Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security //

Risk Management

1/26/2018
09:50 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Intel CEO Promises Chips That Fix Spectre & Meltdown Flaws

During Intel's fourth-quarter earnings call, CEO Brian Krzanich promises the company will ship processors that are free of the Spectre and Meltdown flaws later this year.

With nearly the entire IT industry still getting to grips with the Spectre and Meltdown vulnerabilities found in CPUs, Intel's CEO promised that a more permanent silicon fix would arrive later this year.

In a call with analysts to discuss the company's fourth-quarter financial results, Intel Corp. (Nasdaq: INTC) CEO Brian Krzanich said that new chips that correct the Spectre and Meltdown flaws would ship later this year, although he did not give a specific timeframe.

"We're working to incorporate silicon-based changes to future products that will directly address the Spectre and Meltdown threats in hardware. And those products will begin appearing later this year," the CEO stated, according to a transcript of the January 25 call.

While some have argued that these two security flaws have been part of CPU architecture for the past 20 years, a research report published earlier this year highlighted that attackers could use these vulnerabilities to hack into the hardware itself. Specifically, the researchers found that by manipulating pre-executed commands within the chip, which help make data available faster, hackers can gain access to the content of the kernel memory.

This, in turn, can allow the hacker to gain access to encryption keys and other authentication details of whatever system the CPU is running in.

While Intel, which is the world's largest maker of x86 chips, has taken the brunt of the criticism, other chip suppliers, such as Advanced Micro Devices Inc. (NYSE: AMD) and ARM Ltd. (Nasdaq: ARMHY; London: ARM), have also been called on to answer for the Spectre and Meltdown vulnerabilities. (See Congressman Looking for Answers About Spectre & Meltdown.)

Still, Intel has managed to bungle some of the response to the vulnerabilities since early January when the paper first came out. A series of BIOS patches caused additional problems with performance, and the company was forced to withdraw those and start again. (See HPE, Dell EMC Warn Customers Over Spectre, Meltdown Patches.)

After that, Linux founder Linus Torvalds took to a message board earlier this week and slammed Intel's response as "complete and utter garbage." (See Linus Torvalds: Intel's Spectre Patch Is 'Complete & Utter Garbage'.)


The fundamentals of network security are being redefined – don't get left in the dark by a DDoS attack! Join us in Austin from May 14-16 at the fifth annual Big Communications Event. There's still time to register and communications service providers get in free!

While Krzanich did not dwell on Spectre and Meltdown for long during Thursday's call, he did note that the company has allocated significant resources to fixing the problem and has updated its risk assessments to reflect these ongoing problems. "I've assigned some of the very best minds at Intel to work through this and we're making progress," he added.

The good news for Intel is that it produced a solid fourth quarter that sent the company's stock up almost 4% in after-hours trading on Thursday night: However, it's worth noting that the quarter ended before the vulnerabilities were announced.

During the fourth quarter, Intel posted non-GAAP earnings per share of $1.08 and revenue climbed 4% year-over-year to reach $17.1 billion. Analysts were expecting earnings per share of $0.86 and revenue of about $16.34 billion, according to Reuters.

The chipmaker did take a hit on a $5.4 billion charge related to taxes on offshore earnings.

For the year, Intel posted total net income of $9.6 billion and revenue of $62.8 billion.

Related posts:

— Scott Ferguson, Editor, Enterprise Cloud News. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Hacking It as a CISO: Advice for Security Leadership
Kelly Sheridan, Staff Editor, Dark Reading,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-16137
PUBLISHED: 2020-08-12
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of ...
CVE-2020-16138
PUBLISHED: 2020-08-12
** UNSUPPORTED WHEN ASSIGNED ** A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remotely disable the device until it is power cycled. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being ...
CVE-2020-16139
PUBLISHED: 2020-08-12
** UNSUPPORTED WHEN ASSIGNED ** A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE i...
CVE-2020-16186
PUBLISHED: 2020-08-12
A stored Cross-site scripting (XSS) vulnerability in Firco Continuity 6.2.0.0 allows remote unauthenticated attackers to inject arbitrary web script or HTML through the username field of the login page.
CVE-2020-8904
PUBLISHED: 2020-08-12
An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_len value and write to an arbitrary location in the trusted (en...