Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

10/12/2018
09:35 AM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

Intel's 9th Gen Processors Offer Protections Against Spectre & Meltdown

While talking up its 9th Gen processors this week, Intel offer some subtle hints about plans to protect its CPUs against the Spectre and Meltdown vulnerabilities that have plague x86 processors.

When the Spectre and Meltdown class of vulnerabilities in x86 processors became widely known in March of 2018, the then-CEO of Intel, Brian Krzanich, told the world that its upcoming CPUs would have hardware partitioning enabled for protection.

At this week's Fall Desktop Event, Intel announced just what it was that the company was going to do.

One of the processors Intel talked about was the new Core i9-9900K that offers eight cores and 16 threads. It is clocked at base frequency of 3.6GHz, which can be boosted up to 5GHz.

Intel additionally announced the 9th Gen Core i5 and Core i7 models. The i7-9700K has eight cores and eight threads, and base 3.6GHz clock speed, which can be boosted to 4.9GHz, while the i5-9600K has six cores and six threads at a base 3.7GHz speed -- which can be boosted up to 4.6GHz.

(Source: Intel)\r\n
(Source: Intel)\r\n

All are based on Intel's existing 14nm process, which has been in use since the Broadwell chips of 2014. All these processors are expected to be released in November.

However, with Intel delaying the truly next-gen 10nm Cannon Lake chips until 2019, this is the hardware approach that will be used until those chips emerge.

Buried in all these announcements and speed calculations, Intel offered some guidance on one section on one slide about what the company will do to minimize the Spectre and Meltdown vulnerabilities as far as CPU hardware solutions go.

That one slide, according to Bleeping Computer, notes:

The new desktop processors include protections for the security vulnerabilities commonly referred to as "Spectre," "Meltdown" and "L1TF." These protections include a combination of the hardware design changes we announced earlier this year as well as software and microcode updates.

Other security points include:

  • Speculative side channel variant Spectre V2 (Branch Target Injection) = Microcode + Software
  • Speculative side channel variant Meltdown V3 (Rogue Data Cache Load) = Hardware
  • Speculative side channel variant Meltdown V3a (Rogue System Register Read) = Microcode
  • Speculative side channel variant V4 (Speculative Store Bypass) = Microcode + Software
  • Speculative side channel variant L1 Terminal Fault = Hardware

It seems that Intel has designed hardware protection for the L1 Terminal Fault and Meltdown V3 -- but not the V3a variation.

This splitting of hardware and software (in microcode) fixes did not impress some users on a forum.

"They're still having to use software. Software = slowdown. Not a 100% hardware fix. I bet there is zero change in the massive performance hit NVMe and Optane take," one observer wrote in a forum. "The thing is there will now be no way to test a before/after as the new BIOSs are required just to run the new CPUs."

"It would take clocking a 9600K exactly like an 8700K with an unfixed BIOS and comparing…," the post added.

The specifics of what exactly is being done in the chips that were announced has not yet been released by Intel. Until it is, users fear that any Intel solution in microcode will also cause a significant performance hit.

Only when the chips have been released to the public will comparison testing be possible.

Related posts:

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-16060
PUBLISHED: 2021-10-15
Mitsubishi Electric SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
CVE-2018-16061
PUBLISHED: 2021-10-15
Mitsubishi Electric SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
CVE-2021-27561
PUBLISHED: 2021-10-15
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
CVE-2020-4951
PUBLISHED: 2021-10-15
IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.
CVE-2021-28021
PUBLISHED: 2021-10-15
Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.