Friday, January 19th 2018
Skyfall and Solace Could be the First Attacks Based on Meltdown and Spectre?
Out of the blue, a website popped up titled "Skyfall and Solace," which describes itself as two of the first attacks that exploit the Spectre and Meltdown vulnerabilities (it doesn't detail which attack exploits what vulnerability). A whois lookup reveals that the person(s) behind this website may not be the same one(s) behind the Spectre and Meltdown website. The elephant in the room, of course, is that the two attacks are named after "James Bond" films "Skyfall" and "Quantum of Solace." The website's only piece of text ends with "Full details are still under embargo and will be published soon when chip manufacturers and Operating System vendors have prepared patches," and that one should "watch this space for more." We doubt the credibility of this threat. Anyone who has designed attacks that exploit known vulnerabilities won't enter embargoes with "chip manufacturers and operating system vendors" who have already developed mitigation to the vulnerabilities.
7 Comments on Skyfall and Solace Could be the First Attacks Based on Meltdown and Spectre?
With the problem being in hardware and hardware design rather than specific bugs, software patches are mitigation measures not a complete fix. Even with current (rushed and incomplete) patches, both chip and operating system vendors may want to take additional measures when new ways to attack are found. Embargoes are also pretty standard operating procedure in these situations.