5 ms·
The creators aren't always aware of the monsters they create. I think Intel was caught with their trousers down - AMD and ARM in many respects too. Hopefully th
by bArray 8y ago
The creators aren't always aware of the monsters they create. I think Intel was caught with their trousers down - AMD and ARM in many respects too. Hopefully this will lead to automated testing procedures for Intel, other processor manufacturers and security researchers.
The reason these flaws were found in the first place were because of security researchers, hopefully they can now make their cases to get large research grants and bring about a more secure future.
On the other hand, if you want to talk about tin-foil hat "CPUs working against users", only look so far as Intel ME and the equivalents on other processors. Closed-source and highly privileged code running all the time inside the CPU - it's not unthinkable that Intel would bend the knee to some state actors, especially if that leads to higher profits (i.e. a tax break or entry into a new market (cough China)). It's enough of a concern that a lot of reverse engineering effort has gone into preventing it from running.
- acdha 8y ago> Hopefully this will lead to automated testing procedures for Intel, other processor manufacturers and security researchers. They have tons of testing already. The problem is that this is the kind of problem which is easy to miss with tests, especially automated ones, because everything worked correctly and no real code would ever have been affected by the side effects.
- bArray 8y agoThis is what I meant and didn't say - it should read: Hopefully this will lead to better automated testing procedures for Intel, other processor manufacturers and security researchers. The emphasis on "better" as there is obviously automated testing in existence already.
- acdha 8y agoI’m sure it will but I wouldn’t underestimate the difficulty of finding significant unintended state changes in something on the order of complexity of a modern CPU.
- adiusmus 8y agoPlenty more security vulnerabilities in Intel ME to be found. It’s now a well known attack surface full of goodies to plunder. I’m sure AMD and ARM have similar excitement in store. This is in addition to what has already been found.