Live data from Hacker News

Intel Responds to Security Research Findings

newsroom.intel.com

81–90 of 245 posts

Re: Intel Responds to Security Research Findings

#81
post #75
post #65

Earlier quoted context omitted.

Bigger than KASLR it seems. https://twitter.com/brainsmoke/status/948561799875502080 Not good.

That's a tweet of someone using the bug to defeat KASLR.

By reading from the actual memory address, yes. Defeating kASLR with side channels is meh. Reading from actual addresses is a different matter entirely.

Re: Intel Responds to Security Research Findings

#82

Intel believes these exploits do not have the potential to corrupt, modify or delete data. Followed by... Check with your operating system vendor or system manufacturer and apply any available updates as soon as they are available. This press release is a minefield. There are whole paragraphs devoted to say nothing.

Somebody please correct me if I'm wrong, but I believe they're basically saying "These exploits do have the potential to read data."

Re: Intel Responds to Security Research Findings

#83

Interesting use of language: 'Recent reports that these exploits... are unique to Intel products are incorrect... Intel is committed to product and customer security and is working closely with many other technology companies, including AMD...' Someone new to the issue might think AMD also has this problem. Similarly (replacing the first elision in the above quote): 'Recent reports that these exploits are caused by a…

Not defending Intel here, but devils advocate... You will find many clients asking how to disable, for example, the Linux patch. Linux is releasing with a flag to disable it, so there is some merit. Why would you want that? There are a lot of times you trust everything running on your box and don't need to take the perf hit. Intel (and possibly other archs/families) found a perf win that ends up having security impli…

Intel is certainly entitled to make and promulgate an objective assessment of the impact of the problem, but a problem is still a problem even if it doesn't affect everyone.

Re: Intel Responds to Security Research Findings

#84

> Intel believes these exploits do not have the potential to corrupt, modify or delete data. Reading from kernel memory [edit: from unprivileged apps] is still a severe security issue though, right? This sounds like they're trying to downplay that hard, especially with the "operating as designed" phrase. > Recent reports that these exploits are caused by a “bug” or a “flaw” [Unprivileged] reading from kernel memory i…

> Hearing echos of Intel's early FDIV response along the lines of "the average computer user doesn't need perfectly accurate division"...

Has to be pointed out that they were correct. Public outrage forced them to change their tune, but their original summary was still on point. That said, it of course could majorly impact a select few.

Re: Intel Responds to Security Research Findings

#85
post #8

Earlier quoted context omitted.

Considering Intel's dominance in the server space, I don't anyone is worried about the average user here

I mean, I am. I have a really nice laptop that I'd rather not have to replace.

Maybe wait until next week to decide if it needs replacing?

Re: Intel Responds to Security Research Findings

#86
post #12

> Intel believes its products are the most secure in the world https://security-center.intel.com/advisory.aspx?intelid=INTE...

"The most secure in the world" does not mean "flawless". Thinking like that is pretty dangerous (and silly)

No, but it does mean more secure than anything else, which is pretty doubtful. Competitors to x86 have always had an advantage as far as security goes; then there is the ME mess; and now we have this latest bug. Nobody expects perfection, but Intel is not "most secure in the world" by any stretch.

Re: Intel Responds to Security Research Findings

#88
post #66
post #10

It comes across as fairly defensive. Presumably the statement was hastily put together, but it's not really the tone you want to strike when you have a lot of worried customers wondering what is going on. > Intel believes its products are the most secure in the world and that, with the support of its partners, the current solutions to this issue provide the best possible security for its customers. A rather bizarre s…

>Presumably the statement was hastily put together I don't think so. Given that both *nix and MS seems to have been working on this for at least a month already it can't have come as a surprise.

But the story seems to only have broken to "mainstream" yesterday and has gained a lot of attention in the last 24 hours.

Re: Intel Responds to Security Research Findings

#89

Earlier quoted context omitted.

I do agree that there are passages in this press release that are totally justified e.g. their calling attention to the fact that other processor vendors have probably been incorporating this flaw into their designs for a while. However, their seemingly innocent mentioning of AMD as being a vendor with which they are coordinating to resolve this issue appears to unfairly (and probably deliberately) implicate AMD in a…

> their calling attention to the fact that many other processor vendors have been incorporating this flaw into their designs for while. You have a source for this claim? Because besides for Intel's press release I can't find any evidence that other manurfacture's processors are vulnerable to this bug.

https://lwn.net/Articles/740393/

...which was linked-to from this article: https://arstechnica.com/gadgets/2018/01/whats-behind-the-int...

Post reply on HN