Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

10/12/2018
09:35 AM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

Intel's 9th Gen Processors Offer Protections Against Spectre & Meltdown

While talking up its 9th Gen processors this week, Intel offer some subtle hints about plans to protect its CPUs against the Spectre and Meltdown vulnerabilities that have plague x86 processors.

When the Spectre and Meltdown class of vulnerabilities in x86 processors became widely known in March of 2018, the then-CEO of Intel, Brian Krzanich, told the world that its upcoming CPUs would have hardware partitioning enabled for protection.

At this week's Fall Desktop Event, Intel announced just what it was that the company was going to do.

One of the processors Intel talked about was the new Core i9-9900K that offers eight cores and 16 threads. It is clocked at base frequency of 3.6GHz, which can be boosted up to 5GHz.

Intel additionally announced the 9th Gen Core i5 and Core i7 models. The i7-9700K has eight cores and eight threads, and base 3.6GHz clock speed, which can be boosted to 4.9GHz, while the i5-9600K has six cores and six threads at a base 3.7GHz speed -- which can be boosted up to 4.6GHz.

All are based on Intel's existing 14nm process, which has been in use since the Broadwell chips of 2014. All these processors are expected to be released in November.

However, with Intel delaying the truly next-gen 10nm Cannon Lake chips until 2019, this is the hardware approach that will be used until those chips emerge.

Buried in all these announcements and speed calculations, Intel offered some guidance on one section on one slide about what the company will do to minimize the Spectre and Meltdown vulnerabilities as far as CPU hardware solutions go.

That one slide, according to Bleeping Computer, notes:

The new desktop processors include protections for the security vulnerabilities commonly referred to as "Spectre," "Meltdown" and "L1TF." These protections include a combination of the hardware design changes we announced earlier this year as well as software and microcode updates.

Other security points include:

  • Speculative side channel variant Spectre V2 (Branch Target Injection) = Microcode + Software
  • Speculative side channel variant Meltdown V3 (Rogue Data Cache Load) = Hardware
  • Speculative side channel variant Meltdown V3a (Rogue System Register Read) = Microcode
  • Speculative side channel variant V4 (Speculative Store Bypass) = Microcode + Software
  • Speculative side channel variant L1 Terminal Fault = Hardware

It seems that Intel has designed hardware protection for the L1 Terminal Fault and Meltdown V3 -- but not the V3a variation.

This splitting of hardware and software (in microcode) fixes did not impress some users on a forum.

"They're still having to use software. Software = slowdown. Not a 100% hardware fix. I bet there is zero change in the massive performance hit NVMe and Optane take," one observer wrote in a forum. "The thing is there will now be no way to test a before/after as the new BIOSs are required just to run the new CPUs."

"It would take clocking a 9600K exactly like an 8700K with an unfixed BIOS and comparing…," the post added.

The specifics of what exactly is being done in the chips that were announced has not yet been released by Intel. Until it is, users fear that any Intel solution in microcode will also cause a significant performance hit.

Only when the chips have been released to the public will comparison testing be possible.

Related posts:

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3166
PUBLISHED: 2021-01-18
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it were a real update, r...
CVE-2020-29446
PUBLISHED: 2021-01-18
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
CVE-2020-15864
PUBLISHED: 2021-01-17
An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page.
CVE-2021-3113
PUBLISHED: 2021-01-17
Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and ...
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...