Octubre 22, 2018

'Serious' flaws in Intel and other chips impact millions of devices

13 Enero 2018, 03:45 | Bibiana Flor

'Serious' flaws in Intel and other chips impact millions of devices

'Serious' flaws in Intel and other chips impact millions of devices

Google's Project Zero security team recently discovered the bug in processors from Intel, while it has been already confirmed that the bug also exists in AMD and ARM chipsets.

"Intel and its partners have made significant progress in deploying updates as both software patches and firmware updates", the company said in a press release. The researchers who discovered the vulnerabilities said that "almost every system", since 1995, including computers and phones, is affected by the bug.

Suspiciously, Intel CEO Brian Krzanich sold off $24 million worth of stock late last year before the vulnerabilities became public knowledge.

So far, it has not received any reports of attacks due to the two critical flaws, dubbed Meltdown and Spectre.

"Programs can, for example, find passwords that are stored in other programs", he said.

Are the iPad and AppleTV affected?

These exploits make most of the world's devices vulnerable to potential attacks from cyber-criminals.

However, later on Thursday afternoon, CERT/CC withdrew that recommendation, saying merely that anybody affected should install operating system updates as soon as possible.

"From these traces, we can find out some information about the data that it was processing", Dr Yarom explained.

At the moment, the main details of the flaw are being kept under wraps. Spectre won't be stamped out entirely until processors stop relying on a concept known as "speculative execution", which is a cornerstone of modern chip design.

Google agrees. In a blog posted on Thursday, the tech giant says it created a technique called "Retpoline" that protects against the attack with minimal impact on performance.

The chipmaker said it would require users to download a patch and update their operating system to fix the issue.

How will it affect you?

And the worst part is that this patch is going to affect your computer performance. The computing industry is scrambling to lessen the severity of the problem with updates to operating systems, web browsers, cloud-computing services and other foundations that need to be kept secure. And the company now faces class-action lawsuits, including one in Oregon, alleging "material defects" in its technology.

For Chrome OS, version 63 released in December includes patches for "Intel Chrome OS devices on kernels 3.18 and 4.4". However, to call this ill-timed would be an understatement. Fixing the flaw could result in your system slowing down as much as 30 percent.

Intel briefly addressed performance in its statement.

AMD said that its processors are not subject to the vulnerability. Amazon and Apple did not respond to requests for comment.

Dr Glance described the situation as serious but not "hopeless". Google says Android devices are protected if they have the latest security updates.

Otras noticias

Tendencias Ahora

Galaxy S9 Will be Announced at MWC — Samsung Confirms
There's a power/lock key on the right, and a volume rocker on the left, both of which fall nicely under the thumb and finger. Samsung's all-new A8+ dives straight into that zone with a price tag that matches the OnePlus 5T down to the rupee.

Georgia a 'force to be reckoned with' in coming seasons — Kirby Smart
Then, there was a missed facemask call on a D'Andre Swift run that would have extended a Georgia drive. I ran the simulation of the Alabama Crimson Tide vs the UCF Knights on a neutral field 442 times.

Sam's Club in Orange to close
He said some employees would be re-hired at other Walmart locations or at the newly created e-commerce distribution sites. However, the store has yet to open , and Sam's Club has not provided a timeline for the beginning of construction.

Evergreen Federer is clear Australian Open favourite — Tennis
Thiem squibbed a simple overhead with the score at 8-8, allowing Nadal to close out the match. "It's going to be a tough match". Then there is the more cyclical matter of whether a new ruling class is at last prepared to take power on the court.

Microsoft confirms Spectre fix will slow down your Windows PC
Where to go from here? Seems to me they were hoping no one would find out about the bugs whilst they silently fixed them. Last week, security researchers found a couple of major vulnerabilities affecting most modern computing devices.

Manchester United Targets Shakhtar Donetsk Star Fred
So most of the intrigue for the remainder of the season could lie in the fight for Champions League qualification behind City. Manchester City have reportedly decided that they are willing to spend £45m to sign Shakhtar Donetsk midfielder Fred .

A fantastic finish for Alabama — PROCESSING GEORGIA
Nick Saban made what may have been the gutsiest decision of his collegiate coaching career on the biggest stage. The present and future of the Alabama Crimson Tide football team now falls on the shoulders of Tua Tagovailoa .

Manchester United preparing to hijack any Liverpool bid for Christian Pulisic
Liverpool are also interested in the Borussia Dortmund wonderkid, and a head-to-head battle seems to be brewing up for the player. Needless to say, United's board will be keeping a close eye on him this season.

AMD To Begin Distributing Firmware Updates To Patch Spectre Vulnerability
Like this story? Share it! In each case, AMD will supply to OEMs who will then need to make sure they are passed on to the user. Finally, keep in mind we're still in the early days of dealing with these fundamentally different security problems.

Saban has no plans to retire soon — CFB notebook
The New Year's Six bowls and championship game drew an average of 17 million viewers, the most in four years of the format. He allows himself far less time to celebrate actually winning titles, even ones as dramatic as this one.