Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Horrific Security Flaw Affects Decade of Intel Processors
www.popularmechanics.com ^ | 03 January 2018 | By Eric Limer

Posted on 01/03/2018 1:55:39 PM PST by Red Badger

click here to read article


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-111 next last
To: Red Badger; dayglored; Swordmaker

Windows and Mac ping.


61 posted on 01/03/2018 5:46:35 PM PST by upchuck (President Trump is great because he actually runs something other than his mouth!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: w1andsodidwe

You didn’t administer any beatings? They expect that, you know.


62 posted on 01/03/2018 5:51:56 PM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 50 | View Replies]

To: Red Badger

Per this article, AMD and ARM chips are also impacted:

https://www.reuters.com/article/us-cyber-intel/security-flaws-put-virtually-all-phones-computers-at-risk-idUSKBN1ES1BO


63 posted on 01/03/2018 6:05:12 PM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger; dayglored
It looks as if Apple was already on top of this Intel vulnerability:


Apple has already partially implemented fix in macOS for 'KPTI' Intel CPU security flaw



Multiple sources within Apple not authorized to speak on behalf of the company have confirmed to AppleInsider that there are routines in 10.13.2 to secure the flaw that could grant applications access to protected kernel memory data. These measures, coupled with existing programming requirements about kernel memory that Apple implemented over a decade appear to have mitigated most, if not all, of the security concerns associated with the flaw publicized on Tuesday.

Further confirming the fixes, developer Alex Ionescu has further identified the code that fixed the issue, and is calling it the "Double Map."



Our sources, as well as Ionescu, say that there are more changes in the macOS High Sierra 10.13.3 —but both declined comment on what they may be, or what else is required to totally secure users.

AppleInsider is in the midst of comparative speed testing on a 2017 MacBook Pro. Early indications are that there are no notable slowdowns between a system running macOS High Sierra 10.13.1 and 10.13.2.

Mitigations by Linux code-base maintainers are underway, as are changes by Microsoft to protect Windows users. In response to a query, Microsoft told AppleInsider that they had no comment on a timetable of a release to fix the security flaw at this time, but kernel memory handling was altered by the company in Windows 10 beta builds in the end of 2017.

Potentially at risk from the flaw is anything contained in kernel memory, such as passwords, application keys, and file caches. Details surrounding the bug, and how to exploit it, are still under wraps.

Intel is unable to fix the flaw with a firmware update.

Aside from macOS, Microsoft's Windows and Linux are also open to the vulnerability. Beyond personal computers, some believe cloud services like Amazon EC2, Microsoft Azure and Google Compute Engine are impacted by the bug and will need to be updated.

Amazon has alerted its customers to a large security update coming to AWS in February. Microsoft's Azure service has a maintenance period scheduled for Jan. 10.

64 posted on 01/03/2018 6:11:36 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger
Back in the 80’s I had an IBM XT clone that had a ‘Turbo Boost’ button on the front.

I think all it did was turn on a light..................

Leaving the button off slowed your PC to 4.77 MHz. Turning it on let it run at whatever the advertised speed was (16, 20, 33, 66). It was found on 80286, 386, and 486 machines.

Many games timed off of the original 4.77 MHz chip speed on the PC. They would not run at higher speeds. The button gave you backwards compatibility for these games.

65 posted on 01/03/2018 6:14:43 PM PST by IndispensableDestiny
[ Post Reply | Private Reply | To 27 | View Replies]

To: Red Badger

Thank goodness I’m on my AMD FX-8350 as I type ...... yeah, she’s old and she’s not the fastest CPU in the world but she don’t have this steenking vulnerability!!!


66 posted on 01/03/2018 6:14:52 PM PST by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: AFreeBird
Apple uses intel on Macs. But phones and pads don’t.

It turns out that Apple patched for this Intel vulnerability on December 6, 2017. . . so it's not a problem. It's not an issue on Macs now and no slowdown in the operations.

67 posted on 01/03/2018 6:22:22 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 52 | View Replies]

To: Red Badger

4.77 Mhz to 8 Mhz


68 posted on 01/03/2018 6:22:55 PM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 27 | View Replies]

To: Swordmaker
It's not an issue on Macs now and no slowdown in the operations.

Would be interesting to see before & after patch performance benchmarks for Microsoft, Apple and Linux. Any future lawsuits against Intel for this vulnerability are going to depend on/require demonstration of loss of performance.

69 posted on 01/03/2018 6:31:29 PM PST by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 67 | View Replies]

To: Red Badger

Intel has had backdoors forever, as per our “government” requests.


70 posted on 01/03/2018 6:35:30 PM PST by BereanBrain
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Windows has another undocumented “feature”?? Who would have thought........?


71 posted on 01/03/2018 6:40:36 PM PST by HP8753 (Live Free!!!! .............or don't.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Windflier; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ...
Intel CPU Mega-flaw affects Windows, etc. ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Windflier for the ping!!

72 posted on 01/03/2018 6:44:49 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 25 | View Replies]

To: martin_fierro
Per this article, AMD and ARM chips are also impacted:

There are two vulnerabilities only one of which is the Intel vulnerability. The other, called Spectre can effect the AMD and ARM processors, especially mobile devices such as cellular phones and tablets, for it to be exploited required the following:

"In order to exploit the flaw the "attacker gains physical access by manually updating the platform with a malicious firmware image through flash programmer physically connected to the platform’s flash memory."

So it's not really too much of a serious exploit. "Physical access" and "manually updating" the device's firmware. Right. Sure.

73 posted on 01/03/2018 6:58:15 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 63 | View Replies]

To: Swordmaker
> It turns out that Apple patched for this Intel vulnerability on December 6, 2017. . . so it's not a problem. It's not an issue on Macs now and no slowdown in the operations.

Does that apply to all supported versions, or only High Sierra? I.e. Has Apple rolled out fixes for older versions, -or- will older versions get a fix in the future, -or- does this force us all to upgrade?

74 posted on 01/03/2018 7:09:43 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 67 | View Replies]

To: Swordmaker

And it seems, according to the wording, that the “physical” stuff only applies to the AMD and ARM chips.


75 posted on 01/03/2018 7:12:57 PM PST by SgtHooper (If you remember the 60's, YOU WEREN'T THERE!)
[ Post Reply | Private Reply | To 73 | View Replies]

To: Pollard

A similar exploit has been found in AMD processors. https://www.windowscentral.com/all-modern-processors-impacted-new-meltdown-and-spectre-exploits


76 posted on 01/03/2018 7:23:04 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 37 | View Replies]

To: cyberstoic

A similar exploit has been found in AMD processors. https://www.windowscentral.com/all-modern-processors-impacted-new-meltdown-and-spectre-exploits


77 posted on 01/03/2018 7:23:18 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 19 | View Replies]

To: ImJustAnotherOkie

Apple’s is already patched as of 10.13.2 (which has been out a while) and further steps will be taken in 10.13.3, currently in dev beta. 10.13.2 shows no significant speed loss.


78 posted on 01/03/2018 7:24:21 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Swordmaker

I wish I understood all of this tech stuff.

My computer says it has an Intel Core 17????

Just what we need a bunch of broken computers after this fix.


79 posted on 01/03/2018 8:22:39 PM PST by hsmomx3
[ Post Reply | Private Reply | To 73 | View Replies]

To: Red Badger

[[Back in the 80’s I had an IBM XT clone that had a ‘Turbo Boost’ button on the front.

I think all it did was turn on a light..................
]]

Yeah but I’ll bet the light came on really really fast=- turbo fast


80 posted on 01/03/2018 8:26:13 PM PST by Bob434
[ Post Reply | Private Reply | To 27 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-111 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson