[ meltown & spectre ] Puppy's kernel update ?

For discussions about security.
Message
Author
musher0
Posts: 14629
Joined: Mon 05 Jan 2009, 00:54
Location: Gatineau (Qc), Canada

#21 Post by musher0 »

souleau wrote:Okay, so the situation with me is that I am running Puppy Precise 5.7.1 on an machine with an AMD Athlon 3000+ processor.

I am very happy with this setup since it has been tweaked to cater my preferences over a long period of time.

Now, patches for Ubuntu Precise are only available for Ubuntu Advantage customers with Extended Security Maintenance. So if I want security I should basically switch to another Puppy.

But I don't want to.

If I understand correctly, my cpu is only vulnerable to one form of the Spectre exploit, which in itself is the more difficult one to accomplish.
So the question really is, am I a wreckless idiot for thinking the risks are negligible if I don't do anything at all?
Hi souleau.

I don't think so. If you are, I am too! ;)

One other reason being that, at this time, the threats are "theoretical", as I
understand it.

It's good to know that some computer experts are on the look-out for these types
of technical failings, and are doing something about it.

But IMO it does no one any good to lose sleep over this if no easy-to-apply end-
user solution is available.

I read elsewhere that Linux kernels are susceptible to only one of the three threats
as well. If the threats are not the same (checking this is above my pay grade), one
would be safe running a Linux distro on an AMD machine -- without doing anything.

BFN.
musher0
~~~~~~~~~~
"You want it darker? We kill the flame." (L. Cohen)

User avatar
souleau
Posts: 148
Joined: Sun 23 Oct 2016, 15:24

#22 Post by souleau »

Thank you for the reassurance musher0!

It seems my risk asessment was not merely born out of convenience after all.

ozsouth
Posts: 858
Joined: Fri 01 Jan 2010, 22:08
Location: S.E Australia

#23 Post by ozsouth »

I spent a day upgrading my Slacko64-6.9.9.9 k4.9.30
to kernel 4.9.77. Meltdown is covered - others not as compiler isn't retpoline aware, & insufficient LFENCES.
Hence an updated Pup is still required. Site isolation in Firefox 55 onwards mitigates to some degree.

Post Reply