Major Security Flaws Found to Affect Nearly All Computers

Major Security Flaws Found to Affect Nearly All Computers

The vulnerabilities, which were originally believed to only be in Intel chips, affect a variety of chip vendors and could allow hackers to steal the entire memory contents of computers, mobile devices and services running in cloud computer networks.

[UPDATED January 5, 2018, at 9:38 a.m.]

Two major security flaws have been discovered in the microprocessors inside nearly all computers. The vulnerabilities, which were originally believed to only be in Intel chips, affect a variety of chip vendors and could allow hackers to steal the entire memory contents of computers, mobile devices and services running in cloud computer networks.

The two security flaws, called Meltdown and Spectre, allow programs to read and steal data from other programs on a computer. This could include stored passwords from a browser or password manager, personal files, important documents and online communication like emails.

Software patches can help with Meltdown, and Microsoft and Google have already issued emergency patches, though they could slow the performance of devices by as much as 20 to 30 percent.

Spectre, unfortunately, won’t be as simple to resolve. Researchers believe it’s a more difficult flaw to exploit, but it affects most microprocessors now in use, and there is no known fix. Some experts believe it could ultimately warrant a complete redesign of hardware, an expensive task.

“We’re talking about an average, $1,000 per computer versus a free software patch,” said Devon Ackerman, associate managing director of the cybersecurity and investigations practice at risk mitigation firm Kroll. “Basically, I am replacing the entire computer with something that is a newer generation, something that is no longer susceptible to this exploit at a hardware level.”

As a result, Spectre may not be solvable until new chips hit the market. Paul Kocher, the president and chief scientist at Cryptography Research, a division of Rambus, said the threat from Spectre is “going to live with us for decades.”

“This will be a festering problem over hardware life cycles. It’s not going to change tomorrow or the day after,” Kocher said. “It’s going to take a while.”

Both the U.S. Department of Homeland Security and Britain’s National Cyber Security Centre are monitoring the situation with both vulnerabilities but say they have not yet seen evidence that the flaws are being exploited.

Original story below.

A hardware bug may make all computers with Intel Corp. chips from the last decade vulnerable to hackers, according to a report released by The Register on Tuesday. Fixing the bug will require patching at the operation system level.

The circumstances of the security exploit have not been publically released due to security concerns, but the bug is related to the way regular apps and programs can access the contents of protected kernel memory and could be present on Intel processors made in the past 10 years. Hackers could potentially exploit security weaknesses to access security keys, passwords and other files in protected kernel memory.

The fix appears to be to implement Kernel Page Table Isolation, making the kernel essentially invisible to running process. Unfortunately, patching the operating system and updating the security could slow down older machines by between 5 and 30 percent, according to the Register.

The Register’s report said that programmers have been working since November on a software patch that addresses the issue. Linux patches and a partial fix for the bug in macOS have been rolled out, and Microsoft is expected to release a fix soon.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • Integration Imagination: The Future of Connected Operations

    Security teams that collaborate cross-functionally and apply imagination and creativity to envision and design their ideal integrated ecosystem will have the biggest upside to corporate security and operational benefits. Read Now

  • Smarter Access Starts with Flexibility

    Today’s workplaces are undergoing a rapid evolution, driven by hybrid work models, emerging smart technologies, and flexible work schedules. To keep pace with growing workplace demands, buildings are becoming more dynamic – capable of adapting to how people move, work, and interact in real-time. Read Now

  • Trends Keeping an Eye on Business Decisions

    Today, AI continues to transform the way data is used to make important business decisions. AI and the cloud together are redefining how video surveillance systems are being used to simulate human intelligence by combining data analysis, prediction, and process automation with minimal human intervention. Many organizations are upgrading their surveillance systems to reap the benefits of technologies like AI and cloud applications. Read Now

  • The Future is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reason. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. But as the number of cameras grows and resolutions push from HD to 4K and beyond, the cloud’s limits are becoming unavoidable. Bandwidth bottlenecks. Latency lags. Rising storage costs. These are not abstract concerns. Read Now

  • Right-Wing Activist Charlie Kirk Dies After Utah Valley University Shooting

    Charlie Kirk, a popular conservative activist and founder of Turning Point USA, died Wednesday after being shot during an on-campus event at Utah Valley University in Orem, Utah Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.