# Security threats to computer chips- how to proceed?

**URL:** <https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981>\
**Category:** Factual Questions\
**Created:** [January 6, 2018, 4:08pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981 "2018-01-06T16:08:24Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cartooniverse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cartooniverse/32/3084_2.png) [@Cartooniverse](https://boards.straightdope.com/u/Cartooniverse)\
**Post date:** [January 6, 2018, 4:08pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/1 "2018-01-06T16:08:24Z")

</div>

Been following the stories for a few days. Sufficiently impressed that this isn’t just a Chicken Little situation.

Here’s the thing. I use an Android phone. I asked it to look for software updates a few days ago. No updates were offered.

I also use a Macintosh. ( OS-X 10.12.6 Sierra ). Cannot find an update that dates from this week.

[This CNN article details the overall story, with links.](http://money.cnn.com/2018/01/04/technology/spectre-meltdown-cpu-flaws-explainer/index.html).

[This security note linked in the above CNN article is from a Carnegie Mellon University center and details the issues.](https://www.kb.cert.org/vuls/id/584653%22=)

No fixes. No patches to download.

You cannot splash shit around on the media, with huge font screaming headlines that read " UPDATE YOUR SOFTWARE TODAY. SERIOUSLY ", without providing the fucking patches or downloads.

Anyone actually _found_ the appropriate patches and updates? I for one would be interested in seeing them and downloading them.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [January 6, 2018, 4:17pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/2 "2018-01-06T16:17:28Z")

</div>

OS X 10.13.2 has a mitigation patch.

---

<div class="post-metadata">

**Author:** ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)\
**Post date:** [January 6, 2018, 5:03pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/3 "2018-01-06T17:03:35Z")

</div>

Apple’s recent update on the situation:

> **[About speculative execution vulnerabilities in ARM-based and Intel CPUs](https://support.apple.com/en-us/HT208394)**
>
> Apple has released security updates for macOS Sierra and El Capitan with mitigations for Meltdown.
> Apple has released updates for iOS, macOS High Sierra, and Safari on Sierra and El Capitan to help defend against Spectre.
> Apple Watch is unaffected by...

Android is more complex, it’s dependent on the how old the phone/OS is and which company controls the updates (e.g. Google, Verizon, etc.).

Article with some phone/tablet info:

> **[How the Spectre and Meltdown CPU flaws affect phones and tablets](https://www.pcworld.com/article/407771/spectre-cpu-faq-phones-tablets-ios-android.html)**
>
> The CPU flaw isn't just limited to PCs and Macs anymore. The Spectre vulnerability affects mobile devices and your phone is likely at risk. Here's what it is and how you can mitigate the risks.

“How can it be fixed in non-Google phones?  
Just like Meltdown, Spectre can only be mitigated via software. Some newer Android phones (such as certain versions of the Samsung Galaxy S8 and Note 8) have already received Google’s December security update, and other manufacturers should start pushing out their own updates within the next few weeks, as well as Apple’s iOS devices. However, many Android phones will likely remain vulnerable.”

"However, even if you have a phone that’s vulnerable, Google notes that “exploitation has been shown to be difficult and limited on the majority of Android devices.”

---

<div class="post-metadata">

**Author:** ![Cartooniverse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cartooniverse/32/3084_2.png) [@Cartooniverse](https://boards.straightdope.com/u/Cartooniverse)\
**Post date:** [January 6, 2018, 5:21pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/4 "2018-01-06T17:21:06Z")

</div>

> [@beowulff](#):
>
> OS X 10.13.2 has a mitigation patch.

Eeech. As usual, Apple demands that I upgrade to their new software in order to get the patch. They refuse to make the patch insertable into 10.12.6 What a shocker. :dubious::dubious::dubious:

That said, I have to assume it’s better to upgrade and deal with the failed software packages, slower operation due to greater RAM hunger from 10.13, etc - than it is to have everything I’ve ever done on my Mac available.

Of course, it already is, but still.

Thank you for the detailed information. Much appreciated.

---

<div class="post-metadata">

**Author:** ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)\
**Post date:** [January 6, 2018, 5:32pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/5 "2018-01-06T17:32:41Z")

</div>

Here’s a security page that has links to all major vendors and their statements:

> **[Meltdown and Spectre CPU Vulnerabilities: What You Need to Know | WeLiveSecurity](https://www.welivesecurity.com/2018/01/05/meltdown-spectre-cpu-vulnerabilities/)**
>
> Critical flaws in the CPU that affects almost every device has been exploited by Meltdown and Spectre exposing nearly any data the computer processes.

---

<div class="post-metadata">

**Author:** ![scr4](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@scr4](https://boards.straightdope.com/u/scr4)\
**Post date:** [January 6, 2018, 6:14pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/6 "2018-01-06T18:14:20Z")

</div>

Ongoing discussion in [this MPSIMS thread](http://boards.straightdope.com/sdmb/showthread.php?t=846124).

---

<div class="post-metadata">

**Author:** ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)\
**Post date:** [January 6, 2018, 6:48pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/7 "2018-01-06T18:48:45Z")

</div>

> [@beowulff](#):
>
> OS X 10.13.2 has a mitigation patch.

Sorry to be the dull crayon in this box, but, how do I get a mitigation patch? I’m running 10.13.2 (and IOS 11.2.1) and the only thing I know how to do is use Settings or the App Store to check for updates – both systems report they are up to date, no updates available.

A patch isn’t an update, I guess, but where do patches live?

---

<div class="post-metadata">

**Author:** ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)\
**Post date:** [January 6, 2018, 6:59pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/8 "2018-01-06T18:59:05Z")

</div>

> [@Cartooniverse](#):
>
> Eeech. As usual, Apple demands that I upgrade to their new software in order to get the patch. They refuse to make the patch insertable into 10.12.6 What a shocker. :dubious::dubious::dubious:
> 
> That said, I have to assume it’s better to upgrade and deal with the failed software packages, slower operation due to greater RAM hunger from 10.13, etc - than it is to have everything I’ve ever done on my Mac available.
> 
> Of course, it already is, but still.
> 
> Thank you for the detailed information. Much appreciated.

The way I explain it to people, and this isn’t friendly, or satisfying, is that by agreeing to use a Mac and MacOS, you’ve also agreed to be at the mercy of Apple, and what version of the operating system they are willing to support. This unfortunately includes being forced to accept updates you don’t want in order to continue to use a safe and secure system.

I know “agree” might not be what is actually happening, in that you may be forced to run MacOS (or Windows, or whatever) because that is what you need, but the bargain doesn’t change.

Anyway, 10.12 might still be patched. [The security notes](https://support.apple.com/en-us/HT208331) for the latest patch aren’t entirely clear if 10.12 is as protected as 10.13. I brief web search suggests that Apple supports each OS version for 3 years from release date, but I didn’t see that directly from Apple. Considering how new 10.13 is, I’m sure 10.12 is still receiving updates.

As for Android, well, sorry. Security updates on Android are generally a disaster, because phone manufacturers and carriers don’t take it seriously, and some manufacturers stop updating phones shortly after they’re released. Fortunately, unless you’re using one of the very few phones with an Intel processor (some Asus Zenfone 2 models, any others?) then you are probably not subject to the more serious meltdown vulnerability. Some ARM based processors are vulnerable, so it isn’t a sure thing.

---

<div class="post-metadata">

**Author:** ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)\
**Post date:** [January 6, 2018, 7:03pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/9 "2018-01-06T19:03:11Z")

</div>

> [@Napier](#):
>
> Sorry to be the dull crayon in this box, but, how do I get a mitigation patch? I’m running 10.13.2 (and IOS 11.2.1) and the only thing I know how to do is use Settings or the App Store to check for updates – both systems report they are up to date, no updates available.
> 
> A patch isn’t an update, I guess, but where do patches live?

In this case people are using patch and update interchangeably. Continue to get updates in whatever is the standard method on your system. Apply them when convenient, but don’t put it off too long. Updates are important to apply because they usually fix known problems. Sometimes they introduce new problems, too. Life’s not fair.

---

<div class="post-metadata">

**Author:** ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)\
**Post date:** [January 7, 2018, 4:12am UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/10 "2018-01-07T04:12:13Z")

</div>

> [@echoreply](#):
>
> In this case people are using patch and update interchangeably. Continue to get updates in whatever is the standard method on your system. Apply them when convenient, but don’t put it off too long. Updates are important to apply because they usually fix known problems. Sometimes they introduce new problems, too. Life’s not fair.

But I hear above Apple has a mitigation patch, and the App Store tells me there are no updates available.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [January 7, 2018, 5:10am UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/11 "2018-01-07T05:10:25Z")

</div>

> [@Napier](#):
>
> But I hear above Apple has a mitigation patch, and the App Store tells me there are no updates available.

If you have updated to 10.13.2, you have the patch.

---

<div class="post-metadata">

**Author:** ![Cartooniverse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cartooniverse/32/3084_2.png) [@Cartooniverse](https://boards.straightdope.com/u/Cartooniverse)\
**Post date:** [January 7, 2018, 7:18pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/12 "2018-01-07T19:18:06Z")

</div>

I have 10.12.6 and I detest the idea that I have to upgrade to High Sierra - which is as blatant a nod to Northern California pot culture if ever there was one.

But, I also want that patch.

Damn.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [January 7, 2018, 8:02pm UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/13 "2018-01-07T20:02:52Z")

</div>

> [@Cartooniverse](#):
>
> I have 10.12.6 and I detest the idea that I have to upgrade to High Sierra - which is as blatant a nod to Northern California pot culture if ever there was one.
> 
> But, I also want that patch.
> 
> Damn.

I’d just wait and see if Apple rolls out a patch for earlier OSes.

---

<div class="post-metadata">

**Author:** ![zbuzz](https://avatars.discourse-cdn.com/v4/letter/z/e19b73/32.png) [@zbuzz](https://boards.straightdope.com/u/zbuzz)\
**Post date:** [January 8, 2018, 12:32am UTC](https://boards.straightdope.com/t/security-threats-to-computer-chips-how-to-proceed/805981/14 "2018-01-08T00:32:58Z")

</div>

> [@Cartooniverse](#):
>
> I have 10.12.6 and I detest the idea that I have to upgrade to High Sierra - which is as blatant a nod to Northern California pot culture if ever there was one.

The name is not intended as a nod to pot culture. It’s generally accepted that when Apple releases a yearly update that doesn’t have too many user-facing features or most of the changes are under-the-hood refinements, they use a variation of the name from the previous update instead of giving it a brand new name. So from Leopard, we got Snow Leopard. From Lion, we got Mountain Lion. And now from Sierra, we get High Sierra. Craig Federighi made a joke about the name being “fully baked” at WWDC but that was clearly just keynote patter to acknowledge that some people could misconstrue the name.
