-
dportenlanger
AskWoody LoungerApril 25, 2018 at 8:42 pm in reply to: Are Windows customers getting Meltdown/Spectre bullied into buying new computers? #187467Look here.
https://www.cyberciti.biz/faq/check-linux-server-for-spectre-meltdown-vulnerability/
1 user thanked author for this post.
-
dportenlanger
AskWoody LoungerApril 25, 2018 at 7:12 am in reply to: Are Windows customers getting Meltdown/Spectre bullied into buying new computers? #187155My point is simply this. If SpecCheck says you are not vulnerable to any of the three specex variants, either the SpecCheck is wrong or Intel and Microsoft have made the decision to leave systems vulnerable, which is negligent and irresponsible, even if the likelihood of an issue is near zero.
I would suggest that if Linux can mitigate all three variants, Windows can too. I have tested three different machines.
- Lenovo G700 which will have no firmware update.
- Lenovo W701 which Intel pulled the firmware update.
- Toshiba Satellite which is the oldest spare machine I can test.
All three pass SpecCheck as noted by Ascaris.
Does this mean that those of us who have to administrate hundreds of Windows machines could have been spared the CVE-2017-5715 firmware updates? Microsoft is pushing out microcode for some processors.
Is there some architecture difference between Windows and Linux that will reopen the Linux is more secure than Windows debate?
Are Intel and Microsoft leaving older machines vulnerable on purpose?
Does specheck need an update because it is misreporting?
Is using one of the three variants to exploit a machine so difficult and unlikely that it isn’t worth protecting every machine?
I am no expert, but I feel it is important to understand the issues and the exposure to make informed decisions
3 users thanked author for this post.
-
dportenlanger
AskWoody LoungerApril 24, 2018 at 8:30 pm in reply to: Are Windows customers getting Meltdown/Spectre bullied into buying new computers? #187047Myself and several other people have several computers that will not have BIOS updates from Intel or from the manufacturer. One machine I have is an Ivy Bridge machine, but Lenovo doesn’t have the model listed as eligible. The other is much older but has a 4 core 8 thread Extreme processor that was abandoned but still runs great.
What I discovered was running Meltdown/Spectre check scripts on Linux (Ubuntu in my case) seems shows that my older machines are not vulnerable to Meltdown or Spectre. So Linux must have done something in the boot process that loads microcode to foil Meltdown and both variants of Spectre.
I am curious whether others have found this to be the case and is it a possible solution to save these machines from the scrap bin. If this is the case, would running Linux with Windows OS and applications running in a VM (if Windows is needed) keep the older but powerful hardware operational?
-
dportenlanger
AskWoody LoungerDon’t you know the solution to all your computing resource problems are “To The Cloud!”?
Yeah, I am not drinking that Kool-Aid either.
-
dportenlanger
AskWoody LoungerYou already have your answer. Meltdown/Spectre aren’t being fixed. They are being mitigated. As such, the past few months has demonstrated the outcome. The whole thing is a complete cluster.
-
dportenlanger
AskWoody LoungerI did some of my own informal unscientific testing of patching and firmware updates for Meltdown/Spectre. The firmware kills I/Os. We know Meltdown and one variant of Spectre are already software patched. I wonder, given the surface area of Spectre variant 2, whether the firmware update performance hit is even worth considering. Unless you are a government or financial entity, is it worth suffering such a performance hit? I recommend holding off on firmware updates. See below.
-
- The difference between having the firmware patched almost doubled application load times on my test laptop. An app that took 7 seconds to load before patching took 13 seconds after patching on a 3 year old machine. This was on the Lenovo E550 before and after firmware loads.
I ran for a week and witnessed zero reboots or instability. I have some suspicion that Intel pulled the firmware because of performance, not instability.
I am a little concerned about verification tools. I patched my the E550 firmware and OS and passed Inspectre’s testing. Then I back leveled the firmware. Inspectre still showed my system was completely secure. Microsoft’s powershell script showed the E550 was secure on Winodws 10 1703. Inspectre wouldn’t verify the E550 was secure until it was on Win 10 1709. We need better verification tools.
Below are some other informal unscientific load times. The T430 has a slightly faster processor than the E550, but the E550 is much newer and most every other piece of hardware should be faster.
Machine 1: Lenovo T430 – No Spectre Firmware Patch.
Core i7, 12GB RAM, 512GB SSD, Bitlocker
Machine 2: Lenovo E550 – Spectre Firmware Patch
Core i7, 16GB RAM, 512GB SSD, BitlockerEdit to remove HTML. Post may not appear as author intended.
Please convert to plain text (.txt) before cut/paste operation from Word document -
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
MailStore Home updates
by
Alex5723
4 hours, 7 minutes ago -
T-Mobile users say they see other people’s account information
by
Alex5723
15 hours, 17 minutes ago -
Retirement of Exchange Web Services in Exchange Online
by
Alex5723
1 day, 3 hours ago -
What Remote Desktop credentials do I use to access a MS Account computer
by
JP
14 hours, 31 minutes ago -
Office 2003 Compatibility with One Drive in Windows 11
by
langsjw
1 day, 14 hours ago -
Has KB5030219 been pulled for Windows 11 Pro for Workstations?
by
jharri46
1 day, 15 hours ago -
By default encryption on Apple
by
Susan Bradley
1 day, 7 hours ago -
KB5029331 Macrium/Reflect
by
fpefpe
1 day, 9 hours ago -
Windows 10 Build 19045.3513 (22H2) to Release Preview Channel
by
joep517
1 day, 20 hours ago -
Microsoft worker accidentally exposes 38TB of sensitive data in GitHub blunder
by
Nibbled To Death By Ducks
1 day, 5 hours ago -
Change CPU/Mainboard without reinstallation of OS and Apps – Win10
by
schmersa
1 day, 11 hours ago -
Mouse slows to crawl if Edge in focus
by
bryash
2 days, 15 hours ago -
Windows and Surface chief Panos Panay is leaving Microsoft
by
Alex5723
2 days, 5 hours ago -
Essential Office Portable
by
Microfix
2 days, 17 hours ago -
Essential Office: Disable Spell Check
by
Bob Blum
2 days, 17 hours ago -
Apple 2030
by
Will Fastie
15 hours, 43 minutes ago -
Wi-Fi 7? Why not!
by
B. Livingston
2 days ago -
Second city — the AI view from Washington
by
Max Stul Oppenheimer
3 days, 2 hours ago -
Zeroing in on zero days
by
Susan Bradley
1 day, 11 hours ago -
LMDE – Software Update
by
bassmanzam
17 hours, 5 minutes ago -
MacAfee anti virus left overs
by
Barry
11 hours, 37 minutes ago -
Google issues update for Chrome 109 (Win 7 – Server 2012r2) that fixes WebP
by
n0ads
1 day, 9 hours ago -
Microsoft apparently canning P2P Win32 services on Windows 11 23H2, Windows 12
by
Alex5723
3 days, 12 hours ago -
Inserting from clipboard into posting
by
WSraysig
3 days, 11 hours ago -
Background picture not invoked @ startup
by
WSraysig
1 day, 14 hours ago -
download Linux Mint most recent
by
rjacobscan
3 days, 19 hours ago -
Modify email account settings
by
metzmatt
4 days, 3 hours ago -
Microsoft’s Edge 109 updates for Windows 7 , 8, 8.1, 2012 R2 ! webP fix
by
Alex5723
4 days, 17 hours ago -
High CPU Temperatures (Stock Cooler Insufficient)
by
voltapc
5 days, 1 hour ago -
How to use Roadside Assistance via satellite on iPhone 14 and iPhone 15
by
Alex5723
4 days, 16 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.