The bad news just doesn’t seem to stop where Intel and the Speectre vulnerability are concerned. The latest bit of news comes directly from Intel, as the company admits that it’s just not possible to address the Spectre vulnerability in some of its older hardware. This means that nine families of chips and more than 230 models of computers (mostly manufactured between 2007 and 2011) will remain vulnerable to Spectre forever.
The company has stopped Spectre mitigation development on the following families of chips:
Bloomfield
Clarksfield
Gulftown
Harpertown Xeon
Jasper Forest
Penryn
SoFIA 3GR
Wolfdale
Yorkfield
A company spokesman had this to say about the recent announcement:
“We’ve now completed the release of microcode updates for Intel microprocessor products launched in the last 9+ years that required protection against the side-channel vulnerabilities discovered by Google. However, as indicated in our latest microcode revision guidance, we will not be providing updated microcode for a select number of older platforms for several reasons, including limited ecosystem support and customer feedback.”
It’s unfortunate, but not entirely unexpected. If you have any older Intel equipment still in service at your company, have your IT group check the processor family. If it’s one of the above, it’s well worth marking those systems high priorities for upgrades, and limiting their use until you can.
Spectre is a devastating flaw, and it’s just not worth the risk to leave exposed systems connected to your network and in service. This is especially true now that it’s official that no help is coming for certain older systems.
Even worse, AMD chips, which are not impacted by Spectre and Meltdown, have since been found to have their own critical security flaws. While not as bad or as pervasive as the two Intel is facing, they will nonetheless require the company to issue its own microcode updates, which they are currently scrambling to do.
The long and the short of it is that there really are no safe harbors anymore.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Microsoft recently made small but significant changes to its Office 365 subscription service and to OneDrive, which are often used in tandem. The goal is to make it easier for users whose files have been encrypted by ransomware (or otherwise corrupted) to recover them.
Congratulations to Adobe Flash Player for not being the software most targeted by hackers. Security vendor “Recorded Future” has just published their annual list of the software hackers most commonly focus on when targeting computers and handheld devices for attack.
Last year’s Wannacry attack was bad, but in many ways, it was a self-inflicted wound. According Webroot’s recently published “Annual Threat Report,” almost all of the machines that succumbed to the Wannacry attack were running Windows 7. That attack is estimated to have caused in excess of $4 billion in total losses.
There’s a lot to talk about in Apple’s latest update to iOS. Version 11.3 boasts some significant changes and is well worth getting. We’ll go over the highlights below.
If you use Amazon’s Cloud MP3 Locker to store your music online, now is the time to start looking for a new home for it. Last year, the company announced that they were ending the service, but didn’t provide a firm date. April 30, 2018 will be the last day you’ll be able to access your music if you don’t take action.
There are some big changes coming to Facebook, which may have some serious unintended consequences.
Another week, another high-profile data breach. This time, it’s Under Armour in the hot seat. Under Armour acquired the MyFitnessPal app back in February 2015, and the company recently announced that their new acquisition was hacked in late February 2018.
There’s a new type of hacking attack to be concerned with, and it’s growing by leaps and bounds. Called “Crypto-Jacking,” it’s a process by which malicious code is placed on websites. When the sites are visited, the code secretly siphons off a portion of the affected user’s PC, laptop, or smartphone’s processing power and uses it to mine for various cryptocurrencies so that the hackers can profit from it.
If you are a fan of, and regularly use Goo.gl (the URL shortener service), brace for impact. The company has announced that as of March 30, 2019, the service will be shut down for good. Long before then, beginning April 18th of this year, only existing users will be able to shorten links via goo.gl. No new signups will be allowed.