Saturday, 06 January 2018 18:21
Amazon, Apple, Google, and Microsoft are reporting that their computer performance has been largely unaffected by the patches for Meltdown and Spectre. The news of the Meltdown and Spectre security vulnerabilities, which together affect almost all modern CPUs, has been sweeping the web since the start of the year. The fix for Meltdown, an OS-level method of mitigation called kernel page table isolation (KPTI), has now been implemented for major operating systems, including Linux, macOS, iOS, Android, and Windows. Mitigations for Spectre, which is actually two different vulnerabilities, are currently less understood, however. Fixes, so far, have involved program-level, OS-level, and hardware-level patching, but it seems there isn't a single solution to both of the Spectre vulnerabilities. Meltdown has a singular fix across all operating systems because the vulnerability results from an optimization present in specific CPUs, namely Intel's and some of ARM's. With no way to fix the CPUs, the only way is to apply a heavy-handed approach that nullifies the optimization within the OS--KPTI. It was known that KPTI would, in theory, have a real performance cost. The earliest tests on Linux with worst case scenarios showed performance drops of up to 30%.