Why are Spectre and Meltdown So Dangerous?

Поділитися
Вставка
  • Опубліковано 27 вер 2024
  • Squarespace link: Visit squarespace.com... and use offer code TECHQUICKIE to save 10% off your first order.
    Spectre and Meltdown are security flaws that, between them, affect nearly all of the world's PCs and smartphones! How did this happen, and what makes these bugs so sinister?
    Techquickie Merch Store: www.designbyhu...
    Techquickie Movie Poster: shop.crowdmade...
    Follow: / linustech
    Leave a reply with your requests for future episodes, or tweet them here: / jmart604
    Join the community: linustechtips.com
    Intro Theme: Showdown by F.O.O.L from Monstercat - Best of 2016
    Video Link: • Monstercat - Best of 2...
    iTunes Download Link: itunes.apple.c...
    Listen on Spotify: open.spotify.c...

КОМЕНТАРІ • 1,6 тис.

  • @tonydas999
    @tonydas999 6 років тому +2745

    Why do vulnerabilities always get such cool names?

    • @DerEwigeWanderer
      @DerEwigeWanderer 6 років тому +261

      there was once a worm called "conficker". in german, "ficker" means "fucker" :)

    • @potatopobobot4231
      @potatopobobot4231 6 років тому +78

      Like aids?

    • @Wonky2
      @Wonky2 6 років тому +225

      And why did they get such pretty logos?

    • @TestiEsti123
      @TestiEsti123 6 років тому +84

      Probably the same reason as why storms get Human names. Easy to remember

    • @ref3665
      @ref3665 6 років тому +165

      Yeah, CVE-2018-7600 is a really cool name.

  • @moth.monster
    @moth.monster 6 років тому +191

    Wow, someone finally actually explained what the fucking bugs do. Thank you. I was getting tired of people just saying "Oh it's bad" and not actually caring about what it really does

    • @m3talgame20
      @m3talgame20 6 років тому +13

      you are more likely to encounter a dinosaur than a meltdown or spectre exploit

    • @Mik-kv8xx
      @Mik-kv8xx 3 роки тому +3

      @@m3talgame20 how do you know?

    • @justacasualgamer1957
      @justacasualgamer1957 3 роки тому +1

      @@m3talgame20 can you explain how

    • @VeryBigExplosion
      @VeryBigExplosion 3 роки тому +5

      @@m3talgame20 *Last Online 3 years ago*

    • @m3talgame20
      @m3talgame20 3 роки тому +1

      @@VeryBigExplosion hmm old video it seems. I'd be more worried about china

  • @1stfloorguy59
    @1stfloorguy59 6 років тому +5079

    It's a good thing my bank account is always empty

    • @IV_Cornec
      @IV_Cornec 6 років тому +61

      1stfloorguy I feel ya

    • @drmegaman
      @drmegaman 6 років тому +176

      fucking steam

    • @rdln4313
      @rdln4313 6 років тому +48

      Dr Megaman more like fucking mundaine life shit to buy

    • @drmegaman
      @drmegaman 6 років тому +45

      Lou D yeah, I said Steam because I thought that'd be funnier but it really is amazing how much little random stuff adds up

    • @RettigJ
      @RettigJ 6 років тому +12

      That is normal. (For ~8/10 Americans -Dave Ramsey)

  • @PedroOjeda
    @PedroOjeda 6 років тому +474

    This was probably the best Techquickie video. I actually learned something instead of just getting a lot superficial knowledge

    • @masoluboxD
      @masoluboxD 6 років тому +31

      I think this is still superficial knowledge

    • @joesterling4299
      @joesterling4299 6 років тому +20

      I learned more about how the exploits work, but nothing to change my mind about how useless it is to obsess about them. Fact is we're screwed if anyone truly talented decides to come after our info. Vulnerabilities >>> Fixes for them

    • @jeffbrownstain
      @jeffbrownstain 6 років тому

      Really, because this was the most useless video I've watched yet.
      What does knowing how these work do for anyone that isn't working to fix them?
      I'd much rather learn all the discrepancies between file types than how a bug that will never effect 99% of people works.

    • @mcrsit
      @mcrsit 5 років тому +16

      ​@@jeffbrownstain You obviously didn't understand the video then.

    • @jeffbrownstain
      @jeffbrownstain 5 років тому

      mcrsit Year old video dude gtfo

  • @Matthigast
    @Matthigast 6 років тому +1689

    You didn't give enough ram to chrome, ffs Linus!

    • @JonatasAdoM
      @JonatasAdoM 6 років тому +36

      He closed the tabs in chrome's task manager

    • @dagg497
      @dagg497 6 років тому +33

      Chrome 💕 RAM
      And the internet Tabs get super tiny with no text, so I'll never leave Firefox.

    • @Hydr8Man
      @Hydr8Man 6 років тому +15

      Good thing my school uses MacBooks *AND CHROME* and the teachers are always wondering why the laptops are so slow

    • @Ferotiq
      @Ferotiq 6 років тому

      matthigast that’s every teacher but they only have 2gigs of ram XD

    • @itsmetheherpes1750
      @itsmetheherpes1750 6 років тому

      what the heck is specter and meltdown ?

  • @AlexanderPavel
    @AlexanderPavel 6 років тому +44

    One important thing that was not mentioned: Meltdown (Intel specific) allows a program to read memory from anywhere on the CPU, included protected system memory. The 2 main spectre vulnerabilities can only read from the currently executing program or another program running in userspace (not system).

  • @sidewinder3422
    @sidewinder3422 6 років тому +475

    As I expected Modern Technology is dangerous, nothing beats my old but realiable Abacus

    • @Dragon22999
      @Dragon22999 6 років тому +6

      Franz Tinuviel how bout them space probes orbiting jupiter?

    • @estoor4258
      @estoor4258 6 років тому +4

      Comet Streak
      Probably just trash we found in space

    • @taustyz5875
      @taustyz5875 5 років тому +26

      Yeah but can it run Crysis

    • @parasztj
      @parasztj 5 років тому

      It is dangerous. Depends on acceleration.

    • @lennon8435
      @lennon8435 4 роки тому +2

      Abacus is a bit advanced for me

  • @herrreinsch
    @herrreinsch 6 років тому +1010

    *4:26** the barking cpu, I'm dead.* 😂

    • @blackhatvisions
      @blackhatvisions 6 років тому +14

      normie

    • @ZargAtHome
      @ZargAtHome 6 років тому +10

      BlackHat Visions REEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE

    • @seppmartti
      @seppmartti 6 років тому +4

      I'm not sure what's going on, but: REEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEST IN PEACE.

    • @hypermangi8265
      @hypermangi8265 6 років тому +1

      BlackHat Visions REEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEST IN PEACE.

    • @kmical1564
      @kmical1564 6 років тому +2

      BlackHat Visions
      REEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE

  • @aR0ttenBANANA
    @aR0ttenBANANA 6 років тому +945

    i aint afraid of no ghost

    • @uhoy1488
      @uhoy1488 6 років тому +25

      aR0ttenBANANA96 GHOSTBUSTERS

    • @SimGunther
      @SimGunther 6 років тому +30

      aR0ttenBANANA96 I ain't afraid of no sleep
      I ain't afraid of no bed

    • @MC2738
      @MC2738 6 років тому +8

      My server doesn't have this vulnerability, but my Gaming PC does :(

    • @samwansitdabet6630
      @samwansitdabet6630 6 років тому +10

      Banking on server
      Fapping on battlestation
      Not that hard

    • @simontay4851
      @simontay4851 6 років тому +1

      Who you gonna call...

  • @JorgetePanete
    @JorgetePanete 4 роки тому +25

    So, the CPUs are like:
    "Your next line will be..."

    • @deki9827
      @deki9827 3 роки тому +2

      Oh ho

    • @ashii_ii
      @ashii_ii 3 роки тому

      @@deki9827 josef joster

  • @Robo4720011
    @Robo4720011 6 років тому +5

    This is one of the best readers digest explanations of the Spectre and Meltdown exploits I've seen so far. Bravo, Linus and the Techquickie team!

  • @petarpartaloski8889
    @petarpartaloski8889 4 роки тому +2

    As a guy who just had a subject dedicated to building processors from scratch, all of these terms seem very familiar to me, and I loved how well described the problems are in this video, just as always, Techquickie delivers!

  • @nicolasmunoz1847
    @nicolasmunoz1847 6 років тому +3

    The whole schematic to explain the vulnerabilities is very well put together. Nice work!

  • @Twatical
    @Twatical 6 років тому +42

    Checked my steam like 10 times whilst watching this video

    • @EREMIT-DE
      @EREMIT-DE 4 роки тому

      Could you enlighten me? Also have Steam, just be online there once a month for new games.
      And then just single player rpg, as I am married 😂
      Have no clue why someone even would go online on steam once a day...

    • @NobbsAndVagene
      @NobbsAndVagene 4 роки тому +1

      ​@@EREMIT-DE Because they play a lot of games?

    • @EREMIT-DE
      @EREMIT-DE 4 роки тому

      @@NobbsAndVagene
      Cool answer, so they play a lot of games
      and that is why they checking steam 10 times a day instead of playing a lot of games...
      so... if someone has a real answer... still no clue ^^ are you watching comments on games or have some forums I still not know about...?

    • @Mugetsu_Gaming
      @Mugetsu_Gaming 4 роки тому +7

      @@EREMIT-DE because the video had a lot of sound effects similar to that of which steam uses.

    • @missingno2401
      @missingno2401 4 роки тому

      bro i have no steam friends i dont have such weaknesses

  • @Jan-vv1zk
    @Jan-vv1zk 6 років тому +42

    Hands down, this was pretty amazing. Great job, Linus.

    • @kenstoudamire7366
      @kenstoudamire7366 5 років тому +1

      Cant expect an assembly spectre exploit in a 10 min vid

  • @Kneedragon1962
    @Kneedragon1962 6 років тому +6

    One consolation about Spectre & Meltdown. We've been hearing (a lot) about these vulns that will end life as we know it, but so far, (as far as I know), there has not been a single malicious example used in the wild, anywhere, any time, by anyone against anyone. The Y2K bug was lot more real and present and easy to demonstrate...
    I'm not saying they can't be used in the wild, but we've heard a hell of a lot about them, but after 4 or 5 months, there's still not been a single case of anyone catching gonorrhoea off a toilet seat.

  • @remirms2239
    @remirms2239 6 років тому +205

    Lol, my name really is Jeff and I live in N.Y. I own an i7 4770k though, not an i5 4670k.😋

    • @haas170
      @haas170 6 років тому +31

      Sure it’s not Rémi?

    • @remirms2239
      @remirms2239 6 років тому +5

      Qyndryx
      Yeah because my Surname would be *Rooms* ...

    • @Minecrafted907
      @Minecrafted907 6 років тому

      My name jeff

  • @bas7545
    @bas7545 6 років тому +329

    Could you talk about the Cambridge analytica scandal?

    • @zyyyper2459
      @zyyyper2459 6 років тому +35

      Bas 7 its more a political topic than anything else

    • @TROONTRON
      @TROONTRON 6 років тому +27

      We have all known about facebook selling our personal info for years, yet only now do people seem to care...

    • @Shuvojit69
      @Shuvojit69 6 років тому +1

      It's just Facebook, Twitter selling data to a company that then does shit.. Thats what I understood 🙂

    • @bas7545
      @bas7545 6 років тому

      nigga what yeah that's true

    • @SpartanDusk
      @SpartanDusk 6 років тому +2

      T.S that’s not the issue, it’s the fact that Cambridge will also take your friends info and sell it. It’s like your friend had sex with a skank and you got their aids as well. It’s probably worth for them but not for you

  • @hobomisanthropus2414
    @hobomisanthropus2414 6 років тому +1

    Spectre is incredibly impractical to exploit. It can really only be used effectively against task-specific machines since the standard home user machine has so much junk data. This supposedly makes it a very useful exploit to steal hashing addresses and wipe out crypto wallets though. Enterprise servers that process payments are ripe targets as well.

  • @rustyshackleford5166
    @rustyshackleford5166 6 років тому +191

    6:01 Speaking of plugging holes.....buttplu.....ahem....tunnel bear!! Wanna plug the holes where your ISP can peek at your data? Use a vpn to plug your data holes.
    LMAO!

    • @burner887
      @burner887 6 років тому +7

      Russ Orler tunnelbear was bought by mcafee so no more tunnelbear ads lol

    • @rustyshackleford5166
      @rustyshackleford5166 6 років тому +6

      Dadda Purple speaking of no more ads..... ADVERTISEMENT HERE!

    • @thischannelwillselfdestruc4977
      @thischannelwillselfdestruc4977 6 років тому +1

      its all pia ads now.
      Although I've started using IPVanish and am comfy.

  • @MWLLxUnderTaker
    @MWLLxUnderTaker 6 років тому +2

    My comp is protected by Drax! His reflexes are so fast nothing would go over his head!

  • @sroku7673
    @sroku7673 4 роки тому +5

    "Why are Spectre and Meltdown so dangerous?"
    Mindustry players: indeed they are

  • @user-ok4pk2mp3e
    @user-ok4pk2mp3e 6 років тому +7

    I was watching this on my newly bought Sceptre monitor and freaking out until I realized it's just an anagram.

  • @gamboodle
    @gamboodle 6 років тому +3

    "Knock knock!"
    *Branch prediction*
    "Who's there?"

  • @handymani4502
    @handymani4502 6 років тому +14

    The power of christ compels you - spectre the ghost flys out of pc -

  • @matthewday7565
    @matthewday7565 6 років тому

    Wasn't quite sure of the scope, whether it meant fishing with half a chance, or if it could target particular data.
    One thing that seems clear, the two vulnerabilities will not help to gain access initially, but could be used by malware that has already entered, or by a malicious user on a shared system

  • @Elijah2
    @Elijah2 5 років тому +2

    At 4:22, “This guy really likes x+y” LOL! And the barking CPU

  • @brentsnocomgaming7813
    @brentsnocomgaming7813 6 років тому +6

    Thank you for developing meltdown and spectre, NSA

  • @shudidesai
    @shudidesai 6 років тому +1

    Good job, can't imagine how hard this was to make, simplifying and compressing technical information like this is truly impressive. Give my regards to the script writer.

  • @larrylentini5688
    @larrylentini5688 6 років тому +3

    You say I'll notice when my bank account is empty, but that's my secret. My bank account is *always* empty.

  • @MycoolGaming
    @MycoolGaming 5 років тому +1

    Those noises from the viruses are enough to give me nightmares and make me not download anything off the web again...

  • @prowhiskey2678
    @prowhiskey2678 6 років тому +4

    Great explanation!

  • @xGatoDelFuegox
    @xGatoDelFuegox 6 років тому +1

    Watching this after taran said he gave the malwares their own "personalities"...great touch :)

  • @romulino
    @romulino 6 років тому +21

    photoshop using less ram than chrome? 🤣

  • @Dakktyrel
    @Dakktyrel 6 років тому

    Both of these require a persistent threat that has already defeated any security features (AV, IDS, IPS) installed. So the threat is there...but if an attacker has already compromised your device or network....Spectre and Meltdown will be the hard way to get what they already have access to.

  • @V0TION
    @V0TION 6 років тому +50

    4:21 Who else checked Steam??

    • @xXConsmariosXx
      @xXConsmariosXx 5 років тому

      2:10 i checked steam xD

    • @danielediedrichs8478
      @danielediedrichs8478 5 років тому

      It's not really the same Sound

    • @DacLMK
      @DacLMK 4 роки тому

      Change your name asshole

    • @V0TION
      @V0TION 4 роки тому +1

      @@DacLMK no I don't think I will

    • @DacLMK
      @DacLMK 4 роки тому +1

      @@V0TION Change it, it disrupts scrolling on the page

  • @Right-Is-Right
    @Right-Is-Right 6 років тому

    A smartphone trick is to close down all your programes already assigned ram by hitting the square on the left bottom of most devices and hitting the x on the right top of the pages that come up looking like open apps. It is often called closing your recnt apps but I wanted to wxplain it in a way a newbie should be able to understand.

  • @nocturnalnights27
    @nocturnalnights27 6 років тому +4

    Welp, time to bust out the old 486!

    • @sulphurous2656
      @sulphurous2656 5 років тому +1

      "Here's what you won't get on your 486!"

  • @danielblack4190
    @danielblack4190 4 роки тому +1

    Actual question here: how do specter and meltdown know how fast certain data from certain memory addresses get loaded in if they don't have access to the data in the first place, and so, don't know when they would otherwise get it?

  • @doncosner2611
    @doncosner2611 3 роки тому +1

    This is the best explanation of these vulnerabilities I have heard! Nice job!

  • @lordmarshmal_0643
    @lordmarshmal_0643 3 роки тому

    Being a guy that plays Mindustry, a Factorio-like game, I got confused like "Wait are we really analyzing these 2 end-game turrets" and I got dragged into just as informative a rabbit hole
    Mindustry V1 wasn't even a thing at the time this was uploaded, haha

  • @PeteSinHouston
    @PeteSinHouston 5 років тому +4

    Brought to you by the good folks at the NSA (and the University of Wisconsin). A feature, not a bug.

  • @gregbenwell6173
    @gregbenwell6173 6 років тому

    About 12 years ago the company I worked at my former boss, had his credit account hacked, from a website he bought parts for a shop off of!!! Since then I ONLY USE prepaid credit cards online and NEVER use my own personal bank card or credit cards for transactions on the internet!!! For an extra layer of security I buy two or three prepaid cards and switch up which one I use every couple of months, and then when they are about to expire, I buy new prepaid credit cards!!! And when I DO use them I put just the money on them I need to make a purchase!! Call me paranoid, but it hasn't been an issue for me for almost 16 years now!!! In the end if you are buying $200 worth of stuff on eBay, then you keep $220 on the card (to cover any shipping and the cost of the items). Then in a lot of cases just before they expire you yank out your old cards use up the $5 balances before you use your next card!! It confuses the snot out of the hackers, because they see you are using 3 different cards for one purchase and not any of the numbers match!!! And ALSO use different four digit password numbers on each card as long as you can remember what the password is for each card it shouldn't be a problem and I write my last four card numbers down in a small note book, with the four digit pass code next to it, on my desk!!!! If you pick it up YOU CAN NEVER figure out what the 8 digit strings of numbers mean and without the security code number off the back of the prepaid credit card in most cases they are completely worthless as well too!!! Even if somebody steals the notebook!!! Like I say I might be a little paranoid, but this system has worked for me over the course of 16 years and NOBODY has ever hacked my bank account or run up my credit cards without my knowledge!!! So it DOES work!! And even if the hackers get your prepaid credit card number there is never a balance on them either until you are ready to actually use them, so they can't get anything either!!! And it only costs $5 to put money on the cards which is what I consider as money well spent for the "insurance value" of being secure!! And still in a pinch you can use the cards at ANY ATM without fear as well in case you need the money back off of them as well!!! So in most cases it is far more secure then ANY bank will offer you too!!! Lastly in a given month I use between 3 to 5 different prepaid cards, constantly switching between them randomly.....so this week I might use card number 1234 and card 4321, and card 2134 even on the same website!!! All are called out to my name......but my personal information on the prepaid cards are almost totally limited to just my name and address and not much more!!

  • @kayleighmoore6951
    @kayleighmoore6951 4 роки тому +2

    1:19 But what about consoles and refrigerators?

  • @ShiroKage009
    @ShiroKage009 6 років тому

    There have been windows patches pushed it to essentially disable the gesture that enables the hole. It had a performance penalty in some applications, but it's not horrible.

  • @antiseth3964
    @antiseth3964 6 років тому +1

    Wrote a paper on this, so it's interesting to understand what he's talking about in this case. These flaws are game-changing for microarchitecture design.

  • @monkeywithocd
    @monkeywithocd 6 років тому

    6:25 - That really needs more explanation. Are you saying it would load into memory and then delete the executable, and then maybe put the executable back on the hard drive if it detected the system was being shut down?

  • @geckoo9190
    @geckoo9190 5 років тому

    So, if I understand well this is like those ram attacks before it was protected and randomized, but instead of just passing an addres, it tells windows to fetch the slippers.

  • @jumpierwolf
    @jumpierwolf 6 років тому +4

    Could those exploits be used on game consoles to run homebrew?

    • @Ardkun00
      @Ardkun00 6 років тому +1

      Yes, but it would require some customization.

    • @HP97user
      @HP97user 6 років тому +2

      no... that's not how any of this works... this is reading memory, not running an os

    • @allanlansdowne340
      @allanlansdowne340 6 років тому

      Only if you are connected to the internet.

  • @joesterling4299
    @joesterling4299 6 років тому

    6:22 - "All you can really do is be careful what you click on out there."
    That's all we can ever really do. (Well, sanitizing with script blockers also helps.) Security holes spring up faster than the plugs for them.

  • @spectrefour2404
    @spectrefour2404 6 років тому +19

    I'm still wondering why my name was used for a security bug.

  • @tzint56
    @tzint56 6 років тому

    glad i learned more about assembly and internal operations of a CPU. all of this makes a ton of sense. it's a way of deducting data at a memory address instead of asking for it directly (which will give a segmentation fault because the memory address it's asking for is outside of the program's "virtual memory", basically its partitioned area / sandbox that it plays in). seems to exploit cpu registers, wouldn't surprise me if this video explains it a little off just so that it's easier to explain. it'd be hard to write an assembly-level bug that utilizes any kind of inference of data, but then again it could probably be done in C, but i doubt it would be

  • @inidjilin
    @inidjilin 6 років тому +15

    Who the hell cares about someone being the first of a video

  • @TeamTeddy666
    @TeamTeddy666 6 років тому +1

    4:20
    I think I've done this before. Right after my PC turns on, if i try to open explorer, it won't open immediately because it just turned on. But, if I try to open it again, it immediately opens 2 windows of it. I'm not sure if this would fall into this "pattern" category, but It's something I noticed.

    • @FireController1847
      @FireController1847 6 років тому +4

      that's just lag. you hit the button twice, so it will open two windows. if you hit it once, and wait, it will only open once.

    • @tiosatria9919
      @tiosatria9919 6 років тому +1

      after you turn on your pc. your disk usage will reach about 100% that's because windows memory management, cache, and all that stuff to keep your windows running. because of that, you cant access your windows explorer immediately, there's alot of data to process. here's a tip : Replace your current hdd with ssd, this will solve your problem.

  • @xavierssounds3232
    @xavierssounds3232 6 років тому +120

    Only one of you were first.

  •  6 років тому

    well thats one of the reason i'm using adblock and pop up blocker
    you'll never know what ads on some website can harm your devices.

  • @Trev0r98
    @Trev0r98 6 років тому

    "Speculative execution" or "branch prediction" are not "bugs", they're features, and they're burned into intel, Sun, HP, DEC, AMD and ARM silicon, since 1995.

  • @marekvrbka
    @marekvrbka 6 років тому +41

    *Laughs in AMD*

  • @mikeloeven
    @mikeloeven 5 років тому +1

    How much you want to bet Specter and Meltdown were intentionally implemented at the direction of the NSA and only got fixed because OOPS cats out of the bag

  • @dominikgoslawski627
    @dominikgoslawski627 6 років тому +3

    time to change my passwords to some 10 word sentences

    • @Ardkun00
      @Ardkun00 6 років тому

      Don't say that or attackers will know the method to crack you.

    • @MLWJ1993
      @MLWJ1993 6 років тому +1

      Dominik Goslawski Problem is they get cached anyway...

  • @as7river
    @as7river 5 років тому

    6:41 you can see he's ridiculously proud of the segway he just came up with.

  • @marcuswilson3375
    @marcuswilson3375 5 років тому

    When Spectre and meltdown start trying to steal each other's information

  • @muffinV136
    @muffinV136 3 роки тому +1

    Techquickie: it infects computer CPU’s
    Me around 1:00: good thing im watching this on a tablet ;-;
    Techquickie: IT EVEN INFECTS SMARTPHONES
    Me: NOOOOOOOOOOOOOOOOOOOO

  • @josiahjoel7580
    @josiahjoel7580 6 років тому +1

    This was so simpified and and comprhensive thanks lmg

  • @EdyDev
    @EdyDev 4 роки тому +1

    I like how at 2:35 PhotoShop eats up more RAM than Chrome ;))))

  • @seapeajones
    @seapeajones 6 років тому

    That squarespace segue was gold.

  • @Competitive_Antagonist
    @Competitive_Antagonist 5 років тому

    My CompTIA teacher would say how he only uses telephone banking on a separate line and would only plug it in when he needed to use it. I can see why now.

  • @a7medal-tell471
    @a7medal-tell471 Рік тому

    This video is the best one about processor security

  • @sagetx
    @sagetx 6 років тому

    I was under the impression to get any information out, you needed local access. As opposed to "clicking on something bad".

  • @marcse7en
    @marcse7en Рік тому

    I love "Dr. No's" kinky shiny black PVC hands! (mentioned at the start of the video, in case you weren't paying attention) 👍😜🤣

  • @schunter20
    @schunter20 6 років тому

    Why has this channel not tackled the important issues like slime and it's effectiveness as a thermal paste?

  • @letslike15
    @letslike15 6 років тому

    You should take a Look at Branchscope, it's as devastating as Spectre but not mentioned in mainstream media for some reason.

  • @FlameSoulis
    @FlameSoulis 6 років тому

    That just blows my mind. So even if I do something as simple as:
    if(false) {dothis()} it will still 'dothis()' even though the code literally renders it impossible because of the possibility of having to 'dothis()'?

  • @stevenlonien7857
    @stevenlonien7857 3 роки тому +2

    The gold is best mylar to drone sheets over triple meltdowns plutonium concoction.keep change bagged good defence.weapon..

  • @StackableGoldMC
    @StackableGoldMC 6 років тому

    So um why the whole Spectre and Meltdown viruses seem worrying this also explained to me why my applications seem to just speed up in loading times over a few days.... weird.

  • @ahobimo732
    @ahobimo732 5 років тому

    This is why I do all my computing with an enormous roll of toilet paper and a vast quantity of pebbles.

  • @elgsquilliam
    @elgsquilliam 6 років тому

    The tech quickie intro is so good. I forgot about it, since I've been watching all vids in Floatplane

  • @Rock-pu8bw
    @Rock-pu8bw 6 років тому

    Way to change moods...
    "And that's why, all of your data can be stolen and you should be afraid. Also, check out squarespace to make your very own website!!"

  • @KrisMcCool
    @KrisMcCool 4 роки тому

    Ah well good luck trying to extract bank account from my computer that doesn’t even have a bank account.

  • @Tallone55
    @Tallone55 6 років тому

    Linus didn't mention the way these vulnerabilities affect cloud hosts the most.

  • @darkcreature9755
    @darkcreature9755 6 років тому

    Linus could you please make a video talking about differences between C++ and C# and which one is better.

  • @trentonpaul6376
    @trentonpaul6376 6 років тому

    woah this video is far better than the rest on this channel (I want to see more videos like this)

  • @gigabyte128
    @gigabyte128 6 років тому

    and no mention of the spectre microcode updates... well done linus..

  • @haas170
    @haas170 6 років тому

    2:25 Missed chrome joke opportunity there

  • @Covid-bv4hp
    @Covid-bv4hp 4 роки тому

    Spectre: Affects Intel, AMD, and even phone CPUs.
    Watch Dogs 2:

  • @kaiwenyu6519
    @kaiwenyu6519 6 років тому

    It is so clever to figure this bug out. So much fun understanding Meltdown!

  • @hedlund
    @hedlund 6 років тому

    You may have done this already, but if not: I'd really love to see a vlog or WAN Show segment regarding these vulns. Aside from wanting your personal opinion(s) on the whole spectacle, I want to know if you've any tips for us, because I'm sure I'm not alone in having less-than-savvy relatives and friends who are damn near guaranteed to achieve said meltdown in record time, and I really don't know how to begin explaining this to them.

  • @HocksEvan
    @HocksEvan 2 роки тому

    When Linus explains a topic better than a university lecturer.

  • @self_checkout
    @self_checkout 6 років тому +1

    The Spectre! One of my favorite son- Oh.. you are talking about that other Spectre...

  • @donny6003
    @donny6003 4 роки тому

    Wow I'm impressed, this video actually got down into pretty technical subjects

  • @nFBMAGIX
    @nFBMAGIX 6 років тому

    As requested, AsRock made a microcode-Update for the good old Z77Pro3. SandyBridge is safe for now. Good thing.

  • @HellcatGamin
    @HellcatGamin 4 роки тому

    Is it not possible to to code a software that tells the processor to check for a certain code before allowing it to do anything whatsoever?

  • @Flabbycakes
    @Flabbycakes 6 років тому +1

    Well then... I guess I'll add this to the list of things that keep me up at night...

  • @william_mazza
    @william_mazza 6 років тому

    Thank for the explaination Linus

  • @WarmongersInc
    @WarmongersInc 6 років тому

    Why did it take until now to be discovered? 1995 bro.... Also i heard that for Spectre you have to be physically next to someone's PC, while Meltdown can be exploited remotely. Is it true?

  • @gFamWeb
    @gFamWeb 6 років тому

    Thank you for actually explaining what it does in detail.

  • @1x4x9
    @1x4x9 5 років тому

    I got a kick out of how you guys made Meltdown sound like a Breen...

  • @powder3d
    @powder3d 3 роки тому

    Linus: Meltdown affects every intel CPU made since 1995
    Me: *gets a 1994 intel Celeron* YEET

  • @frostytheiceberg1127
    @frostytheiceberg1127 4 роки тому

    *Footage of technical explanation of the ICUP Joke, 2000-something, Colorized*

  • @harshivpatel6238
    @harshivpatel6238 6 років тому

    now that, was a good rectangular space advert!