Windows Client Guidance against speculative execution vulnerabilities

Page 33 of 75 FirstFirst ... 23313233343543 ... LastLast
  1.    24 Jan 2018 #320

    fdegrove said: View Post
    Hi,



    Disabling it and then re-enabling it is pretty easy to do actually.



    The Spectre patch is at hardware level so I doubt that that can be toggled. It's a bit like if you could toggle between BIOS\UEFI versions which you can't.


    Cheers,
    Yes, that does seem odd. However, if you run it, and scroll down you find it says:

    The system's registry is configured to enable both of the Spectre and Meltdown protections. Within the bounds of any limitations described above, Windows will work with the system's processor to prevent the exploitation of these vulnerabilities.

    So I suppose all it will do in either case is edit the Registry to either allow or disallow the protection, PROVIDED that either the MS updates OR the BIOS update is installed as appropriate.

    UPDATE: @johngalt was the first to post about this utility and I just re-read his posts (#307, 308) in which he has copied from the GRC website and that is pretty much what he said in the first place!
      My ComputerSystem Spec

  2. johngalt's Avatar
    Posts : 1,534
    WinX Pro x64 IP current
       25 Jan 2018 #321

    VBF said: View Post
    Yes, that does seem odd. However, if you run it, and scroll down you find it says:

    The system's registry is configured to enable both of the Spectre and Meltdown protections. Within the bounds of any limitations described above, Windows will work with the system's processor to prevent the exploitation of these vulnerabilities.

    So I suppose all it will do in either case is edit the Registry to either allow or disallow the protection, PROVIDED that either the MS updates OR the BIOS update is installed as appropriate.

    UPDATE: @johngalt was the first to post about this utility and I just re-read his posts (#307, 308) in which he has copied from the GRC website and that is pretty much what he said in the first place!
    Thanks - yeah, it is a lot of reading at his site, but here is the gist:

    If the buttons are disabled - nothing you can do until your OEM either provides you with the necessary files (usually the BIOS), or else your OS provides you with the necessary files (kernel, etc), *OR* (in the case of Meltdown) you're on an AMD processor-based machine.

    If the buttons are enabled then that means you have the files / firmware necessary to implement protection. That leads to 2 cases:

    • The buttons show Enable, which means the protection is available but not actually enabled - so click it!
    • The button shows Disable, which means the protection is available and enabled, which means you don't need to do anything.


    The reason for having this is an easy way for folks with the fixes in place to easily enable and disable the protection - for example, a gamer notices that his FPS has dropped 15%, may then choose to disable protection while in game, and then re-enable it after his gaming session is done. Or, a videographer haws noticed a 10% increase in time it takes to encode his videos for publishing to his stream, so he temporarily disables the protection while encoding.

    The site has more info, and a lot of what is at the site is in the app itself as well.

    Also, be aware that he has revised the app a few times already since the initial release, so it is a good idea to keep checking his site to see if a newer version is available that may have more enhancements.

    (Also, Post#308 was actually all directly from the app itself.)
      My ComputersSystem Spec

  3. storageman's Avatar
    Posts : 458
    Windows 10 Pro 1803 17134.345
       25 Jan 2018 #322

    johngalt said: View Post
    But your buttons are not disabled....

    Meaning you CAN click them. So... Click!
    Well we did that and guess what it works. Interesting - my system now also passes all of the other Meltdown/Spectre test.
    Attached Thumbnails Attached Thumbnails Inspectrre.jpg  
      My ComputersSystem Spec

  4. johngalt's Avatar
    Posts : 1,534
    WinX Pro x64 IP current
       25 Jan 2018 #323

    Bravo!

    SO, you can rest assured, now that these things are not able to affect you anymore.

    Also, with this utility, you can benchmark your system to see how badly it affects your performance, if you so choose.
      My ComputersSystem Spec

  5.    25 Jan 2018 #324

    I think that tool is a bit misleading. Even with a microcode update, I'm pretty sure that any processor that does speculative execution is still vulnerable to Spectre to some degree.

    And what exactly happens when you click on "Disable Meltdown Protection" or "Disable Spectre Protection"? Do you get a UAC prompt?
      My ComputerSystem Spec

  6. Neil Macready's Avatar
    Posts : 340
    Microsoft Windows 10 Home x64
       25 Jan 2018 #325
      My ComputerSystem Spec

  7. johngalt's Avatar
    Posts : 1,534
    WinX Pro x64 IP current
       25 Jan 2018 #326

    Ground Sloth said: View Post
    I think that tool is a bit misleading. Even with a microcode update, I'm pretty sure that any processor that does speculative execution is still vulnerable to Spectre to some degree.

    And what exactly happens when you click on "Disable Meltdown Protection" or "Disable Spectre Protection"? Do you get a UAC prompt?
    Your opinion. I'd trust Gibson over any of the hoopla being spouted by the Media - he didn't start doing this yesterday.

    As for what happens when you press the button - well, considering the buttons are disabled on my machine considering that I'm most likely not receiving a BIOS update and am currently running FCU, well, I can't exactly press the buttons and find out, can I?

    If you read what Gibson wrote at his site and in the software, there is nothing that is misleading. But, at the same time, we're all entitled to our own opinions.
      My ComputersSystem Spec


  8. Posts : 505
    Windows 10 pro 18.03, Ubuntu 18.04, win 8.1 pro
       26 Jan 2018 #327

    What are my options?


    I ran some tests as suggested in this pages and it seems i'n not protected from bugs:

    Suggested actions:

    * Install BIOS/firmware update provided by your device OEM that enables hardware support for the branch target injection mitigation.


    Click image for larger version. 

Name:	spectre.PNG 
Views:	53 
Size:	11.8 KB 
ID:	174256


    my pc is a bit old (i think 2011/2012) and there is no firmware update in asus support, am i out of option? shoud i buy a new one?

    thanks!
      My ComputerSystem Spec

  9.    26 Jan 2018 #328

    Neil Macready said: View Post
    Same here..... my laptop, a Satellite L755-13K Part Number : PSK1WE is amongst the many listed against "TBD"
    Being a 2011 model, somehow I don't think it will get an update...
      My ComputerSystem Spec

  10. dencal's Avatar
    Posts : 2,846
    W10 Pro + W10 Preview
       26 Jan 2018 #329

    Could this all be "False News".....scaremongering in a bid to increase the sale or upgrading of computers???

    Not one recorded infiltration.....it makes you think huh!!!....food for thought.
      My ComputersSystem Spec


 
Page 33 of 75 FirstFirst ... 23313233343543 ... LastLast

Related Threads
The PowerShell script execution policies enables you to determine which Windows PowerShell scripts (if any) will be allowed to run on your computer. Windows PowerShell has four different execution policies: Execution Policy Description ...
Source: Mitigating speculative execution side-channel attacks in Microsoft Edge and Internet Explorer - Microsoft Edge Dev Blog See also update: Cumulative Update KB4056892 Windows 10 v1709 Build 16299.192 - Windows 10 Forums
Source: Google Online Security Blog: Disclosing vulnerabilities to protect users
Windows 10 - Need some guidance on recovery in Installation and Upgrade
One of my spare Windows 10 machines is on life support. I must have clobbered it somehow when I was tweaking the multiple display settings ( to incorporate a HDMI projector). It actually worked fine all week, but today, when I tired to set it...
Read more: http://www.zdnet.com/article/microsoft-offers-it-guidance-to-prepare-for-windows-as-a-service/
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 04:45.
Find Us