DEV Community

Discussion on: Software security is hopelessly broken

Collapse
 
hepisec profile image
hepisec

I don't think that "code" can be vulnerable to Meltdown and Spectre. These are information leakage vulnerabilities which require to run code on your machine. If you're running your web application on bare metal (no shared host), you won't be affected much as long as you apply normal security best practices.

In cloud environments these vulnerabilities are critical, but I expect all major cloud platforms to apply the patches quickly.

Vulnerable clients should also apply normal security best practices, including ad blocking and patching.

Thread Thread
 
bosepchuk profile image
Blaine Osepchuk

Yes. Where I said "code" it would have been more accurate to say "the security of the information contained in your app" is/was still vulnerable...