January 17, 2018
The Artemis Security Team is continually monitoring the IT Security landscape. In early 2018, two major vulnerabilities known as “Meltdown” and “Spectre” were publicly announced. These vulnerabilities affect the majority of modern computing devices. The Artemis Security Team immediately began risk analysis and remediation planning.
Our IT Resources Inventory has been thoroughly reviewed to identify all affected systems. We have followed up with cloud, hardware, and software vendors to determine the firmware updates and/or security patches needed to fix the vulnerabilities. We are pushing updates through an accelerated patch management process to test and release them to our production systems with minimal impact to employees and customers.
As the Artemis Platform service infrastructure resides entirely in Amazon Web Services, we refer to the AWS response to address the underlying hardware: https://aws.amazon.com/security/security-bulletins/AWS-2018-013/
We run Ubuntu Server on all of our servers, so for operating system updates we refer to the official Ubuntu response: https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown
There are reports that many of the patches to fix the vulnerabilities could have mild to significant performance impacts. As always, we are monitoring the Artemis Platform performance and system resources, and we will allocate additional resources as needed to ensure optimal performance.
Artemis employee workstations include both Mac and Windows. Security updates have been released for both, and we are installing these updates as soon as they become available.
Our software development team is up-to-date on the vulnerabilities and taking these into consideration for future development. At this time, we have determined that the Artemis Platform is not affected by the vulnerabilities.
Security at Artemis is a top priority, and our robust security program is designed to address these types of issues. We are confident that our customers’ data is safe and secure within our network. We encourage all our customers to seek advice from their internal IT Security teams to protect the systems they use to access the Artemis Platform.
Thank you!
The Artemis Security Team