Live data from Hacker News

Intel Responds to Security Research Findings

newsroom.intel.com

11–20 of 245 posts

Re: Intel Responds to Security Research Findings

#15
>Recent reports that these exploits are caused by a “bug” or a “flaw” and are unique to Intel products are incorrect.

From the English, this report makes it seems like there was no bug and no flaw. However, they say that ((bug || flaw) && only_intel) is false, but I have seen that AMD was not impacted.

Seems like this is a bug or flaw, since they are addressing it soon. They make it seem like everyone should be working in the same boat to address this, but they are just trying to un-distance themselves from their competition.

Re: Intel Responds to Security Research Findings

#16
Lots of people being critical of this response. I think it's pretty good, and have been on the disclosing side of this equation many times.

Admits responsibility and says their current course of action (working with key stakeholders). Addresses concerns of the workaround. Has a timeframe for future updates. Has a call to action for what you should be doing next. To those of you pointing out that this is PR, you're right but that's not a problem...

Short and sweet and has it all. If anything, it is a day late but monstrous organizations probably had a lot of bureaucracy to cut through.

People are so reactionary and quick to throw any company with a security issue under the bus, without ever having been on the other side of the table. The reality is issues happen to everyone and Intel wants to fix it.

Re: Intel Responds to Security Research Findings

#17
post #10

It comes across as fairly defensive. Presumably the statement was hastily put together, but it's not really the tone you want to strike when you have a lot of worried customers wondering what is going on. > Intel believes its products are the most secure in the world and that, with the support of its partners, the current solutions to this issue provide the best possible security for its customers. A rather bizarre s…

> A rather bizarre statement of nothingness, and also an odd thing to say in a statement that just named AMD and ARM.

Particularly bizarre considering the use of "believes". If Intel disbelieved that their own products are the best in any particular respect, that might actually warrant a press release on its own.

Re: Intel Responds to Security Research Findings

#18
This is a good time to bring up Intel ME. It is a black box and has already proven to have security issues. There maybe be more we do not know of. This paging flaw is accidental however Intel ME is designed to have unfettered control over all parts of the machine.

If Intel really believed in making secure products and believed in secure computing, they would remove Intel ME.

Re: Intel Responds to Security Research Findings

#19
post #15

>Recent reports that these exploits are caused by a “bug” or a “flaw” and are unique to Intel products are incorrect. From the English, this report makes it seems like there was no bug and no flaw. However, they say that ((bug || flaw) && only_intel) is false, but I have seen that AMD was not impacted. Seems like this is a bug or flaw, since they are addressing it soon. They make it seem like everyone should be worki…

> since they are addressing it soon. They make it seem like everyone should be working in the same boat to address this

I can assure you that indeed "everyone is working in the same boat to address this", and has been doing so for months, across multiple OS and processor vendors. It's already public that Microsoft and Apple have also implemented page table isolation, and certainly Intel didn't name-drop AMD and ARM carelessly in the press release.

Re: Intel Responds to Security Research Findings

#20
post #4

This is not a security report, this is PR. Among other things, it implies, without explicitly naming them, that AMD, ARM and OS vendors are being directly affected while most information out there point out it's merely an Intel issue.

Some ARM cores are genuinely implicated in this: https://news.ycombinator.com/item?id=16058454
Post reply on HN