Skip to content
Support Us

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Nor Gal via Shutterstock

People being warned to check systems as Intel reveals 'serious flaws' in its computer chips

Researchers said any fix for the bug could slow computers down by 30% or more.

A NEWLY DISCOVERED vulnerability in computer chips has raised concerns that hackers could access sensitive data on most modern systems, as technology firms sought to play down the security risks.

Chip giant Intel issued a statement responding to a flurry of warnings surfacing after researchers discovered the security hole which could allow privately stored data in computers and networks to be leaked.

Intel labelled as incorrect reports describing a “bug” or “flaw” unique to its products.

Intel chief executive Brian Krzanich told CNBC that “basically all modern processors across all applications” use this process known as “access memory”, which was discovered by researchers at Google and kept confidential as companies work on remedies.

Google, meanwhile, released findings from its security researchers who sparked the concerns, saying it made the results public days ahead of schedule because much of the information had been in the media.

The security team found “serious security flaws” in devices powered by Intel, AMD and ARM chips and the operating systems running them and noted that, if exploited, “an unauthorised party may read sensitive information in the system’s memory such as passwords, encryption keys, or sensitive information open in applications”.

“As soon as we learned of this new class of attack, our security and product development teams mobilised to defend Google’s systems and our users’ data,” Google said in a security blog.

“We have updated our systems and affected products to protect against this new type of attack. We also collaborated with hardware and software manufacturers across the industry to help protect their users and the broader web.”

Spectre and Meltdown

The Google team said the vulnerabilities, labelled “Spectre” and “Meltdown”, affected a number of chips from Intel as well as some from AMD and ARM, which specialises in processors for mobile devices.

Intel said it was working with AMD and ARM Holdings and with the makers of computer operating software “to develop an industry-wide approach to resolve this issue promptly and constructively.”

Jack Gold, an independent technology analyst, said he was briefed in a conference call with Intel, AMD and ARM on the issue and that the three companies suggested concerns were overblown.

“All the chips are designed that way,” Gold said.

The companies were working on remedies after “some researchers found a way to use existing architecture and get into protected areas of computer memory and read some of the data,” he added.

Microsoft said in a statement it had no information suggesting any compromised data but was “releasing security updates today to protect Windows customers against vulnerabilities”.

But an AMD spokesman said that because of the differences in AMD processor architecture, “we believe there is near zero risk to AMD products at this time”.

ARM meanwhile said it was “working together with Intel and AMD” to address potential issues “in certain high-end processors, including some of our Cortex-A processors”.

“We have informed our silicon partners and are encouraging them to implement the software mitigations developed if their chips are impacted,” the SoftBank-owned firm said.

Slowdown?

Earlier this week, some researchers said any fix – which would need to be handled by software – could slow down computer systems, possibly by 30% or more.

Intel’s statement said these concerns, too, were exaggerated.

“Contrary to some reports, any performance impacts are workload-dependent, and, for the average computer user, should not be significant and will be mitigated over time,” the company statement said.

Tatu Ylonen, a security researcher at SSH Communications Security,  said the patches “will be effective” but it will be critical to get all networks and cloud services upgraded, Ylonen said.

British security researcher Graham Cluley also expressed concern “that attackers could exploit the flaw on vulnerable systems to gain access to parts of the computer’s memory which may be storing sensitive information”.

“Think passwords, private keys, credit card data.”

But he said in a blog post that it was “good news” that the problem had been kept under wraps to allow operating systems such as those from Microsoft and Apple to make security updates before the flaw is maliciously exploited.

Read: Nearly 3,000 fuel allowance payments delayed after technical glitch

More: Some Aer Lingus flights to and from the US cancelled due to ‘bomb cyclone’

Author
View 16 comments
Close
16 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Install the app to use these features.
    Mute ⚡ Seánie ⚡
    Favourite ⚡ Seánie ⚡
    Report
    Jan 4th 2018, 8:38 AM

    Let’s keep this quite though!!

    49
    Install the app to use these features.
    Mute George Salter
    Favourite George Salter
    Report
    Jan 4th 2018, 8:44 AM

    @⚡ Seánie ⚡: “quiet”

    54
    Install the app to use these features.
    Mute Gillian Weir Scully
    Favourite Gillian Weir Scully
    Report
    Jan 4th 2018, 8:49 AM

    @⚡ Seánie ⚡: Slow Down you move too fast, you’ve got to make the moment last! Who sang that?

    So intel and Apple slow down who will be third?

    6
    See 2 more replies ▾
    Install the app to use these features.
    Mute Thomas McGuire
    Favourite Thomas McGuire
    Report
    Jan 4th 2018, 9:42 AM

    @⚡ Seánie ⚡: Would you prefer the fault have been revealed prior to update(s) resolving it?

    11
    Install the app to use these features.
    Mute ⚡ Seánie ⚡
    Favourite ⚡ Seánie ⚡
    Report
    Jan 4th 2018, 10:40 AM

    @Thomas McGuire: it was revealed, otherwise it wouldn’t have been removed

    1
    Install the app to use these features.
    Mute Towger
    Favourite Towger
    Report
    Jan 4th 2018, 9:35 AM

    There is also talk of the Intel’s CEO offloading shares before this went public and a replacement chip scheme, as per the Pentium Division error.

    23
    Install the app to use these features.
    Mute David Murphey
    Favourite David Murphey
    Report
    Jan 4th 2018, 9:58 AM

    @Towger: “Talk”?

    So, gossip, then?

    10
    Install the app to use these features.
    Mute Derek
    Favourite Derek
    Report
    Jan 4th 2018, 11:32 AM

    @David Murphey: no, $24 million worth. It’s reported on plenty of American news sites

    13
    Install the app to use these features.
    Mute Shougeki
    Favourite Shougeki
    Report
    Jan 4th 2018, 9:31 AM

    AMD are not affected. Quick version. Kernel and user space interactions can potentially be fooled using speculative execution methods to potentially read memory address spaces. Fix is to move kernel into a completely invisible (to the user space) area. This has to be done in OS, hence the slow down.

    18
    Install the app to use these features.
    Mute red dave
    Favourite red dave
    Report
    Jan 4th 2018, 10:40 AM
    12
    Install the app to use these features.
    Mute Donal O'Leary
    Favourite Donal O'Leary
    Report
    Jan 4th 2018, 9:10 AM

    I only started overclocking last week =(

    9
    Install the app to use these features.
    Mute Déaglán Ó hÍceadha
    Favourite Déaglán Ó hÍceadha
    Report
    Jan 4th 2018, 8:42 AM

    A storm in a tea cup.

    8
    Install the app to use these features.
    Mute Partysauras Rex
    Favourite Partysauras Rex
    Report
    Jan 4th 2018, 9:01 AM

    @Déaglán Ó hÍceadha: a bit like your sex life so.

    24
    Install the app to use these features.
    Mute Déaglán Ó hÍceadha
    Favourite Déaglán Ó hÍceadha
    Report
    Jan 4th 2018, 11:01 AM

    @Partysauras Rex: Ask your Ma.

    35
    Install the app to use these features.
    Mute purple rain
    Favourite purple rain
    Report
    Jan 4th 2018, 10:11 AM

    Just purchased the new intel 8th gen i5 . that’s me fooked so

    7
    Install the app to use these features.
    Mute Martin Byrne
    Favourite Martin Byrne
    Report
    Jan 4th 2018, 10:55 PM

    @purple rain: not at all. Be grand

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.

Leave a comment

 
cancel reply
JournalTv
News in 60 seconds