Major Security Flaws Found to Affect Nearly All Computers

Major Security Flaws Found to Affect Nearly All Computers

The vulnerabilities, which were originally believed to only be in Intel chips, affect a variety of chip vendors and could allow hackers to steal the entire memory contents of computers, mobile devices and services running in cloud computer networks.

[UPDATED January 5, 2018, at 9:38 a.m.]

Two major security flaws have been discovered in the microprocessors inside nearly all computers. The vulnerabilities, which were originally believed to only be in Intel chips, affect a variety of chip vendors and could allow hackers to steal the entire memory contents of computers, mobile devices and services running in cloud computer networks.

The two security flaws, called Meltdown and Spectre, allow programs to read and steal data from other programs on a computer. This could include stored passwords from a browser or password manager, personal files, important documents and online communication like emails.

Software patches can help with Meltdown, and Microsoft and Google have already issued emergency patches, though they could slow the performance of devices by as much as 20 to 30 percent.

Spectre, unfortunately, won’t be as simple to resolve. Researchers believe it’s a more difficult flaw to exploit, but it affects most microprocessors now in use, and there is no known fix. Some experts believe it could ultimately warrant a complete redesign of hardware, an expensive task.

“We’re talking about an average, $1,000 per computer versus a free software patch,” said Devon Ackerman, associate managing director of the cybersecurity and investigations practice at risk mitigation firm Kroll. “Basically, I am replacing the entire computer with something that is a newer generation, something that is no longer susceptible to this exploit at a hardware level.”

As a result, Spectre may not be solvable until new chips hit the market. Paul Kocher, the president and chief scientist at Cryptography Research, a division of Rambus, said the threat from Spectre is “going to live with us for decades.”

“This will be a festering problem over hardware life cycles. It’s not going to change tomorrow or the day after,” Kocher said. “It’s going to take a while.”

Both the U.S. Department of Homeland Security and Britain’s National Cyber Security Centre are monitoring the situation with both vulnerabilities but say they have not yet seen evidence that the flaws are being exploited.

Original story below.

A hardware bug may make all computers with Intel Corp. chips from the last decade vulnerable to hackers, according to a report released by The Register on Tuesday. Fixing the bug will require patching at the operation system level.

The circumstances of the security exploit have not been publically released due to security concerns, but the bug is related to the way regular apps and programs can access the contents of protected kernel memory and could be present on Intel processors made in the past 10 years. Hackers could potentially exploit security weaknesses to access security keys, passwords and other files in protected kernel memory.

The fix appears to be to implement Kernel Page Table Isolation, making the kernel essentially invisible to running process. Unfortunately, patching the operating system and updating the security could slow down older machines by between 5 and 30 percent, according to the Register.

The Register’s report said that programmers have been working since November on a software patch that addresses the issue. Linux patches and a partial fix for the bug in macOS have been rolled out, and Microsoft is expected to release a fix soon.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Protecting Data is Critical

    To say that the Internet of Things (IoT) has become a part of everyday life would be a dramatic understatement. At this point, you would be hard-pressed to find an electronic device that is not connected to the internet. Read Now

  • Mobile Access Adoption

    Smartphones and other mobile devices have had a profound impact on how the world securely accesses the workplace and its services. The growing adoption of mobile wallets and the new generation of users is compounding this effect. Read Now

  • Changing Mindsets

    We have come a long way from the early days of fuzzy analog CCTV systems. During that time, we have had to migrate from analog to digital signals. When IP-based network cameras arrived, they opened a new world of quality and connectivity but also introduced plenty of challenges. Thankfully, network devices today have become smart enough to discover themselves and even self-configure to some degree. While some IT expertise is certainly required, things are much smoother these days. The biggest change is in how fast security cameras and supporting infrastructure are evolving. Read Now

Featured Cybersecurity

Webinars

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3