Behind the Speculative Curtain The True Story of Fighting Meltdown and Spectre @HackersOnBoard
Behind the Speculative Curtain The True Story of Fighting Meltdown and Spectre  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 5 days ago
Black Hat USA 2018

It's January 2nd, 2018. Your phone buzzes. You've been working for more than 6 months to fight a new class of hardware vulnerabilities with a number of other companies. You had seven days until planned disclosure, but the incoming text tells you that there has been a leak and disclosure is now less than 24 hours away. You aren't ready…what do you do?

Months before the public learned about the challenges with speculative execution, defenders from hardware, platform, cloud, and service providers were working together around the clock building mitigations and coordinating a response to help protect the billions of users depending on their platforms. This is the behind the scenes story of what those months were like, from the perspective of Apple, Google, and Microsoft. Along the way, competitors became partners and an unprecedented level of information was shared.

Much has been written about how to do multi-party coordinated response, it's time to throw out what you know – we need a new playbook. In this panel, you'll learn about details of the response that have never been shared with the public, and you'll come away with lessons about what worked and what didn't in the most complicated multi-party vulnerability in memory.

The tech industry is increasingly interdependent and Spectre and Meltdown are a wake-up call on multiple dimensions – how we engineer, how we partner, and how we react when we find new security issues. This panel won't give you all the answers, but it is a start.
Behind the Speculative Curtain The True Story of Fighting Meltdown and SpectreBlack Hat USA 2018 - Lowering the Bar Deep Learning for Side Channel AnalysisBlack Hat USA 2018 - Identity Theft Attacks on SSO SystemsSubverting Sysmon: Application of a Formalized Security Product Evasion MethodologyBlack Hat USA 2018 - WebAssembly A New World of Native Exploits on the BrowserBlack Hat USA 2018 - Dont @ Me Hunting Twitter Bots at ScaleBlack Hat USA 2018 - Demystifying PTSD in the Cybersecurity EnvironmentDEF CON 27 - Bug Finding And Exploit Techniques On File Transfer App Of All Top Android VendorsBlack Hat USA 2018 - Attacking Client Side JIT CompilersBlack Hat USA 2018 - Return of Bleichenbachers Oracle Threat (ROBOT)Black Hat USA 2018 Keynote Parisa TabrizDEF CON 27 - Hila Cohen - Malproxy Leave Your Malware at Home
HackersOnBoard |

Behind the Speculative Curtain The True Story of Fighting Meltdown and Spectre

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER