre, affect virtually every computer existing today, in particular those with Intel, Advanced Micro Devices, Inc. (AMD), Nvidia and Arm Holdings (ARM) processors.

Spectre and Meltdown essentially permit unauthorized access to an operating system’s secure and secret kernel memory, which often contains highly sensitive data, such as passwords, secret keys and other credentials as well as personal photos and emails. Generally, any personal or desktop computer, laptop, cloud system, mobile device, tablet or other computing device that uses these processors is vulnerable.   In addition, Intel processors are used in a wide array of products, from personal computers to medical equipment.   For a detailed technical description of how the vulnerabilities can be exploited, see https://googleprojectzero.blogspot.gr/2018/01/reading-privileged-memory-with-side.html

Initially, the Software Engineering Institute (SEI), a U.S.-government funded body operated by Carnegie Mellon University for the U.S. Department of Defense researching cybersecurity problems recommended replacing the vulnerable processor hardware in order to remove the threat.  However, SEI subsequently amended its advice to say that software solutions should be pursued and quickly downloaded to mitigate against the vulnerabilities. Software solutions, patches and workarounds may not resolve the vulnerability and may actually affect system performance, but at this time they are the only known feasible measure to mitigate these vulnerabilities.

A bit of good news is that The European Union Agency for Network and Information Security (ENISA), which advices on cybersecurity matters for the EU reports that at this time, there are no known documented exploitations of these vulnerabilities.  See https://www.enisa.europa.eu/publications/info-notes/meltdown-and-spectre-critical-processor-vulnerabilities

 

Photo of Kathleen Porter Kathleen Porter

Kathy Porter’s practice straddles the areas of intellectual property, business transactions, trade regulation, and Internet law and includes import/export control issues, such as compliance and enforcement, competition, privacy, and data security. She counsels businesses on the development and implementation of data security and…

Kathy Porter’s practice straddles the areas of intellectual property, business transactions, trade regulation, and Internet law and includes import/export control issues, such as compliance and enforcement, competition, privacy, and data security. She counsels businesses on the development and implementation of data security and privacy practices to comply with the patchwork of laws and rules applicable to the collection, use, safeguarding, sharing, and transfer of protected or personal data. She regularly structures arrangements with promoters, marketers, website exchanges, and other third parties for the purchase, sale, sharing, and safeguarding of personal data. Kathy prepares and negotiates representations, warranties, and indemnities regarding personal or protected data and privacy and data practices. She also assists clients with privacy audits and works with third-party certification organizations to obtain certification of companies’ privacy practices. She guides clients through internal investigations to assess and address notice and other obligations regarding privacy breaches. Kathy often works closely with our litigation attorneys to manage external investigations such as those by federal or state regulators. Read her rc.com bio here.

Read more about Kathleen PorterEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo