• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back

2

When SpaceX starts trading, some 'shareholders' will discover they own nothing at all

3

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

1

Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back

2

When SpaceX starts trading, some 'shareholders' will discover they own nothing at all

3

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
TechIntel

Understanding Those Alarming Computer Chip Security Holes: ‘Meltdown’ and ‘Spectre’

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
January 4, 2018, 9:54 AM ET

A bomb cyclone hit the IT world on Wednesday as tech giants and computer security researchers released details pertaining to two major security holes that affect the processors in almost all computers. Researchers, including ones employed by the likes of Google, various tech firms, and academic institutions, independently discovered the flaws last year.

The vulnerabilities could allow attackers to swipe sensitive secrets from the memory of almost all devices, including phones, tablets, PCs, and computer servers. Experts have warned that hackers could develop exploits to purloin personal data, passwords, cryptographic keys, and other supposedly inaccessible information from targets.

Several programmers have already demonstrated proofs of concept for these so-called side channel attacks.

Using #Meltdown to steal passwords in real time #intelbug #kaiser #kpti /cc @mlqxyz @lavados @StefanMangard @yuvalyarom https://t.co/gX4CxfL1Ax pic.twitter.com/JbEvQSQraP

— Michael Schwarz (@misc0110) January 4, 2018

Silicon Scars

The flaws plague hardware produced by top chip makers like Intel (INTC) and Advanced Micro Devices (AMD), and Softbank-owned chip designer ARM Holdings. Big tech companies including Microsoft (MSFT) and Apple (AAPL) have been scrambling in recent weeks to address these threats by developing fixes for their software while cloud computing giants, like Amazon (AMZN) and Google (GOOG), have been rushing to apply patches to their data center infrastructure.

The first attack, dubbed “Meltdown,” applies specifically to Intel chips and allows hackers to circumvent the isolation barrier between user applications and operating systems, thereby opening up access to otherwise restricted machine memory. The second attack, “Spectre,” which is harder to pull off but has no available patches, lets hackers pry secrets out of the memory of devices running Intel, AMD, and ARM chips.

The Meltdown Mess

Per Meltdown, Apple and Microsoft have produced patches for Windows and macOS, as has the open source Linux project for its namesake operating system, although implementing these mitigations could cause computers to slow down by as much as 30%, researchers say. At the scale of a data center, such a performance hit could be severely detrimental to operations.

Intel countered in a statement that “any performance impacts are workload-dependent, and, for the average computer user, should not be significant and will be mitigated over time.”

Get Data Sheet, Fortune’s technology newsletter.

Amazon, Google, and Microsoft have all been applying the patches to their data center systems this week, the companies said. The companies were, in some cases, forced to act sooner than anticipated as news of the chip flaws began to trickle out online, causing the corporations to advance their disclosure timelines by a week.

Big Tech’s Response

Google, whose security researcher Jann Horn of the Project Zero team (see this Fortune profile of that ace hacker squad from last year) discovered both flaws, first alerted Intel to the problem, giving the company a headstart on the process. Other independent discoverers of Meltdown included Werner Haas and Thomas Prescher of Cyberus Technology and Daniel Gruss, Moritz Lipp, Stefan Mangard, and Michael Schwarz of Austria’s Graz University of Technology.

“We have updated our systems and affected products to protect against this new type of attack,” Google said in a statement Wednesday.

Microsoft said in a statement Wednesday that it had updated “the majority” of its Azure cloud infrastructure, though some aspects “are still being updated and require a reboot of customer [virtual machines] for the security update to take effect.” Official updates were originally expected to arrive as part of one of the company’s upcoming Patch Tuesdays on January 9th (though the company has been testing beta versions of the patches since November).

“The majority of Azure customers should not see a noticeable performance impact with this update,” Microsoft said.

Amazon issued a similar statement Wednesday: “All but a small single-digit percentage of instances across the Amazon EC2 fleet are already protected. The remaining ones will be completed in the next several hours, with associated instance maintenance notifications.”

Haunted by Spectre

Spectre—the more pervasive and more difficult to take advantage of the two flaws—has no clear solution as yet. While the U.S. Department of Homeland Security’s computer security advisory group US-CERT has suggested replacing affected CPUs, industry experts have countered that the recommendation is unfeasible.

Consumers and businesses should look to apply patches and workarounds if and when those become available.

Spectre’s discoverers include Google Project Zero’s Jann Horn, independent security researcher Paul Kocher, Daniel Genkin at the University of Pennsylvania and University of Maryland, Mike Hamburg at the American tech firm Rambus, Moritz Lipp at Austria’s Graz University of Technology, and Yuval Yarom of Australia’s University of Adelaide.

“It is not easy to fix, it will haunt us for quite some time,” Spectre’s discoverers warned.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Elon Musk stands behind the Nasdaq opening bell and in front of a "SpaceX" background.
Startups & VentureSpaceX
Founders Fund, Andreessen Horowitz, Valor, and the biggest VC winners from SpaceX’s IPO
By Allie GarfinkleJune 12, 2026
4 hours ago
Sven Gerjets, chief technology officer at Gap, speaks on stage on a panel at Fortune Brainstorm Tech 2026.
Future of WorkBrainstorm Tech
Why companies are treating AI as a strategic partner rather than a passive technology, and how to avoid an ‘AI hangover’
By Sebastian HerreraJune 12, 2026
5 hours ago
Elon Musk stands behind the Nasdaq opening bell and in front of a "SpaceX" background.
Future of WorkElon Musk
Despite his new trillionaire status, Elon Musk says money ‘will stop being relevant’ in the future because of AI
By Sasha RogelbergJune 12, 2026
6 hours ago
AI was supposed to cut health care costs. One of its first jobs was charging you more, PwC report shows
AIHealth Care Service
AI was supposed to cut health care costs. One of its first jobs was charging you more, PwC report shows
By Whizy Kim and Tech BrewJune 12, 2026
7 hours ago
paul
AIWorld Cup
Machine learning gives the U.S. a 1% chance of winning the World Cup final in its own backyard
By Achim Zeileis and The ConversationJune 12, 2026
7 hours ago
DoorDash wants you to stop scrolling and just tell its new AI chatbot what you’re hungry for
RetailDoorDash
DoorDash wants you to stop scrolling and just tell its new AI chatbot what you’re hungry for
By Dave Lozo and Morning BrewJune 12, 2026
7 hours ago

Most Popular

Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
Environment
Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
By Catherina GioinoJune 9, 2026
3 days ago
When SpaceX starts trading, some 'shareholders' will discover they own nothing at all
Investing
When SpaceX starts trading, some 'shareholders' will discover they own nothing at all
By Jim EdwardsJune 12, 2026
15 hours ago
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
Energy
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
By Sasha RogelbergJune 10, 2026
2 days ago
Current price of oil as of June 12, 2026
Personal Finance
Current price of oil as of June 12, 2026
By Joseph HostetlerJune 12, 2026
12 hours ago
American taxpayers have spent $33 billion on sports stadiums. They got fewer seats—and higher prices
Success
American taxpayers have spent $33 billion on sports stadiums. They got fewer seats—and higher prices
By Catherina GioinoJune 11, 2026
1 day ago
Current price of oil as of June 11, 2026
Personal Finance
Current price of oil as of June 11, 2026
By Joseph HostetlerJune 11, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.