Skip to content

Meltdown & Spectre – Part 2: The Internet of Security Risk

Share:

Meltdown and Spectre represent a new class of security threat that endangers our digital world at its core – the processor. What aspects of our digital lives, work, society and economy will be impacted by Meltdown and Spectre?

When the news first broke on Meltdown and Spectre on January 3rd of 2018, the predominant headline was that Apple’s product were vulnerable to Spectre and Meltdown, yet, they had distributed a patch back in November of 2017 for Meltdown ahead of other vendors to their installed base of over 1.5 billion plus Apple devices, with over 80% running the latest version of iOS or MacOS.  With Apple apparently well ahead of the curve in terms of addressing the security risks associated with this new processor-level threat, are there bigger thing to be concerned about?

The answer is yes.  That bigger thing is the Internet of Things, which is notorious for its current lack of security mostly due to a fragmented, multi-tier landscape of vendors and technologies, and general lack of device, software and network security standards.  Dean Freeman, neXCurve principal analyst, expressed particular concern for older IoT implementations that likely implemented a variety of endpoint device, network and datacenter compute equipment that utilized x86 chipsets that are very likely vulnerable to the Meltdown and Spectre bugs and may not run OS versions that can be easily patched.

IoT applications that can succumb to Meltdown and Spectre could be mission critical such as utilities, refineries, bank ATMs among many others.  Though older generation IoT endpoint devices apply simple intelligence and are largely limited to using microcontrollers that are generally immune to Meltdown and Spectre, IoT endpoint devices are becoming increasingly smarter and using more robust and advanced chipsets to process data for analytics at the edge.  As more of these advanced, multi-core chips that utilize speculative execution make their way into IoT endpoint devices, the Meltdown and Spectre threats will increase as will the challenge of remediating these devices as malware and derivatives of these bugs inevitably emerge.

The Meltdown and Spectre threat goes beyond your iPhone.  Businesses and consumers need to be conscious of their legacy tech, their current tech and their future tech and ensure that vendor and service providers are hardening their hardware with firmware and OS patches to minimize the risk of a new and potentially expanding category of security threat that can jeopardize the foundation of everything digital.

For more information, listen to the audio replay of part 2 of our webcast discussion on the topic of Meltdown & Spectre.


neXCurve can help you and your team develop a strategy for dealing with the new breed of processor-level vulnerabilities and the threats they pose to your organization and your businesses.  Contact us for a complimentary consultation and an overview of our advisory and coaching services.

You can listen to the audio replay of our Meltdown & Spectre webcast by playing the media below or downloading the Podcast available on iTunes.  Subscribe to our Podcast channel and keep up to date on the latest insights from neXt Curve.

Presentation Materials

neXt Curve Meltdown & Spectre Presentation (PDF)

Audio replay of the Meltdown & Spectre webcast

 

This material may not be copied, reproduced, or modified in whole or in part for any purpose except with express written permission or license from an authorized representative of neXt Curve. In addition to such written permission or license to copy, reproduce, or modify this document in whole or part, an acknowledgement of the authors of the document and all applicable portions of the copyright notice must be clearly referenced.

If you would like to engage with a neXt Curve analyst on this topic, please:

If you would like to be notified of our latest research by email, please:

Related Content

Discover more from neXt Curve

Subscribe now to keep reading and get access to the full archive.

Continue reading

Subscribe to neXt Curve!

By subscribing to the neXt Curve site you will registered with our reThink research blog and have an opportunity to engage with one of the most vibrant and independent discussions on our digital future. As a subscriber, you will receive newly published research articles and content as well as invitations to exclusive events by mail.

By subscribing you acknowledge and accept the terms of neXt Curves privacy policy.

Request an Inquiry

Send us an email

Request a Briefing