Günter Born has an important recap of the the test website xlab.tencent.com, which has a tool that can check to see if your browser is currently susce
[See the full post at: Born: Is my browser vulnerable for Spectre attacks?]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Born: Is my browser vulnerable for Spectre attacks?
Home » Forums » Newsletter and Homepage topics » Born: Is my browser vulnerable for Spectre attacks?
- This topic has 22 replies, 17 voices, and was last updated 7 years, 4 months ago by
anonymous.
AuthorTopicViewing 13 reply threadsAuthorReplies-
MrBrian
AskWoody_MVPJanuary 11, 2018 at 10:34 am #158500If I recall from seeing the source code for this test, this test will always report “not vulnerable” if a browser feature called SharedArrayBuffer is not available. SharedArrayBuffer provides a source of timers that a Spectre attack needs, but there are other sources available. There is probably no test that could prove that a browser isn’t vulnerable to Spectre.
7 users thanked author for this post.
-
AlexEiffel
AskWoody_MVPJanuary 11, 2018 at 12:34 pm #158530Yes, it doesn’t mean much. Probably anyone who will develop a working exploit for javascript will have found an alternative way to obtain reliable time and will have tested it against a patched Firefox, IE, Chrome, etc.
4 users thanked author for this post.
-
abbodi86
AskWoody_MVPJanuary 11, 2018 at 1:19 pm #158541Indeed
my Opera 12.18 reported not vulnerable, likewise FlashPeak Slimjet (old version from 2016)
5 users thanked author for this post.
-
MrBrian
AskWoody_MVPJanuary 11, 2018 at 1:29 pm #158547From https://twitter.com/bojanz/status/950458779744825344: “Tencent released a PoC for #spectre at http://xlab.tencent.com/special/spectre/exploit/check.js … Won’t work with patched browsers due to usage of SharedArrayBuffer”
2 users thanked author for this post.
-
anonymous
GuestJanuary 11, 2018 at 1:54 pm #158558I tested an old portable Firefox (v33.x — which definitely has no SharedArrayBuffer feature, as opposed to it being disabled) at Tencent-Xuanwu Lab’s Spectre Online Checker, & the result is instantaneously given as:
$ Start checking…
$
$ According to our checking
$ Your browser is NOT VULNERABLE to SpectreThis is despite the fact that Javascript is enabled, & neither the CPU nor the Win OS kernel is patched against Meltdown-Spectre.
I suppose the online test only checked for the possibility of SharedArrayBuffer-type exploits, but the real world of black hats probably can come up with more tricks.
4 users thanked author for this post.
-
lurks about
AskWoody Loungerryegrass
AskWoody Lounger-
Ed
AskWoody Lounger
anonymous
Guestsamak
AskWoody Plusgeekdom
AskWoody_MVPJanuary 11, 2018 at 3:15 pm #158578It’s way too early to tell. The test must first be reliable.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefenderSteve S.
AskWoody PlusJanuary 11, 2018 at 3:54 pm #158594Tested the latest Firefox ESR 52.5.3 (64-bit) on Win 7 Pro machines and a cheap Win 10 tablet. All show as not vulnerable. But as many have said, this isn’t enough to “rest assured”.
Especially for me with older Core i5 CPUs on Lenovo T410 machines and Lenovo Edge 15 (E50) machines, neither of which are supported by Lenovo now. Processor microcode will likely not be developed by Intel nor issued as a BIOS update by Lenovo.
All our machines are in good shape and do what we need at present. As retirees, we are not excited about having to buy all new machines, let alone having to deal with them being (ugh..) Win 10, though making them Linux is probably our future path….
Win10 Pro x64 22H2, Win10 Home 22H2, Linux Mint + a cat with 'tortitude'.
2 users thanked author for this post.
-
lmacri
AskWoody PlusJanuary 12, 2018 at 8:10 am #158785Hi Steven S.:
From the Mozilla Security Blog entry Mitigations Landing for New Class of Timing Attack:
“Firefox 52 ESR does not support SharedArrayBuffer and is less at risk; the performance.now() mitigations will be included in the regularly scheduled Firefox 52.6 ESR release on January 23, 2018.”
That same blog entry notes that Firefox v57.0.4 update (released 03-Jan-2018) fixed two timing mitigations [SharedArrayBuffer and performance.now()] for the Spectre vulnerability, and other timing sources and time-fuzzing techniques are still being worked on.
According to the Chromium.org article Actions Required to Mitigate Speculative Side-Channel Attack Techniques:
“Chrome has disabled SharedArrayBuffer on Chrome 63 starting on Jan 5th, and will modify the behavior of other APIs such as performance.now, to help reduce the efficacy of speculative side-channel attacks. This is intended as a temporary measure until other mitigations are in place…Chrome’s JavaScript engine, V8, will include mitigations starting with Chrome 64, which will be released on or around January 23rd 2018.”
————
32-bit Vista Home Premium SP2 * Firefox ESR v52.5.3 * NS v22.11.2.7
alpha128
AskWoody PlusPerthMike
AskWoody PlusJanuary 11, 2018 at 7:06 pm #158645I tried to do the vulnerability check, but the page never changed after clicking the CHECK button… Until I noticed the email alert from my firewall that showed that it had blocked the high-security threat. So that was a very useful check of our security!
I fully expected the browser to show up as vulnerable as we haven’t patched IE since December, but the firewall is protecting us in the meantime.
Happy days!
No matter where you go, there you are.
anonymous
GuestMrBrian
AskWoody_MVPJanuary 11, 2018 at 7:40 pm #158657I believe that any web browser used on a device that is vulnerable to Spectre is vulnerable to Spectre, unless the web browser doesn’t allow JavaScript or other programmability.
1 user thanked author for this post.
-
OscarCP
MemberJanuary 12, 2018 at 4:48 pm #158916But isn’t JavaScript (as opposed to Java plugins) needed for maintaining a good deal of a browser’s functionality?
Is this a “d***ed if you do, d***ed if you don’t” situation?
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV -
MrBrian
AskWoody_MVPJanuary 12, 2018 at 5:26 pm #158923“But isn’t JavaScript (as opposed to Java plugins) needed for maintaining a good deal of a browser’s functionality?”
Yes, but one can use an ad blocker and/or selectively allow which domains JavaScript can run from.
2 users thanked author for this post.
-
_Reassigned Account
AskWoody LoungerJanuary 12, 2018 at 10:09 am #158810With Chrome you can enable site isolation but its going to eat up RAM and could break some sites. Google cautions its still experimental. I suspect eventually some of this will end up in the browsers by default in a few months. Not surprising given the hardware is not changing or 100% fixed, so browsers will be part of the solution.
johnf
AskWoody LoungerJanuary 12, 2018 at 10:29 am #158813For those of us running Linux Mint, there’s this from their Website (some of it may be of use in Windows as well):
Firefox 57.0.4
Firefox was patched. Please use the Update Manager to upgrade it to version to 57.0.4.
NVIDIA 384.111</p>
If you are using the NVIDIA proprietary drivers, upgrade them to version 384.111.
In Linux Mint 17.x and 18.x, this update is available in the Update Manager.
In LMDE, it is available on the NVIDIA Website.Chrome Site Isolation
If you are using Google Chrome or Chromium, please follow the steps below:
Type chrome://flags in the address bar and press Enter.
Scroll down the page and find “ and press the Enable button.
Restart the Chrome browser.
https://www.chromium.org/Home/chromium-security/sscaOpera
If you are using the Opera browser, visit opera://flags/?search=enable-site-per-process, click Enable and restart Opera.Linux Kernel
Please use the Update Manager to upgrade your Linux kernel.
The following versions were patched:</p>
3.13 series (Linux Mint 17 LTS): patched in 3.13.0-139
3.16 series (LMDE): patched in 3.16.51-3+deb8u1
4.4 series (Linux Mint 17 HWE and Linux Mint 18 LTS): patched in 4.4.0-108
4.13 series (Linux Mint 18 HWE): patched in 4.13.0-25Note: The current HWE series in Linux Mint 18 moved from 4.10 to 4.13.
Some users reported issues with early kernel updates (4.4.0-108 issues in particular were fixed since in 4.4.0-109). We strongly recommend you use Timeshift to create a system snapshot before applying the updates. Timeshift is installed by default in Linux Mint 18.3 and available in the repositories for all Linux Mint 17.x and 18.x releases.Intel Microcode
Please use the Update Manager to upgrade intel-microcode to version 3.20180108.0.
Note: If intel-microcode isn’t installed on your computer, run the Driver Manager to see if it’s needed.Edit to remove HTML> May not appear as poster intenede.
PLEASE convert to plain text before cut/pasteanonymous
GuestViewing 13 reply threads - This topic has 22 replies, 17 voices, and was last updated 7 years, 4 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Discover the Best AI Tools for Everything
by
Alex5723
2 hours, 9 minutes ago -
Edge Seems To Be Gaining Weight
by
bbearren
4 hours, 28 minutes ago -
Rufus is available from the MSFT Store
by
PL1
13 hours, 7 minutes ago -
Microsoft : Ending USB-C® Port Confusion
by
Alex5723
15 hours, 17 minutes ago -
KB5061768 update for Intel vPro processor
by
drmark
1 hour, 10 minutes ago -
Outlook 365 classic has exhausted all shared resources
by
drmark
13 hours, 28 minutes ago -
My Simple Word 2010 Macro Is Not Working
by
mbennett555
11 hours, 2 minutes ago -
Office gets current release
by
Susan Bradley
13 hours, 39 minutes ago -
FBI: Still Using One of These Old Routers? It’s Vulnerable to Hackers
by
Alex5723
2 days, 3 hours ago -
Windows AI Local Only no NPU required!
by
RetiredGeek
1 day, 12 hours ago -
Stop the OneDrive defaults
by
CWBillow
2 days, 4 hours ago -
Windows 11 Insider Preview build 27868 released to Canary
by
joep517
2 days, 14 hours ago -
X Suspends Encrypted DMs
by
Alex5723
2 days, 16 hours ago -
WSJ : My Robot and Me AI generated movie
by
Alex5723
2 days, 16 hours ago -
Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
by
Alex5723
2 days, 17 hours ago -
OpenAI model sabotages shutdown code
by
Cybertooth
2 days, 18 hours ago -
Backup and access old e-mails after company e-mail address is terminated
by
M W Leijendekker
2 days, 6 hours ago -
Enabling Secureboot
by
ITguy
2 days, 13 hours ago -
Windows hosting exposes additional bugs
by
Susan Bradley
3 days, 2 hours ago -
No more rounded corners??
by
CWBillow
2 days, 21 hours ago -
Android 15 and IPV6
by
Win7and10
2 days, 11 hours ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
3 days, 14 hours ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
3 days, 17 hours ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
3 days, 11 hours ago -
Windows Update orchestration platform to update all software
by
Alex5723
4 days ago -
May preview updates
by
Susan Bradley
3 days, 11 hours ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
3 days, 3 hours ago -
Just got this pop-up page while browsing
by
Alex5723
3 days, 16 hours ago -
KB5058379 / KB 5061768 Failures
by
crown
3 days, 13 hours ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
2 days, 15 hours ago
Recent blog posts
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | 4 | 5 | 6 | 7 |
8 | 9 | 10 | 11 | 12 | 13 | 14 |
15 | 16 | 17 | 18 | 19 | 20 | 21 |
22 | 23 | 24 | 25 | 26 | 27 | 28 |
29 | 30 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.