VMware Patches Spectre Vulnerability In VMware Fusion…. So, What About Parallels Desktop For Mac?
If you run virtual machines on your Mac, you have two choices. You can run VMware Fusion or Parallels Desktop. In both cases, you have to worry about the fallout from the Spectre and Meltdown CPU issues. And in the case of VMware Fusion, they’ve addressed Spectre in their latest update. Specifically, they’ve addressed an attack vector that only appears on virtual machines. Plus VMware has provided specific instructions on how their users can secure themselves.
So, that leaves Parallels Desktop For Mac. What are they doing to protect their users? Well, the closest thing to advice that I have seen is these Tweets:
Hey Brian, Sorry for the late response. Apple has just released a software update to address the Spectre vulnerability: macOS High Sierra 10.13.2. https://t.co/EtbXLyFUdW Please let us know if you need further information. We are happy to help you. Thanks.
— Parallels (@parallels) January 9, 2018
And:
Hey Brian, We have just checked with our engineers. As advised by Apple and Microsoft we recommend that you update your macOS and your VMs. We will share more updates as more information comes available. In the meantime stay alert to updates from Microsoft, Apple & more. Thanks
— Parallels (@parallels) January 10, 2018
The problem with this response is that patching macOS and whatever operating systems that you’re using in your virtual machines isn’t enough as pointed out by VMware. Thus there has to be a patch for the virtual machine software. Now I tried to find any further communication from Parallels and I could not. Thus you have to wonder if Parallels is working on something, or are they ignoring this. I say that because in the absence of any info, people will wonder if the company actually cares. Thus if I were Parallels, I’d be putting out some sort of statement of Spectre and Meltdown ASAP, because VMware has beaten them to the punch and is drawing a pretty stark comparison between the two products that has VMware in control of the message on this issue.
UPDATE: Parallels released an update to Parallels Desktop For Mac. The release notes make no mention of Spectre and Meltdown fixes. So I pinged Parallels over Twitter. Here’s what I got back:
Hi- please refer to https://t.co/n8FHoq05oI for the update summary but it does not have any update related to Spectre and Meltdown.Thanks, AM.
— Parallels Support (@ParallelsCares) February 20, 2018
The release notes that is referenced in the Tweet is the same one that I looked at prior to pinging them on Twitter. Thus it doesn’t appear that they’ve done anything to mitigate Spectre and Meltdown despite the fact that their nemesis VMware Fusion has.
February 5, 2018 at 8:13 am
[…] tried to exploit them. That makes the screw ups in trying to patch these holes, along with the non-action by some companies in not patching these holes a big issue. Thus pretty much everyone who runs a computer could be in very deep trouble very […]
February 21, 2018 at 9:15 am
[…] that my opinion of their software has really gone downhill because of this. Not to mention the fact that they don’t seem to offer mitigations for the threats posed by Spectre and Meltdown like their main competitor which is VMware Fusion does. Thus later this week I’ll be […]
February 23, 2018 at 8:09 am
[…] VMware Fusion 10 provides mitigations from the Spectre CPU vulnerability. That’s important to me as I take security seriously. Parallels Desktop 13 doesn’t appear to provide that mitigation which was a concern to me and was the main driver for me to make the switch. […]
October 18, 2018 at 10:01 am
[…] faster. The second last item was a chief motivator for me to move to VMware Fusion last year as my previous virtualization product didn’t offer those fixes. Support for Metal is great because that is another way that VMware has increased the performance […]