The Dagmar Bürgernew year kicked off with a bang on Jan. 3 when security researchers revealed two major software vulnerabilities that affect, to some extent, most types of computer processors on the planet. Laptops, desktops, Chromebooks, smartphones, and enterprise machines are all potentially at risk, theoretically allowing attackers exploiting what have been dubbed Meltdown and Spectre to steal your passwords and other sensitive data.
And while the ultimate fix may be a costly hardware one, there are steps you can take today to at least mitigate your risk. If you're a Chrome user in particular, Google has one very specific recommendation for protecting against Spectre.
Now here's the rare dash of good news: It's super easy to implement.
SEE ALSO: Google says it's got your back on major CPU vulnerabilityBuried within Google's lengthy (and informative!) blog post on its response to Spectre (Variant 1 and 2) and Meltdown (Variant 3) is a link to a page listing the "mitigation status" of affected products. Essentially, this page lists out all the Google services that are at risk, and what steps the company has taken to address that risk. In some cases, it includes stuff you have to do yourself.
Notably, this doesn't mean that doing these things will 100 percent protect you, but, taken in the aggregate, they represent a line of defense against some seriously big security holes.
This is where we come back to Chrome, and a little something called Site Isolation. According to The Chromium Projects, and this gets technical pretty quickly, "[Site Isolation] makes it harder for untrusted websites to access or steal information from your accounts on other websites."
That sounds good, especially considering that a Google spokesperson told Mashable via email that "Variant 1 (Spectre) can be used in Javascript to pull secrets from a user's browser, by attacking the process memory of the browser."
"The Site Isolation protection loads each individual remote website in a separate process," continued the spokesperson. "By doing so, if a user runs into an attack from a bad site, the process memory for the site the user is trying to reach is unavailable to be attacked. That way, your login secrets for one site cannot be stolen by another."
This is definitely a welcome additional layer of security. So, how to enable it? In Chrome, go to chrome://flags/#enable-site-per-process and click "enable" on "Strict site isolation." You'll need to restart your browser, but otherwise that's it.
Pretty simple, right?
We also reached out to Google to determine if this will have any adverse affects on your browsing experience — say, reduced speeds — and were pleased to hear that we shouldn't really worry about that.
"The performance loss for Chrome specifically should be negligible," the spokesperson assured us.
So, yeah, download all your patches and enable Site Isolation on Chrome. Your data will thank you.
This story has been updated with additional comment from Google.
Topics Cybersecurity Google Intel
Previous:Fucking the Patriarch
Next:Blood Will Out
An artist is turning stretch marks into powerful works of artBeached whale in Paris turns out to be an art pieceAn exit interview with Sean SpicerFeds: Amazon staffers took bribes to prop up sketchy merchants, productsI redownloaded Snapchat for the dancing hot dog, and I am not ashamed'Ratched' on Netflix is the worst season of 'American Horror Story'Sean Spicer apparently stole a miniPandemmys highlights: The best and worst moments of the 2020 EmmysGet a load of this kitty with extremely long legs'Sopranos' memes are having a real moment in 2020WeChat ban in the U.S. temporarily halted by a court orderTwitter to investigate apparent racial bias in photo previewsNicki Minaj has no idea how to use Snapchat and it's hilarious'Sopranos' memes are having a real moment in 2020Here's what healthcare would look like if we took President Trump literallyWeChat ban in the U.S. temporarily halted by a court orderBusiness witches of Instagram: How sorcery found a commercial home on social mediaAn exit interview with Sean SpicerBlue Ivy proves she's got her mother's dance moves in a video too precious for this worldYouTube puts human content moderators back to work Best Black Friday headphones deal: Save $100 on the Beats Solo 4 'Scattered Spider' scammers charged in sophisticated, million Best Mac deal: Get an M4 Mac Mini for $499.99 at Costco 'Alien: Romulus's biggest cameo is its greatest error Shop deals on unlocked phones ahead of Black Friday Arkadium mini crossword answers for November 22 Best Black Friday robot vacuum deal: Save $150 on the iRobot Roomba Vac 2 Windmill Air sitewide sale [November 2024]: Get 20% off everything NYT Connections Sports Edition hints and answers for November 21: Tips to solve Connections #59 When do Black Friday sales start? Early holiday deals are already here. I watch TikTok on mute. Sound off is the way to go. Best Black Friday TV deal: Save $250 on the 75 Best 40th birthday gift ideas What's new to streaming this week? (Nov. 22. 2024) NYT Connections Sports Edition hints and answers for November 22: Tips to solve Connections #60 Best Black Friday smart speaker deal: Save over 50% on Amazon Echo Dot Black Friday Sonos deals: Era 300, Ace, Beam at record lows Best iPad Black Friday deal: Save $70 on the 10th Gen iPad Best Black Friday Garmin deal: Save $50 on Garmin Forerunner 165 France vs. Argentina 2024 livestream: Watch Autumn Internationals for free
2.174s , 8222.921875 kb
Copyright © 2025 Powered by 【Dagmar Bürger】,Pursuit Information Network