Live data from Hacker News

Intel Responds to Security Research Findings

newsroom.intel.com

101–110 of 245 posts

Re: Intel Responds to Security Research Findings

#101
> Based on the analysis to date, many types of computing devices — with many different vendors’ processors and operating systems — are susceptible to these exploits.

Yes, many. Not your biggest competitor though, AMD. They're fine. And that may be the point you're trying to downplay here.

> Intel believes its products are the most secure in the world

Again, your biggest competitor, AMD, does not have this flaw. So precisely how is Intel the 'most secure in the world' if your biggest competitor is more secure than you?

The title of this post should be 'Intel PR Responds to Security Research Findings'.

Re: Intel Responds to Security Research Findings

#102

Do we know the actual bug yet? I sort of assumed it was a timing attack on KASLR rather than a leak of traditional kernel data. Although I guess that there would have been cheaper mitigations like mapping an empty page to all of the other KASLR slots rather than doing a full world switch in that case...

[deleted]

Re: Intel Responds to Security Research Findings

#103
It's always interesting when you see a damage control statement that basically boils down to "contrary to what you may have heard, ". It's a subtle kind of straw man, where you reassure your audience by listing the same mitigating facts they've already heard, but act as if those facts have been previously omitted.

I guess the goal is to produce the affect of reassurance when you don't actually have any substantive reassurance to offer. I wonder if this works, in general? My sense is that it always smells like bullshit, but I wouldn't necessarily recall instances where it didn't.

Re: Intel Responds to Security Research Findings

#104

Earlier quoted context omitted.

https://twitter.com/brainsmoke/status/948561799875502080

Is the source to this published anywhere?

Wondering the same thing, though presumably if one researcher were able to deduce how the exploit worked, more will soon.

Re: Intel Responds to Security Research Findings

#105
post #88
post #66

Earlier quoted context omitted.

>Presumably the statement was hastily put together I don't think so. Given that both *nix and MS seems to have been working on this for at least a month already it can't have come as a surprise.

But the story seems to only have broken to "mainstream" yesterday and has gained a lot of attention in the last 24 hours.

Sure. Catching mainstream media off guard is different from Intel though. There is no way this caught them by surprise.

If anything it reads like it was very carefully crafted by lawyers to make sure they don't get sued to hell for a defective product. (It's not but lawyers are gonna lawyer)

Re: Intel Responds to Security Research Findings

#106

The reports are trickling in that Mossad has already exploited this security flaw to their advantage. Seems like the "flaw" may have been a backdoor designed by someone from their Haifa operations.

Please don't spread conspiracy theories, especially not those with an undercurrent of antisemitism.

At least not without links to these "reports".

Re: Intel Responds to Security Research Findings

#108
What a scummy, dishonest response.

- Saying it's not a 'bug' or 'flaw' = lie.

- Cold naming AMD and ARM in the post, I'm certain not just to throw their names in the ring but also for SEO ranking and relationships.

- Failing to address the root cause, how it came to be and provide other technical references.

And let's not forget - Intel's CEO sold his stock.

--

* Note: "AMD chips are affected by some but not all of the vulnerabilities. AMD said that there is a "near zero risk to AMD processors at this time." British chipmaker ARM told news site Axios prior to this report that some of its processors, including its Cortex-A chips, are affected." - http://www.zdnet.com/article/security-flaws-affect-every-int...

Re: Intel Responds to Security Research Findings

#109

Earlier quoted context omitted.

We know that AMD is not affected: https://lkml.org/lkml/2017/12/27/2

We know that "AMD processors are not subject to the types of attacks that the kernel page table isolation feature protects against." E.g. that AMD does not need the patch that Intel does. That is not the same as saying AMD is not affected at all. We do not know what the actual bug that prompted this activity is. Nobody has revealed that information. It is possible that the bug affects AMD also but does not require th…

The followup sentence: "The AMD microarchitecture does not allow memory references, including speculative references, that access higher privileged data when running in a lesser privileged mode when that access would result in a page fault."

That is a pretty specific reference to the root of the problem, and a pretty clear indication that AMD's design decisions protect against whatever the attack is. Sure, we may find out that there is more to the attack than just speculative memory references, but so far what we have seen suggests a fairly specific vulnerability (that just happens to involve the particular design choices of a dominant chipmaker).

Re: Intel Responds to Security Research Findings

#110

Earlier quoted context omitted.

Intel is certainly entitled to make and promulgate an objective assessment of the impact of the problem, but a problem is still a problem even if it doesn't affect everyone.

Who says they won't? The issue is embargoed, but that's, as usual, not keeping everyone from speculating. That's fine too, but also realize the layman (even people in this thread) is getting pummeled with ideas like "my new laptop is going to be 30% slower tomorrow; WTF!!!"

> Who says they won't?

Not me. My comments are restricted to certain things Intel did choose to say.

And as you are concerned about rumor and disinformation, I cannot imagine you are pleased with Intel's insinuation that AMD processors are also affected.

UPDATE: It seems AMD may be being misleading in this case...

Post reply on HN