01/04/2018
CRITICAL SECURITY ISSUE PSA
We just sent this email out to our clients.
Dear clients,
I’m writing to proactively inform you about two very recent computer security issues that may affect your websites. They’re called “Meltdown” and “Spectre” by the security community. You may see information about these in the news shortly, if you haven’t already. They are hardware level issues in Intel processors, which means that they will probably effect most of the computers in your life, both work and home, including Windows, Mac and even Linux machines.
More information on these issues (warning: pretty technical): https://techcrunch.com/2018/01/03/kernel-panic-what-are-meltdown-and-spectre-the-bugs-affecting-nearly-every-computer-and-device/
The hosting providers we commonly recommend (Digital Ocean and Dreamhost) are already aware of these issues and working to actively patch their servers. This may result in a small period of down time as servers reboot. If this is the case, we’ll be sure to let you know if we get advance warning. If you use another hosting company, we can check into how they’re responding to this issue on your behalf and make a recommendation if appropriate. This will likely be half an hour of billable time.
Additionally, it will be critical to patch the computers you use at home and the office. One of the key issues with these vulnerabilities is the possibility of usernames and passwords being stolen directly from the memory on your computer. No amount of security on your website will prevent hackers from gaining access to it if the computers you use to log in are compromised.
Please work with your IT professional to ensure that your computers are updated at the earliest possible opportunity, and stay on top of keeping them patched.
As a client of Medium Rare Interactive, we treat your site's security with the highest level of importance. We will continue to monitor this situation as it develops. If you are a maintenance client, we will incorporate necessary changes into your hosting account. If you are NOT a maintenance client, we strongly recommend a maintenance contract with Medium Rare. It is not within our power to help you with your own computers, and again strongly recommend that you contact your IT provider to ensure you computers are patched.
More generally, the online world has changed, and continues to change rapidly and dramatically. We strongly recommend that you add the following items into your repertoire:
• A password manager, following best security practices. We recommend Kitestrings: https://www.kitestrings.io
• An ad blocker. One of the most obvious attack vectors proposed with Meltdown and Spectre is malicious JavaScript served through ads on less savoury sites.
• Enable multifactor authentication. We like the Authy app, but there are others that we’re investigating as well. Yubikey comes recommended.
If you're confused by the avalanche of early reports, denials, and conflicting statements about the massive security issues announced today, don't worry —..