Company
Date Published
Author
Roxie Elliott
Word count
473
Language
English
Hacker News points
None

Summary

Today, Intel released a statement regarding L1 Terminal Fault (L1TF), a severe security vulnerability that affects many multi-tenant environments running virtual machines, including DigitalOcean. This vulnerability exposes data to any guest running on the same processor core in our environment, which means an attacker could theoretically use one Droplet to view another Droplet's memory. However, they should have no ability to target a specific Droplet or user. We are continuing to work with Intel to ensure our customers are protected against L1TF and are also proceeding with a longer-tail mitigation response aimed at reducing our reliance on hardware to keep both Droplets and data protected. There is currently no action required from our users to protect their Droplets from the L1TF vulnerability. We will continue to share updates here, and will reach out to you directly if we believe there may be any impact to your account, or should you need to take any action. Remediation efforts are expected to be completed within a few weeks, during which time we will take all possible steps to ensure customer Droplets and data remain safe.