3 ms·
In a Dutch article (https://nos.nl/artikel/2284630-nederlanders-vinden-beveiligingslekken-in-intel-chips.html https://nos.nl/artikel/2284630-nederlanders-vinden
by thijser 7y ago
In a Dutch article (https://nos.nl/artikel/2284630-nederlanders-vinden-beveiligingslekken-in-intel-chips.html https://nos.nl/artikel/2284630-nederlanders-vinden-beveiligi...), one of the researchers says "het aantal mensen bij bedrijven als Intel die zich op dit niveau met beveiliging bezighoudt, is echt op de vingers van twee handen te tellen." = There are 10 or fewer people working on security at this level at companies like Intel.
This sounds very hard to believe to me. With the previous attacks there surely are bigger teams working on this kind of stuff?
- baq 7y agohow much more would you expect? 10 people is pushing the two-pizza limit.
- thijser 7y agoPeople don't necessarily need to be in one big team. Lots of things that are important can be worked on by more than 10 people. (Surely Google and Facebook each have more than 10 people working on security). Is there evidence that so few people are working on security at Intel?
- peteradio 7y agoBigger is definitely not better for this kind of stuff at least as far as team sizes.
- api 7y agoThere are probably fewer than 1000 people in the world capable of finding these kinds of vulnerabilities. Sounds about right to have 10 at Intel.
- Twirrim 7y agoThere's other people working on it outside of Intel, too. https://mdsattacks.com/ https://mdsattacks.com/ if you look at the list of people you'll see there's dozens of folk that independently found and reported the same vulnerabilities.