Privacy & Security Strategies for Non-Profits
Impacts of Meltdown & Spectre
By Kris Constable
@cqwww
Meltdown & Spectre
Speculative execution (what's going to happen
next) & side channel attacks (physical, electrical
and/or mechanical characteristics – hardware)
relating to CPUs (Intel, AMD & ARM)
Meltdown: Kernel vs Userland
Spectre: Segmentation between applications
...
A helpful reminder you need a privacy & security
strategy
What can you do?
Have an organizational strategy and ensure
compliance by measuring compliance
Patch all the things
Masscan & metasploit
Let's go through the layers of the OSI model.
CERT suggests upgrading your CPU
Patch your operating systems
(server, laptop, phone)
Download the latest version of your browser.
I recommend something based off Google
Chromium or Mozilla Firefox.
I use Iridium and Firefox Focus.
For chrome, type this in your URL:
chrome://flags/#enable-site-per-process
and click “enable” on “Strict site isolation.”
Block JavaScript and Flash by default
NoScripts
Ablock Plus or Ublock Origin
Privacy Badger
Make sure you're using antivirus, including
mac/osx users, and are using it properly
Restore from your backups
https://privasectech.com/the-blog/
Or PrivaSecTech on Facebook
Questions?
kris@privasectech.com
@cqwww

Practical Security for Nonprofits: Spectre and Meltdown With Kris Constable