ZombieLoad is Meltdown resurrected. Here’s how to secure your PC right now

Mark Coppock/Digital Trends

Less than a year and a half since Intel had its first public meltdown after finding the highly publicized Meltdown and Spectre security flaws, researchers have discovered a new security vulnerability called Microarchitectural Data Sampling (MDS) — which leaves computers dating back to 2008 vulnerable to eavesdropping attacks.

Fortunately, Intel learned its lesson from the first Meltdown discovery, and it finds itself better prepared to address the recently published security flaw that, if unpatched, could leave computers — ranging from laptops to cloud-based servers — exposed to eavesdropping by an attacker.

Back from the grave

A series of updates were recently deployed to address the newly uncovered security flaw. Whether you’re on a Windows PC or a Mac, you should stay up to date with your security patches to mitigate the risk of attack. Business customers operating their infrastructure from the cloud should check with their service providers to ensure that that latest available security patches will be applied as soon as possible.

MDS was discovered by a wide range of researchers from security firms like Bitdefender, Cyberus, Oracle, and Qihoo360 as well as academic institutions like the University of Michigan, Vrije Universiteit Amsterdam, KU Leuven in Belgium, Austria’s TU Graz, University of Adelaide, Worcester Polytechnic Institute, and Germany’s Saarland University. Researchers have discovered four distinct ways of carrying out MDS attacks, and though some of the attacks were discovered more than a year ago, Intel had asked that the researchers to keep their findings private until a patch was available.

“Academics have discovered four such MDS attacks, targeting store buffers, load buffers, line fill buffers (aka the Zombieload attack), and uncacheable memory — with Zombieload being the most dangerous of all because it can retrieve more information than the others,” ZDNet reported. Some of the attacks, researchers cautioned, could even require hardware changes to the chips to mitigate. Intel claims that some of its chips released within the last month already ship with a fix.

While MDS works in a similar way to Meltdown and Spectre by relying on Intel’s use of speculative execution to boost CPU performance by allowing the processor to guess what data will be required for execution in advance, attackers are able to eavesdrop when data is moving between various components of a processor. In previous attacks, sensitive data was accessed from memory, but in the case of MDS, the data can be accessed from the cache. Anything that passes through the processor, from the website you’ve visited to your password and credit card data, could be accessed through MDS. Hackers can even leverage MDS to extract the decryption keys to an encrypted drive.

Fixing Intel’s chipocalypse

Walden Kirsch/Intel Corporation

Intel has readied a fix for MDS, but the patch will need to be deployed through different operating systems. For now, Apple claims that a recent update to its MacOS Mojave operating system and Safari desktop browser already included the fix, so Mac users should download the latest updates if they haven’t already done so. Google also claimed that its recent products already contains a fix, while Microsoft issued a prepared statement stating that a fix will be ready later today. Windows 10 users are advised to download this patch.

“We are working to deploy mitigations to cloud services and release security updates to protect Windows customers against vulnerabilities affecting supported hardware chips,” Microsoft said.

Amazon Web Services have also deployed fixes. “AWS has designed and implemented its infrastructure with protections against these types of bugs, and has also deployed additional protections for MDS,” AWS said in a statement. “All EC2 host infrastructure has been updated with these new protections, and no customer action is required at the infrastructure level. Updated kernels and microcode packages for Amazon Linux AMI 2018.03 and Amazon Linux 2 are available in the respective repositories (ALAS-2019-1205).”

Though chips released starting last month already contained a hardware level fix, Intel claims that microcode updates are enough. “For other affected products, mitigation is available through microcode updates, coupled with corresponding updates to operating system and hypervisor software that are available starting today,” the chipmaker said in a statement.

Security researchers from TU Graz and VUSec disagreed with Intel’s conclusion and advised that hyperthreading be disabled, as this process could make it easier for attackers to carry out MDS attacks. In an interview with Wired, Intel downplayed the flaw rating the four vulnerabilities at a low to medium severity, and the company claimed that disabling hyperthreading is not necessary. Intel claims that a lot of noise is also leaked, and it would be very difficult for an attacker to infer your secret data.

At this point, AMD and ARM silicon are not affected by the vulnerability. If your system is running an Intel chip, be sure to apply the latest software patches and check for any new system updates in the coming days.

Computing

How talk of 5G and Wi-Fi 6 has displaced higher core counts and clock speeds

At Computex this year, there was no shortage of big processor announcements from the likes of AMD, Intel, and Qualcomm. But amidst the usual talk of clock speeds and core counts was a surprising emphasis on connectivity as a form of…
Small Business

The 15 best tech jobs boast top salaries, high satisfaction, lots of openings

May may be coming to an end, but the bonanza of tech jobs just keeps coming. High-paying jobs abound at companies where people love to work. If you’re ready to make a change, this is a great time to look for something more fulfilling…
Movies & TV

Who needs sunshine? Stay inside and watch the best movies on Netflix instead

Save yourself from hours wasted scrolling through Netflix's massive library by checking out our picks for the streamer's best movies available right now, whether you're into explosive action, witty humor, or anything else.
Computing

At Computex, Intel has given us our first true look at the future of its chips

Intel's 10th-gen chips have arrived, and they're to be based on the 10nm process that has given it so much trouble over the past year. We now some of the specifics if its initial roll-out on mobile, which will be fairly limited to begin…
Mobile

WWDC 2019: From iOS 13 to a new Mac Pro, here’s what to expect

Apple's Worldwide Developer Conference is the best place to see Apple's latest software and announcements, and it's coming today. But what can you actually expect to see? Here's what we expect at Apple WWDC 2019.
Computing

Nvidia’s Super reveal might derail AMD’s RX 5000 debut at E3

Nvidia's teased Super graphics cards could be just around the corner with the latest rumors suggesting we'll get a glimpse at E3 2019. That could take the wind out of AMD's sails, as it plans to reveal its RX 5000 cards at the big show.
Computing

iTunes had to die to be reborn, and it’s making me nostalgic

Apple’s decision to kill off iTunes-as-we-know-it, as announced during WWDC 2019, makes me nostalgic because I still rely on iTunes today for the same reason it was created back in 2001.
Computing

RIP Andromeda, and long live Microsoft’s dual-screen Centaurus PC

Microsoft may be closer to launching a dual-screen PC, which could occur as early as this year. It's been reported that the Surface team has shown off a prototype of the dual-screen Centaurus device internally to employees.
Computing

Apple’s new sign-in feature brings a secure way to log in to your iOS 13 apps

Apple is appealing to security-conscious users by making it easy for users to sign in to their favorite apps with their Apple ID. Unlike similar solutions, Apple's sign-in button comes with added security and privacy features.
Apple

WWDC 2019 Complete Coverage

Apple’s Worldwide Developer Conference is a key tech event each year, and for Apple fans, it will be one of the two best times of 2019 (along with "new iPhone day," of course). For the last few years, Apple has debuted much of its…
Computing

Apple's beefy new Mac Pro looks like a cheese grater, costs serious cheddar

At its annual WWDC event, Apple gave consumers the first look at its powerful new creative device, the Mac Pro. The behemoth machine on display in San Jose features powerful internals and ample expansion capability.
Computing

Apple has finally killed off iTunes. Here’s what’s replacing it

At its annual and perennially anticipated WWDC, Apple announced its plans to finally phase out iTunes in MacOS Catalina. Here's what you need to know about the death of Apple's long-running app, and what's replacing it.
Computing

Apple’s new 6K display costs $5,000 and can maintain 1,000 nits of brightness

Apple just unveiled its studio-grade Pro Display XDR monitor for creative professionals. Starting at $5,000, you're getting a 6K resolution screen with excellent contrast, calibrated HDR support, and a bright and vivid panel.
Computing

The new Mac Pro starts at $6,000 and comes with an interesting modular design

Our Mac Pro 2019 rumor roundup covers all the news, leaks, and rumors about Apple's new machine, set to be announced sometime in 2019. Here's what Apple has said, what the experts think, and what we're likely to see with the new Mac Pro.