Skip to main content

New ‘Prime’ Meltdown, Spectre exploits outlined by Nvidia, Princeton University

Just one month after researchers exposed methods to extract sensitive data from a device’s memory through all modern processors, another research paper arrives to illustrate how the processor design flaw can be used in other attacks. The paper, dubbing the new exploits MeltdownPrime and SpectrePrime, derives from three researchers who work at at Princeton University and graphics chip manufacturer Nvidia. 

As reported last month, all processors dating back to at least 2011 have a flaw in the way they’re designed. Part of a processor’s speed comes from its ability to predict where the current list of instructions will go — they have “branch prediction units” that take an educated guess about what command will come next. To make these predictions, processors toss data back and forth from two memory sets: local on-chip memory called cache for fast access, and the PC’s system memory. This data isn’t secured, and that’s where the original Meltdown and Spectre attacks come in. 

The Meltdown approach applies to Intel and Apple processors. A hacker can create a malicious program to access that raw information, which could include usernames, passwords, credit card numbers, and so on. It taps into the privileged information typically only accessible by the root of an operating system, otherwise known as the kernel. 

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

Meanwhile, Spectre applies to Intel, AMD, and all mobile chips based on ARM’s processor design, including Apple. Here hackers can create a program to trick the processor into executing instructions not built into legitimate programs and apps installed on the PC. In other words, your favorite apps and programs could be tricked into coughing up your sensitive data. 

Both methods are merely proof-of-concepts reported by Google Project Zero, and researchers from Cerberus Technology and various universities. Both are called side-channel attacks as they don’t target specific software, such as Adobe Flash. 

The new MeltdownPrime and SpectrePrime exploits rely on an attack called Prime+Probe that takes advantage of processor “cache invalidations,” which is a method of replacing or removing entries in the CPU’s cache. Whereas Meltdown and Spectre simply “pollute” this cache during the CPU’s path prediction (aka speculative execution), the new exploits take a different approach. 

“MeltdownPrime and SpectrePrime are caused by write requests being sent out speculatively in a system that uses an invalidation-based coherence protocol,” the paper states. A coherence protocol means that the PC is keeping all data stored in cache and memory consistent. But that protocol may “invalidate cache lines in sharer cores as a result of a speculative write access request even if the operation is eventually squashed.” 

The researchers validated their findings using a MacBook packing an Intel Core i7 processor, and MacOS Sierra v10.12.6. They ran the exploit 100 times on the machine, with a 99.95-percent success rate for SpectrePrime versus the 97.9-percent rate seen with the vanilla Spectre exploit. 

“We believe that any software techniques that mitigate Meltdown and Spectre will also be sufficient to mitigate MeltdownPrime and SpectrePrime. On the other hand, we believe that microarchitectural mitigation of our Prime variants will require new considerations,” the paper states. 

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
The first 300TB SSD is on the horizon
An SK Hynix SSD over a dark and orange background.

Some of the best SSDs we use are usually 1TB or 2TB, but consumer models go up to 8TB -- which is nothing in the context of a datacenter, and the latest announcement from SK Hynix puts that into perspective. The company revealed that it's currently developing a solid-state drive with a capacity of 300TB, which is a completely unprecedented size. Seeing these enormous SSDs in the flesh might take some time, though.

The company announced the new drive at a press conference in Seoul, South Korea. There are reportedly more interesting products on the way, including various memory solutions, and the focus is entirely on being able to support data centers as the era of AI progresses. According to Tom's Hardware, SK Hynix's market researchers claim that the global volume of data generated on a yearly basis is on an upward trend, and the increase is truly like nothing we've ever seen before. SK Hynix predicts that we'll see a jump up to 660 zettabytes (ZB), up from 15ZB in 2014.

Read more
Best Chromebook deals: Cheap computers starting at $54
HP Elite Dragonfly Chromebook front view showing display and keyboard deck.

If you want to grab yourself a Windows laptop but feel that the prices are pretty high, especially when it comes to the best laptops on the market, you may want to consider going for a Chromebook instead. That's because ChromeOS tends to be a lot more lightweight than Windows, so the specs you have can go a much longer way, and even the best Chromebooks don't cost as much as the best Windows laptops. Even better, you can still get some great Chromebook deals, which is why we went out and collected our favorites below, although if you'd still like to go with a laptop, these laptop deals are a good option too.
HP Chromebook 11A G6 Education Edition -- $46, was $244

Probably one of the cheapest options you're going to find for a Chromebook is this education edition that's made to be as basic as possible to bring the price down. The processor is a very entry-level AMD A4 9120C which is just about enough to get productivity tasks completely, and probably can't handle more complex tasks. The 4 GB of RAM isn't a lot either, but at least with ChromeOS not being as demanding resource-wise, you shouldn't feel it as much as you would on a Windows device. The biggest downside is the 16GB SSD, which means you will almost certainly have to rely on one of these external hard drive deals.

Read more
I would give up my Steam Deck if the ROG Ally 2 had these features
Lies of P running on the Asus ROG Ally.

Last year, I wrote about how I went back to my Steam Deck after using the ROG Ally for several months. Asus' device is a real competitor (read our Asus ROG Ally review to learn why), but there are a handful of aspects of the Steam Deck that make it the right handheld for me. That could change with the ROG Ally 2, however.

Rumor has it that Asus is gearing up to release an updated version of the ROG Ally for 2024. Even if this isn't an entirely new handheld, it's hard to imagine Asus will exit the world of handheld gaming PCs any time soon. And if it makes a few key changes to the next iteration of the ROG Ally, I might finally retire my Steam Deck for good.
No Windows lock screen

Read more