Live data from Hacker News

Intel Responds to Security Research Findings

newsroom.intel.com

31–40 of 245 posts

Re: Intel Responds to Security Research Findings

#31
post #16

Lots of people being critical of this response. I think it's pretty good, and have been on the disclosing side of this equation many times. Admits responsibility and says their current course of action (working with key stakeholders). Addresses concerns of the workaround. Has a timeframe for future updates. Has a call to action for what you should be doing next. To those of you pointing out that this is PR, you're ri…

There are other issues Intel does not fix (backdoorable hardware outside of the control of the owner). This is part of Intel's image. So, there's that.

Re: Intel Responds to Security Research Findings

#32
post #16

Lots of people being critical of this response. I think it's pretty good, and have been on the disclosing side of this equation many times. Admits responsibility and says their current course of action (working with key stakeholders). Addresses concerns of the workaround. Has a timeframe for future updates. Has a call to action for what you should be doing next. To those of you pointing out that this is PR, you're ri…

It's also manipulative, mentioning AMD and ARM for no other reason to make people think those also have the flaw.

Re: Intel Responds to Security Research Findings

#33
post #16

Lots of people being critical of this response. I think it's pretty good, and have been on the disclosing side of this equation many times. Admits responsibility and says their current course of action (working with key stakeholders). Addresses concerns of the workaround. Has a timeframe for future updates. Has a call to action for what you should be doing next. To those of you pointing out that this is PR, you're ri…

I don’t agree with you but your point is both defensible and well-argued, and I applaud that. That’s what civilised debate should be all about, right?

Re: Intel Responds to Security Research Findings

#34

> Intel believes these exploits do not have the potential to corrupt, modify or delete data. Reading from kernel memory [edit: from unprivileged apps] is still a severe security issue though, right? This sounds like they're trying to downplay that hard, especially with the "operating as designed" phrase. > Recent reports that these exploits are caused by a “bug” or a “flaw” [Unprivileged] reading from kernel memory i…

> Reading from kernel memory is something of a flaw, no? Fair point about not being Intel specific though.

Well the concept is not, but the company who's processors run most of the worlds' databases was PoC'ed, so ....

Re: Intel Responds to Security Research Findings

#35
post #30

> Intel believes these exploits do not have the potential to corrupt, modify or delete data. Reading from kernel memory [edit: from unprivileged apps] is still a severe security issue though, right? This sounds like they're trying to downplay that hard, especially with the "operating as designed" phrase. > Recent reports that these exploits are caused by a “bug” or a “flaw” [Unprivileged] reading from kernel memory i…

I’m with you that this is corporate-speak panicked PR damage containment at its finest, but reading from kernel memory is only a flaw if you aren’t the kernel. ;)

Haha good point! That's what I meant of course :) edited for clarity.

Re: Intel Responds to Security Research Findings

#36
post #6
post #4

This is not a security report, this is PR. Among other things, it implies, without explicitly naming them, that AMD, ARM and OS vendors are being directly affected while most information out there point out it's merely an Intel issue.

It does explicitly name them: > Intel is committed to product and customer security and is working closely with many other technology companies, including AMD, ARM Holdings and several operating system vendors, to develop an industry-wide approach to resolve this issue promptly and constructively.

I think what the parent comment means is that they're explicitly named, but not explicitly called out as being affected, just heavily implied.

Re: Intel Responds to Security Research Findings

#37

  Intel believes these exploits do not have the potential to corrupt, 
  modify or delete data.
Followed by...

  Check with your operating system vendor or system manufacturer 
  and apply any available updates as soon as they are available.
This press release is a minefield. There are whole paragraphs devoted to say nothing.

Re: Intel Responds to Security Research Findings

#38

> Recent reports that these exploits are caused by a “bug” or a “flaw” and are unique to Intel products are incorrect. Isn't the quote above which is from the Intel press release a blatant lie? All the articles I have seen say this only affects Intel processors. Not AMD processors nor, ARM, MIPS, SPARC or PowerPC chips. Did I miss something or is Intel lying in it's press release.

We won't know until we know what the actual bug is. All we know is that people are writing patches for Intel chips, and what those patches do.

It's very possible that other processors are affected by the same issue in some different way that doesn't require this set of patches to mitigate.

Re: Intel Responds to Security Research Findings

#39

> Intel believes these exploits do not have the potential to corrupt, modify or delete data. Reading from kernel memory [edit: from unprivileged apps] is still a severe security issue though, right? This sounds like they're trying to downplay that hard, especially with the "operating as designed" phrase. > Recent reports that these exploits are caused by a “bug” or a “flaw” [Unprivileged] reading from kernel memory i…

> Reading from kernel memory is something of a flaw, no? Fair point about not being Intel specific though. Well the concept is not, but the company who's processors run most of the worlds' databases was PoC'ed, so ....

Source please?

Re: Intel Responds to Security Research Findings

#40
post #19
post #15

>Recent reports that these exploits are caused by a “bug” or a “flaw” and are unique to Intel products are incorrect. From the English, this report makes it seems like there was no bug and no flaw. However, they say that ((bug || flaw) && only_intel) is false, but I have seen that AMD was not impacted. Seems like this is a bug or flaw, since they are addressing it soon. They make it seem like everyone should be worki…

> since they are addressing it soon. They make it seem like everyone should be working in the same boat to address this I can assure you that indeed "everyone is working in the same boat to address this", and has been doing so for months, across multiple OS and processor vendors. It's already public that Microsoft and Apple have also implemented page table isolation, and certainly Intel didn't name-drop AMD and ARM c…

> and certainly Intel didn't name-drop AMD and ARM carelessly in the press release.

I'm sure it wasn't careless, but they are (from all accounts I have read) blatantly lying. Intel isn't known for above board practices. They will do what it takes to win - period.

Name dropping their competitors (to me), honestly shows me how dire of a situation this is. If it wasn't, they wouldn't feel the need to defend themselves and say, "well look at everyone else".

Post reply on HN