Are smaller actors left behind?
Are smaller actors left behind?
DigitalOCean appear out of the loop and they're fairly sizeable[
OVH appear to have received no advanced notice (if you read between the lines of their post)
Cloudflare has been silent and they usually love being at the front of this stuff. They'll also probably take a nasty hit from these mitigation's too with their incredibly heavy network load, so they might all be out buying hardware.
That said, you've got to draw the line somewhere, AWS is truly huge and a key Intel customer, Google is one of Intel's biggest buyers and their researcher independently discovered it, Microsoft equally a massive Intel customer.
Overall I'd say Intel tried to keep it to an absolute minimum which is fair enough really. Had the news not broken early it's probable that patch notifications would have gone out once fully developed to all of these 'smaller' companies.
* https://www.freebsd.org/news/newsflash.html#event20180104:01
The Ubuntu people also got that same notification it appears, but were also secretly told by Intel in November 2017.
* https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAn... (https://news.ycombinator.com/item?id=16071769)
People are claiming that the OpenBSD people knew years ago, but what Theo de Raadt was discussing then was a list of published errata for the Core Duo. The bugs that are in the news right now were never published errata. I suspect that the OpenBSD people found out about them at the same time that the world at large did.
https://en.wikipedia.org/wiki/Iliad_SA
Not quite a smaller actor.