Company
Date Published
Author
Redis
Word count
318
Language
English
Hacker News points
None

Summary

With the recent security vulnerabilities discovered — Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 and CVE-2017-5715) — Redis’ engineering, devops and support teams have been working hard to make sure our cloud services, Redis Enterprise Cloud (REC) and Redis Enterprise VPC (REV), are protected. As of now, all our REC and REV clusters on AWS, Azure, GCP and IBM Cloud have been patched by our cloud partners against Meltdown. In addition, some cloud vendors have already managed to mitigate the Spectre’s branch target injection (CVE-2017-5715). Redis Enterprise Software customers experienced negligible performance impacts of between 2.5% - 30%, depending on cluster instance types and cloud infrastructure, with successful mitigation for several customers during recent days. The engineering team has validated this impact through tests on a 3-node REV cluster on AWS, observing no effect on latency and minor throughput impacts.