Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Microsoft Tweaks Edge Browser in Wake of Meltdown, Spectre CPU Flaws

    Written by

    Pedro Hernandez
    Published January 9, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      After the discovery of the Meltdown and Spectre processor flaws, Microsoft Edge and Internet Explorer 11 will act a little differently, even if it’s not obvious to users. As part of Microsoft’s response to the CPU vulnerabilities that have put much of the IT industry on edge, the software maker is changing how its web browsers process web applications and sites.

      On vulnerable systems, Meltdown and Spectre increase the risk of side-channel attacks triggered by malicious web content, potentially allowing attackers to access private information outside the scope of a given website. One way that Microsoft is mitigating this risk is by removing support for the SharedArrayBuffer JavaScript optimization that was introduced in the Windows 10 Fall Creators Update. SharedArrayBuffer may return after the company is confident that it can’t be used to stage an attack, according to Microsoft Principal Lead Program Manager John Hazen.

      Another step the company took involved “reducing the resolution of performance.now() in Microsoft Edge and Internet Explorer from 5 microseconds to 20 microseconds, with variable jitter of up to an additional 20 microseconds,” wrote Hazen in a blog post. As its name suggests, the performance.now() method is used to gauge the responsiveness in web applications by precisely measuring time intervals, a requirement of a successful Meltdown and Spectre attack.

      “These two changes substantially increase the difficulty of successfully inferring the content of the CPU cache from a browser process,” concluded Hazen.

      Other browser vendors are also working to eliminate the threat posed by Meltdown and Spectre.

      Chrome 64, due on Jan. 23, will “contain mitigations to protect against exploitation,” stated Google in an advisory related to the CPU bugs. In the interim, users can enable the browser’s Site Isolation feature, which isolates websites into separate address spaces. The downside is that Site Isolation can drive up memory utilization by 10 to 20 percent, cautions Google.

      Mozilla, maker of the Firefox browser, is taking a similar approach to Microsoft and addressing the threat by lowering the resolution of performance.now() and disabling SharedArrayBuffer by default. “In the longer term, we have started experimenting with techniques to remove the information leak closer to the source, instead of just hiding the leak by disabling timers,” blogged Mozilla software engineer Luke Wagner.

      Problem Patches Paused

      Meanwhile, Microsoft is dealing with the aftermath of Meltdown and Spectre patches that produced errors that disabled AMD PCs for some users.

      After investigating the problematic patches, the company decided on Jan. 8 to temporarily block the delivery of several Windows updates to PCs running on select AMD processors. A total of nine updates are affected, according to this online support document.

      Finally, Microsoft is weighing in on the performance impact that its patches can have on Windows PCs and servers.

      In a Jan. 9 blog post, Terry Myerson, executive vice president of Microsoft’s Windows and Devices group, warned of “more significant slowdowns” on Windows 10 PCs running on fourth-generation “Haswell” Intel Core processors relative to newer systems. Windows 7 and 8 users can expect a noticeable decrease in performance, Myerson added. He also warned Windows Server administrators of “a more significant performance impact when you enable the mitigations to isolate untrusted code within a Windows Server instance.”

      Pedro Hernandez
      Pedro Hernandez
      Pedro Hernandez is a writer for eWEEK and the IT Business Edge Network, the network for technology professionals. Previously, he served as a managing editor for the Internet.com network of IT-related websites and as the Green IT curator for GigaOM Pro.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.