Showing posts with label Spectre. Show all posts
Showing posts with label Spectre. Show all posts

Friday, January 12, 2018

How chip flaws Spectre, Meltdown work and what's next


LAS VEGAS - Smartphones, PCs and servers across the world have received software updates in recent days to plug security gaps on computer chips that cyber security researchers have described as the most serious threat in years.

Researchers identified the problem last year, shared details with chip manufacturers last summer, and then made a public announcement Jan. 3.

WHAT IS THE PROBLEM? 

The vulnerabilities, known as Meltdown and Spectre, can allow passwords and other sensitive data on chips to be read. The flaws result from the way computers try to guess what users are likely to do next, a process called speculative execution.

Simon Segars, the chief executive of chip designer ARM Holdings, described speculative execution as the equivalent of spinning a bunch of plates in the air, with the plates holding data.

Watching the order in which the plates land lets observers infer the data, he told Reuters during an interview on Wednesday at the tech industry's CES conference in Las Vegas.

HOW BAD IS IT? 

Affected chipmakers and large technology companies including Alphabet Inc's Google say they have not seen any malicious hackers use Meltdown or Spectre in attacks, but the vulnerabilities affect most modern computing devices.

Security analysts have said that Meltdown, which only affects Intel Corp chips, is easier to exploit because the program to steal passwords and other data can be hidden on a website.

Spectre, meanwhile, requires more direct access to the microchip, but affects central processing units from Intel, Advanced Micro Devices Inc and SoftBank Group Corp's ARM.

HOW HAVE CHIPMAKERS AND TECHNOLOGY COMPANIES RESPONDED? 

Chipmakers have teamed up with Google, Microsoft Corp, Apple Inc and other leading tech companies since the summer to devise software patches.

DO THE FIXES HAVE SIDE EFFECTS? 


The slowdown particularly affects Intel chips vulnerable to Meltdown. Intel said on Wednesday that the performance decline is as much as 10 percent, but that a typical home and business PC user should not see big changes in how long it takes to save a document or open a photo stored on a computer.

The patches, however, do not always work with other software. For example, a fix for Spectre led to issues turning on some computers with AMD chips, and a Meltdown patch for Microsoft Windows required changes from antivirus makers.

WHAT IS BEING DONE TO PREVENT SIMILAR PROBLEMS IN THE FUTURE? 


ARM's Segars said his company has been tweaking designs for future chips to add "maximum flexibility."

The biggest change is adding more transistors to chips, a negligible cost, to make it easier to turn chip features on and off, he said.

Giving yourself "maximum flexibility" means it will be easier to respond to future flaw discoveries, Segars said.

Chipmakers and operating system makers must also collaborate more. "What’s important to establish there is guidelines around how to write software so you don’t run afoul," he said.

source: news.abs-cbn.com

Tuesday, January 9, 2018

Microsoft says security patches slowing down PCs, servers


Microsoft Corp said on Tuesday that software patches released to guard against microchip security threats slowed down some personal computers and servers, with systems running on older Intel Corp processors seeing a noticeable decrease in performance.

The comments in a blog post were the clearest signal from Microsoft that the microchip flaws for Intel and other chipmakers described last week could meaningfully degrade performance.

Microsoft also said that security updates froze some computers using chipsets from Intel rival AMD, dragging AMD's shares down nearly 4 percent.

Shares in Intel, which reiterated on Tuesday that it saw no sign of significant slowdown in computers, fell 2.5 percent.

AMD shares have gained nearly 20 percent in the last week as investors speculated that the chipmaker could wrest market share from Intel, whose chips were most exposed to the security flaws.

Security researchers disclosed the flaws on Jan. 3 that affected nearly every modern computing device containing chips from Intel, AMD and ARM Holdings, owned by Japan's SoftBank Group Corp.  




"We (and others in the industry) had learned of this vulnerability under nondisclosure agreement several months ago and immediately began developing engineering mitigations and updating our cloud infrastructure," Microsoft executive Terry Myerson wrote in a blog post on Tuesday.

Meltdown and Spectre are two memory corruption flaws that could allow hackers to bypass operating systems and other security software to steal passwords or encryption keys on most types of computers, phones and cloud-based servers.

ARM Holdings estimated that around 5 percent of more than 120 billion chips its partners have shipped since 1991 was impacted by Spectre. It said the number of chips affected by Meltdown was significantly less.

"ARM will address Spectre in future processors but there will need to be an ongoing discipline in the design of secure systems which needs to be addressed through both software and hardware," a company spokesman said in an emailed statement.

Intel and AMD have not disclosed the number of chips affected by the security flaws.

Intel said a typical home and business PC user should not see significant slowdowns in common tasks such as reading email, writing a document or accessing digital photos.

The chipmaker said last week that fixes for security issues in its microchips would not slow down computers, rebuffing concerns that the flaws would significantly reduce performance.

Rival AMD had also played down the threat, saying its products were at "zero risk" from the Meltdown flaw, but that one variant of the Spectre bug could be resolved by software updates from vendors such as Microsoft.

But on Tuesday AMD said it was aware of an issue with some older-generation processors following the installation of a Microsoft security update that was published over the weekend.

Microsoft said it was working with AMD to resolve the issues.

Apple Inc also released an updated version of its operating system software on Monday to fix the security flaw.

source: news.abs-cbn.com

Friday, October 30, 2015

Self-driving cars headline Tokyo motorshow


Agaw-eksena sa Tokyo motor show ang mga concept cars na eco-friendly at self-driving. Virtual reality naman ang ipinakitang mauuso sa Paris Games Week. Si Lebron James, magkakaroon ng bagong game show. Ang bagong James Bond movie na "Spectre," tumabo agad sa takilya sa opening day sa London. Bandila, October 29, 2015, Huwebes

source: www.abs-cbnnews.com