Patch Notes #122 — The CPU Was Lying the Whole Time
Year six opens with the most unsettling vulnerability disclosure I’ve ever read: Meltdown and Spectre. Not bugs in software, but bugs in the idea of modern CPUs. Speculative execution, the trick where processors guess ahead to go fast, turns out to leak secrets through timing side channels. Meltdown lets a process read kernel memory; Spectre tricks other processes into leaking their own; between them, essentially every Intel chip since the 90s and most others are affected. The fix costs performance (the cloud providers are rebooting the entire planet’s fleet this week, imagine that change-management ticket), and Spectre-class attacks will haunt chip design for a decade because the flaw is load-bearing: the speed we’ve enjoyed since 1995 was partially borrowed against an invariant nobody wrote down. ...