Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Microcode updates are distributed via Windows update.


But Microsoft says they are not:

>In addition to installing the January security updates, a processor microcode, or firmware, update is required. This should be available through your device manufacturer. Surface customers will receive a microcode update via Windows update.

https://support.microsoft.com/en-gb/help/4073119/windows-cli...


If the microcode update requires motherboard vendors to issue BIOS updates we are all doomed.


This appears to be the case at least on my Windows 10 laptop.

I've installed the hotfix for Windows, but when I run the PowerShell script to determine whether mitigation is active, the script tells me that it's not active, due to lack of hardware support. The script then goes on to give the recommendation to "Install BIOS/firmware update provided by your device OEM that enables hardware support for the branch target injection mitigation."

It's a 1-year-old ASUS laptop and I would be surprised if they even give a sane response to my question to their technical support (I doubt they will even know what I'm talking about).


"Dear OEM Vendor Technical Support,

There has been recent news about critical security issues in Intel CPUs, requiring a firmware update for all laptops and motherboards with Intel chips.

The vulnerabilities include the potential for malicious websites to read sensitive system memory, including passwords and encryption keys.

I have model XXYY-ZZZZ, do you have any information on when an update will be available, and where I can access it?

If not, can you attempt to escalate this ticket? The security issues are starting making their rounds in the news, and more information can be found at https://meltdownattack.com

Thank you, and happy new year :)"

Seems like it might be worth a shot.


"Dear usr frend,

thx for ur interst in our product. our team will reach u. we have many new products. hope u have great new year!

- OEM volume sales"


Thanks! I will use this if they don't understand my version of it.


I saw the same thing on my Lenovo laptop: installed the Windows update, the PowerShell scripts said it's missing HW support. Installed a new BIOS update from Lenovo (released two weeks ago, btw), now the PS script says I have the needed HW support and is now protected. So on this laptop, the needed microcode appears to have come from a new BIOS and not via Windows.

I have another Gigabyte MB that I suspect is too old for BIOS updates anymore so I am really hoping that at some point these microcode updates due come through Windows and not just via BIOS updates.


Same here with 1-year old HP laptop.


Somehow I doubt Sony's going to be updating the BIOS for this VAIO laptop I'm typing this on, given that the last update was in 2012... and they don't even make computers anymore.


There are a variety of examples of Microcode updates referenced on support.microsoft.com (here's just one):

https://support.microsoft.com/en-us/help/3064209/june-2015-i...

...so I suspect this is just a standard disclaimer.

Generally, microcode updates are distributed with the OS or OS distribution.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: