punkt.de hosting: Information on Meltdown and Spectre

An architectural error in microprocessors causes a security gap in hosting.

router bgp 16188

Patrick M. Hausen
Netzwerke und Infrastruktur sind sein Steckenpferd - damit Sie sich auf eine stabile Anwendung verlassen können.
Reading duration: approx. 1 Minutes

Dear hosting customers,

As you have no doubt read in the press, fundamental architectural errors were discovered last year in various microprocessors, particularly those manufactured by Intel.

This flaw was used by a team from Google, among others, to construct two different attacks on the confidentiality of applications, which became known as "Spectre" and "Meltdown".

The impact on our hosting is such that we must assume in principle that all information that you process on a proServer or Pluspunkthosting server can be viewed by other customers if they run their applications on the same hardware.

Such a scenario exists for all products that are "virtual" or "shared" - both in the proServer and Pluspunkthosting areas. this is not a problem specific to our infrastructure, but affects all operating systems and also the "cloud environments" of established providers.

If you operate a dedicated server with us, this problem does not affect you.

The developers of our FreeBSD platform were informed by Intel in December 2017 and are working hard on a strategy to work around these problems in the operating system. As the errors lie in the hardware of the processors, there is no guarantee that this can be implemented 100%.

As far as is generally known, it is not possible to penetrate your environment via the network or in any other way and change things (data, software). It is basically "only" a confidentiality problem.

We ask you to generally assume that data that you process on "shared" infrastructure is at least potentially public.

We have always recommended the use of dedicated hardware for processing personal data of protection level C and higher (according to LfD Lower Saxony).

We will inform you about the planned rollout as soon as corresponding operating system updates are available.

You can find some background information here:

If you have any further questions, our hosting team will be happy to help you.

Share:

More articles

Code gestaltet Zukunft – Unsere Leidenschaft für Innovation
Fahim Nasirzadeh, Entwicklung at punkt.de
Working at punkt.de