Intel fixes CPU security flaw it said was patched in May

[ad_1]

The Vrije Universiteit Amsterdam researchers who alerted Intel to the problems have told the New York Times that Intel apparently ignored key proof-of-concept exploits when developing the May update, and should have found the relevant flaws even without those ready-made examples. The team refused to stay quiet with the November patch knowing that there were still issues. There are also criticisms of Intel’s overall approach — instead of tackling the underlying problem, it’s allegedly focused more on patching variants of that problem as they pop up.

The initial problem affected many processors released since 2011 and applied regardless of your operating system. Software-level patches have mitigated some of the security problems on top of Intel’s microcode solutions.

We’ve asked Intel for comment. This isn’t a great look for the chip giant, whatever its response. As the researchers warned, the usual secrecy that governs vulnerability disclosures could hurt users here. Hackers could take advantage of security holes that people don’t realize are still open, and the flaw itself wasn’t all that secret — it leaked to the point where the researchers were told about their own discovery. There may be substantial work ahead (including possible chip design changes) before Intel’s CPUs are more trustworthy.

[ad_2]

Source link