Over the past two days the Internet has been full of news stories about Meltdown and Spectre and how horribly and devastating these issues are. Chipset vendors scramble to update their microcode, operating systems get patched and even web browsers get an update. What I found missing in pretty much all articles, however, was how these attacks that can extract data from the kernel and other threads, actually work. So I resorted to reading the lengthy but very informative whitepapers on Meltdown and Spectre and since I haven’t found a good source that gives an abbreviated and easier to understand version I will attempt to do so myself. I was tempted to call this post the ‘Technical Elevator Pitch’ but quite frankly the elevator would have to stop for a little while to be able to finish the story. But I think it can be told over lunchtime…
Continue reading Meltdown – The Technical Lunchtime Pitch