Skip to content
  • AT SNOWFLAKE
  • Industry solutions
  • Partner & Customer Value
  • Product & Technology
  • Strategy & Insights
Languages
  • Deutsch
  • Français
  • Português
  • Español
  • English
  • Italiano
  • 日本語
  • 한국어
  • Deutsch
  • Français
  • Português
  • Español
  • English
  • Italiano
  • 日本語
  • 한국어
  • AT SNOWFLAKE
  • Industry solutions
  • Partner & Customer Value
  • Product & Technology
  • Strategy & Insights
  • Deutsch
  • Français
  • Português
  • Español
  • English
  • Italiano
  • 日本語
  • 한국어
  • 개요
    • Why Snowflake
    • 고객 사례
    • 파트너 네트워크
    • 서비스
  • 데이터 클라우드
    • 데이터 클라우드
    • 플랫폼 개요
    • SNOWFLAKE 데이터 마켓플레이스
    • Powered by Snowflake
    • 라이브 데모
  • WORKLOADS
    • 협업
    • 데이터 사이언스&머신러닝
    • 사이버 보안
    • 애플리케이션
    • 데이터 웨어하우스
    • 데이터 레이크
    • 데이터 엔지니어링
    • 유니스토어
  • PRICING
    • Pricing Options
  • 산업별 솔루션
    • 광고, 미디어 및 엔터테인먼트
    • 금융 서비스
    • 의료 및 생명 과학
    • 제조
    • 공공 부문
    • 소매 / CPG
    • 테크놀로지
  • 리소스
    • 리소스
    • Documentation
    • 핸즈온 랩
    • 트레이닝
  • CONNECT
    • Snowflake 블로그
    • 커뮤니티
    • 이벤트
    • 웨비나
    • 팟캐스트
  • 개요
    • 회사 소개
    • 투자정보
    • 리더십 및 이사회
    • 채용
Author
Mario Duarte Mario Duarte
Share
Subscribe
2018년 01월 17일

Snowflake’s Remediation Plans for the Meltdown and Spectre Vulnerabilities

  • 제품 및 기술
  • 보안
Snowflake’s Remediation Plans for the Meltdown and Spectre Vulnerabilities

Meltdown

Meltdown is a hardware vulnerability that primarily affects Intel x86 processors. An attacker must have local access on the target system and must be able to run their rogue code to successfully exploit the Meltdown vulnerability. Moreover, security researchers have  determined that Meltdown poses a clear risk to a virtualized environment.

In lieu of that, we commend the major cloud IaaS providers such as AWS for recognizing the threat, rolling-up their sleeves and quickly deploying a remediation security update. All indications from AWS suggest they have successfully remediated this vulnerability. Since Snowflake security tightly controls the code that can be run on our production servers, the main threat for data exposure is cross-VM attacks which AWS has remediated with its hypervisor patch.

There has also been a lot of concern about performance degradation after AWS deployed the security update. Our current internal performance results fall well within the noise range. In other words, we have not detected any significant impact to performance.

In addition, AWS has published an AWS kernel update so customers can deploy it to their respective VMs. However, Snowflake’s defense-in-depth approach adequately addresses the impact of Meltdown in the Snowflake service because we have a tight control of who can access our production environment. We limit this access to only those who need to perform administrative and security support. We also enforce several forms of multi-factor authentications before anyone can access the production VPC,  and we monitor all system changes on our servers and ensure those changes are authorized and secure. Although our security architecture does not require the AWS kernel patch for security reasons, we are evaluating the performance impact of this patch and will install it in all situations that do not materially impact the experience of our customers. Moreover, we have updated all of our Snowflake endpoints such as our company laptops.  

Spectre

Snowflake currently considers the Spectre Variant 1 vulnerability (CVE-2017-5753) as the most risky of the three new classes of speculative attacks (e.g., Spectre Variant 1, Spectre Variant 2, and Meltdown) because it has the ability to exploit browsers via JavaScript. Therefore, we have deployed all available browser Spectre patches to all of our Snowflake endpoints and we will continue to quickly deploy new browser Spectre patches when they become publicly available.

Outside of the browser attack surface, we will continue to remediate this vulnerability across our environment as vendors take proactive measures by releasing security updates. For example, we have deployed a vendor’s Spectre security update in our test environment and we are currently running regression and performance tests. We expect to deploy such a patch to the production environment shortly.

In the interim, we are monitoring our environment and continue to research for potential exploits by leveraging our security partners.

Customers

It is also critical that our customers update their systems, especially if they may execute untrusted code, which could be vulnerable to Meltdown or Spectre. This includes updating user web browsers with vendor-provided updates as soon as possible. We also recommend that customers leverage two-factor authentication whenever possible. As such, Snowflake generally recommends that customers use our MFA services and our IP whitelist features for interactive logins to their Snowflake account for defense-in-depth.

Conclusion

We will continue to send customer updates as we reach patch deployment milestones or if we detect significant system performance issues with the mitigations associated with these vulnerabilities.

Try Snowflake for free. Sign up and receive $400 US dollars worth of free usage. You can create a sandbox or launch a production implementation from the same Snowflake environment.

Share

What is ETL?

ETL (extract, transform, load) are the three processes that move data from one or multiple databases, or other sources to a...

Find Out More
Read More

Build Your Code in Snowflake Using Snowpark and Your Favorite...

To develop and deploy code with Snowpark, developers have always had the chance to work from their favorite IDE or notebook....

More to follow
Read More

Pricing: Why Pay for What You Don’t Use?

Snowflake's data warehouse pricing and cost is based on your actual usage. Scale storage and compute independently.

Full Details
Read More

Data Engineering Use Cases with Snowpark and Java UDFs

Learn how to accelerate data engineering through Snowpark and make building complex data pipelines a breeze.

Expand your knowledge
Read More
Snowflake Inc.
  • 플랫폼 개요
    • 아키텍처
    • 데이터 애플리케이션
  • 데이터 마켓플레이스
  • Snowflake 파트너 네트워크
  • 지원 및 서비스
  • 회사
    • 문의하기

Sign up for Snowflake Communications

Thanks for signing up!

  • Privacy Notice
  • Site Terms
  • Cookie Settings

© 2023 Snowflake Inc. All Rights Reserved