The 2018 Pwnie Nominee For Most Over-Hyped Bug

Meltdown and Spectre

Credit: Jann Horn, Paul Kocher, Daniel Genkin, Mike Hamburg, Moritz Lipp, Yuval Yarom

Meltdown and Spectre were vulnerabilities in the way branch prediction worked which would allow attackers the ability to read memory. It was pretty awesome and affected most systems. But at some point, they hype train jumped the tracks a bit. The normally extremely accurate Fox News called it the worst computer bug in history. One of the researchers who discovered it agreed, calling it “probably one of the worst CPU bugs ever found”. Bloomberg agreed, the Verge said it was a catastrophe.

But after all of this and the fact most device will never be updated, we still don’t see exploitation of this in the wild. You’d think the worst bug in history would lead to at least a few computers getting hacked. Probably the biggest impact of this bug is the performance impact that its patch introduced.

Meltdown and Spectre (CVE-2017-5715)