3 ms·
Main reason is cost to secure vs profits to be made. We technically could have more secure chips, but that would delay the regular release cycle of processors
by techjuice 9y ago
Main reason is cost to secure vs profits to be made. We technically could have more secure chips, but that would delay the regular release cycle of processors that businesses, investors and consumers have come accustomed too.
Now if things were secure by default with no option to disable it we would be in a much better place right now security wise (not sure about how easy the use-ability would be though at first) as engineers would have to adapt to programming more securely on the hardware and software level. Though I did find it strange that when you read the Intel documentation everything is not accurate and there is a large amount of illegal opcode [0].
There is a chance that these vulnerabilities were reported internally and externally, never made it past a manager or never reported to the vendor, seen as not exploitable or theoretical by management or higher level engineer until someone else found it and figured out how to exploit it with time.
This is the same case with encryption algorithms that have been implemented on chip, in theory they are hard to brute force, but with time normally a method is created that can reduce this time by using artifacts found in the algorithm or certain symptoms that occur during the process of attempted encryption/decryption that could be a game changer that was not thought of or documented.
[0] https://github.com/xoreaxeaxeax/sandsifter https://github.com/xoreaxeaxeax/sandsifter