Slashdot Mirror


Intel Says 'Partitions' in New Chips Will Correct the Design Flaw that Created Spectre and Meltdown (geekwire.com)

Intel said on Thursday it is introducing hardware protections against the Spectre CPU flaw that was discovered last year. From a report: Starting with the Cascade Lake version of its Xeon server processors later this year, Intel will incorporate "protective walls" in its hardware that prevent malicious hackers from using speculative execution techniques to steal private information from the secure part of the processor. These fixes will also ship with the PC version of the Cascade Lake chips, but the tech industry has been much more concerned about the effect of these design flaws on server processors running in data centers and cloud vendors.

The new fixes allow Intel to still benefit from the performance advantages of speculative execution -- in which a processor guesses which upcoming instructions it will need to execute in order to speed things up -- without the security risks. The hardware changes address Variants 2 and 3 of the Spectre and Meltdown issues first disclosed in early January, and software fixes should continue to address Variant 1, Intel said.

7 of 68 comments (clear)

  1. In related news ... by fahrbot-bot · · Score: 5, Funny

    Intel will incorporate "protective walls" in its hardware ...

    Big, beautiful walls and Intel will get AMD to pay for them. :-)

    --
    It must have been something you assimilated. . . .
  2. Failed at that before by DrYak · · Score: 4, Insightful

    Intel has already failed at exactly that before :

    IntelME was supposed to be exactly that: a separated isolated ARC core in the chipset, that was used to handle administrative tasks even if the main x86 CPU was shutdown (IntelAMT - Intel own NIH syndrom "lights out management" vaguely similar to IPMI). Got further repurposed for some trusted security tasks (TPM), got further repurposed for DRM related task, used also for critical steps to bring the hardware up.

    And was the target of attacks and exploits last summer. Attacks that thus work EVEN when the main x86 CPU is turned off (remembre, before the overarching list of roles, it began as an IPMI-like solution). To the point that vendors like DELL started offering new BIOS/UEFI firmware, in which the Intel ME code was stripped to the bare strict minimum for just the "bring hardware up" part.

    But I'm sure *this time around* the walled secure CPU core that Intel promise will be flawless and never exploited~~

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
  3. How about more than protective walls? by ctilsie242 · · Score: 4, Interesting

    AMD has its bugs, but one new feature that they have implemented is RAM encryption. This way, one VM has no way of obtaining content from another VM's RAM space, should a leak be possible. Why not be proactive in dealing with virtualization and keeping stuff separate, perhaps adding some pipeline randomization to foil side channel attacks?

    Intel knows what they are doing. Might as well be ahead of the curve and add some useful security features.

  4. Oh great by DontBeAMoran · · Score: 4, Funny

    Partitions inside Intel CPUs? How often will we have to re-format the damn things?

    --
    #DeleteFacebook
  5. Re:Intel Management Engine by sexconker · · Score: 4, Funny

    You work for Oracle?

  6. Won't fix your 'AMD' problem by Khyber · · Score: 4, Interesting

    While you went about paying a company to diss AMD, I checked CTS' report, found out one of my intel systems uses one of the mentioned vulnerable chipsets, the ASM1142, for its USB 3.1 controller.

    I bet that the PoC exploit would work on the intel platform right out of the box, if the CTS code isn't full of shit.

    Gimme a copy so I can test it out.

    --
    Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
  7. We did this in the mainframe days by davecb · · Score: 4, Interesting

    We called it "mandatory security levels and categories" (eg, Dockmaster.mil), and then reinvented them for minis (eg, Trusted Solaris) and micros (eg, SELinux), and now Intel is doing the category part in hardware, just like Multics. Methinks they're a tiny bit behind the times...

    --
    davecb@spamcop.net