Woody Leonhard pointed to this blog post which helped me understand these 2 newly discovered threats.
https://danielmiessler.com/blog/simple-explanation-difference-meltdown-spectre/
Thanks for posting that article. I've been reading about this, but wasn't getting a good grasp on what it was all about.
The question I have about all this is that is there any real protection other than buying a new computer?
And if not, when will new computers be containing secure processor/chips?
I have to think also, that this is going to be a big boon for new computer sales. One has to wonder if part of the information release on this is calculated to increase those sales. (Call me suspcicious.)
No, I do not see this a a boon for new computer sales. Software updates are being/have been released by Microsoft, A/V's, browser and Intel.
Since you use Windows Defender and Malwarebytes Pro, if you haven't received the Microsoft update, KB4056891, launch Malwarebytes and set the Malwarebytes action center setting to "Never register Malwarebytes in Windows Action Center" so that the Microsoft update can apply automatically.
Any firmware update by Intel will be tested and released via the OEMs and the report is that Intel will have Meltdown and Spectre patches ready for 90 percent of modern processors next week (https://betanews.com/2018/01/05/intel-patches-meltdown-spectre/). Because Dell is updating their forums and they are read only, you won't be able to check there until the forums are live again.
Quoteif you haven't received the Microsoft update, KB4056891
I received KB4056892 actually. Is that enough?
When I went to MBytes settings, I already have that "never register" option checked, but the whole section is grayed out and I couldn't have changed it anyway.
That section on Malwarebytes should NOT be grayed out.
You updated Firefox to 57.0.4, right? If not, you need that update. Otherwise, there isn't anything else you can do until Dell releases an Intel firmware update, which I believe "should" happen if it is 1995 or newer.
Yes, I've updated to FireFox 57.0.4 as soon as I saw why it popped up.
I just checked MBAM settings again, and I am able to change that setting now. (when I did, Defender immediately turned itself off.) I don't know what happened before. But it was set on the "never register" and is still set on that. I think you told me to do that so that MBAM would function correctly with Windows 10.
I've attached a screen shot. Now it just looks like the buttons are grayed out.
Quote...launch Malwarebytes and set the Malwarebytes action center setting to "Never register Malwarebytes in Windows Action Center" so that the Microsoft update can apply automatically.
Corrine, sorry for getting into this post, but could you please tell me if this option has to be always checked and why? Why MBAM recommends the opposite?
Quoteif you haven't received the Microsoft update, KB4056891
I also received KB405689
2.
No, not grayed out. You can tst it by changing the setting and then changing it back.
As to the setting, Panos, when I had it set to the recommended option, (Let Malwarebytes apply the best Windows Action settings...), Windows Defender saw MBAM as another antivirus installed and deactivated. When the security update was released for Meltdown/Spectre, Malwarebytes had not yet made the registry change so the update would not be applied unless the setting was to not register MBAM in the Windows Action Center.
KB4056891 is the update for Windows 10 Version 1703 (Creators Update), KB4056892 is for Windows 10 Version 1709 (Fall Creators Update). (Version/Build information is in Settings > System > About)
Quote from: Corrine on January 06, 2018, 02:20:11 PM
As to the setting, Panos, when I had it set to the recommended option, (Let Malwarebytes apply the best Windows Action settings...), Windows Defender saw MBAM as another antivirus installed and deactivated. When the security update was released for Meltdown/Spectre, Malwarebytes had not yet made the registry change so the update would not be applied unless the setting was to not register MBAM in the Windows Action Center.
OK, Corrine. Thank you. I suppose that this concerns only Windows Defender, not ESET. Right? Do I also have to change the MBAM option?
Since ESET made the registry key change and you got the Microsoft security update, no need to make the change. As to the update to 1709, hasn't that been offered to you yet?
Quote from: Corrine on January 06, 2018, 03:05:22 PM
Since ESET made the registry key change and you got the Microsoft security update, no need to make the change. As to the update to 1709, hasn't that been offered to you yet?
Yes, I have version 1709, build 16299.192. Although I solved automatic update problems in Sysnative before, I still don't get automatically the updates concerning new versions (e.g. Creators or Fall Creators). Also sometimes I have to check for updates to let them installed. ESET warns me about them, but Windows updates center does not. So I usually wait for a month, and then manually install them (perhaps my computer is old, I don't know). I manually installed the Falls Creators Update, and also manually installed the latest update yesterday.
Please, see attachment.
With 1709, you shouldn't have been offered KB4056891 since that is for 1703, unless you updated to 1709 after getting KB4056892. Is the date 05Jan2018 for the latest KB update or for 1709?
I wonder -- try making the change in Malwarebytes to not register it in the Windows Action Center and see if that makes a difference getting the Microsoft security updates. The test will be on Tuesday, 09Jan2018, when the next Microsoft security updates are due to be released (9PM UTC).
Quote from: Corrine on January 06, 2018, 03:30:44 PM
I wonder -- try making the change in Malwarebytes to not register it in the Windows Action Center and see if that makes a difference getting the Microsoft security updates. The test will be on Tuesday, 09Jan2018, when the next Microsoft security updates are due to be released (9PM UTC).
OK. I will be here. :)
hmmm.. I double checked my update history.
I have
Version 1709 (OS Build 16299.192) So I apparently have the Fall Creators update. I looked through my update history and don't see the the other KB you listed.
And received this update on 1/4.
2018-01 Cumulative Update for Windows 10 Version 1709 for x64 based systems (KB4056892)
Oddly, my update settings had been allowing several days delay, but MS overrode that an forced the update overnight, so I thought it was this critical patch for the processor vulnerability everyone is talking about.
Do I need to manually install the KB4056891 update? (I also had a system reset for Windows Updates via Sysnative)
I forgot to mention, that with the 1/4 update, my delay update installation settings were reset to immediately update. (I've reset that again.) But I thought that was odd.
No, you do not need KB4056891 on 1709. Go to Windows 10 Update History (http://windows.microsoft.com/en-us/windows-10/update-history-windows-10) and click on "Windows 10 Version 1709" and you'll see it lists KB4056892. If you click on "Windows 10 Version 1703" you'll see that it lists KB4056891 for that version. Different build, different update.
Thank you clearing that up for me. I was a bit confused by the discussion. I've updated the specs in my signature now.
This whole Meltdown/Spectre thing is a confusing mess. :)
Steve Gibson released a nice little program called InSpectre (http://"https://www.grc.com/inspectre.htm") to see if your computer is safe from these threats.
Gibson's tool discussed in the Web News topic, starting Major flaw in millions of Intel chips (https://www.landzdown.com/web-news/major-flaw-in-millions-of-intel-chips/msg196929/#msg196929) here.
Rats. I thought I searched for inspectre too. Sorry about that.
You're forgiven. :)