Who’s affected by computer chip security flaw

Technology companies are scrambling to fix serious security flaws affecting computer processors built by Intel and other chipmakers and found in many of the world’s personal computers and smartphones.

Posted: Jan 4, 2018 3:18 PM

Technology companies are scrambling to fix serious security flaws affecting computer processors built by Intel and other chipmakers and found in many of the world’s personal computers and smartphones.

The two hardware bugs discovered can be exploited to allow the memory content of a computer to be leaked. Such a leak could potentially expose stored passwords and other sensitive data, including personal photos, emails and instant messages.

Researchers at Google’s Project Zero and academic institutions including the Graz University of Technology in Austria discovered the problem last year and disclosed it Wednesday.

There’s no evidence that bad actors have yet exploited the bugs, but companies from Microsoft to Mozilla said this week they have worked to patch up vulnerabilities to their operating systems and browsers to protect against one of the bugs. But researchers say the other is harder to fix and “will haunt us for quite some time.”

Here’s a look at what’s affected, what’s being done about it and whether you should worry.

___

INTEL INSIDE

Intel is at the center of the problem because it supplies the processors used in many of the world’s PCs. Researchers say one of the bugs, called Meltdown, affects nearly every processor it’s made since the mid-1990s.

While security flaws are typically limited to a specific company or product, Intel says the problem is “not a bug or a flaw in Intel products” but rather a broader problem affecting processing techniques common to modern computing platforms.

Both the chipmaker and Google, which informed Intel about the vulnerability last year, said they were planning to disclose the issue next week when fixes will be available. Tech companies typically withhold details about security problems until fixes are available so that hackers wouldn’t have a roadmap to exploit the flaws. But in this case, Intel was forced to disclose the problem Wednesday after British technology site The Register reported it, causing Intel’s stock to fall.

Most of the immediate fixes will be limited to the Meltdown bug. The other, Spectre, is harder to fix, but also harder to exploit, making it less of an immediate threat to consumer devices.

___

OTHER CHIPMAKERS

While researchers say the Meltdown bug is limited to Intel processors, they have verified Spectre as a problem for Intel, Advanced Micro Devices and ARM processors. AMD chips are also common in PCs, while ARM chips are found in many smartphones and other internet-connected products, including cars and home appliances.

AMD said there is “near zero risk” to its own processors, either because its chips are designed differently, or security fixes for Microsoft Windows and other operating systems will take care of the problem. ARM Holdings said it’s working with Intel, AMD and operating system vendors to address the problem. The ARM design is also used in Apple’s mobile chips; Apple didn’t immediately respond to inquiries on whether iPhones and other mobile products are affected.

___

WHAT TO DO NEXT?

There are limits to what consumers can do now to protect their computers.

Advice from the U.S Computer Emergency Readiness Team’s was grim. The federal organization says that “fully removing the vulnerability” requires replacing the hardware already embedded in millions of computing devices.

That’s not to say nothing can be done.

Consumers can mitigate the underlying vulnerability by making sure they patch up their operating systems with the latest software upgrades. There are already Meltdown patches for Microsoft’s Windows, Apple’s macOS and Linux. Mozilla says it’s also implementing a short-term mitigation that disables some capabilities of its Firefox browser. Google says Android devices are protected if they have the latest security updates.

“If you download the latest update from Microsoft, Apple, or Linux, then the problem is fixed for you and you don’t have to worry,” security researcher Rob Graham said in a blog post Thursday. “If you aren’t up to date, then there’s a lot of other nasties out there you should probably also be worrying about.”

Graham says fixing the problem will require a major design of processors and operating systems, but that’s not something most consumers will notice.

Terre Haute
Cloudy
43° wxIcon
Hi: 50° Lo: 28°
Feels Like: 37°
Robinson
Cloudy
41° wxIcon
Hi: 47° Lo: 31°
Feels Like: 36°
Indianapolis/Eagle Creek
Cloudy
41° wxIcon
Hi: 47° Lo: 26°
Feels Like: 38°
Paris
Cloudy
40° wxIcon
Hi: 49° Lo: 27°
Feels Like: 35°
Mattoon/Charleston
Cloudy
40° wxIcon
Hi: 48° Lo: 30°
Feels Like: 40°
Terre Haute
Cloudy
43° wxIcon
Hi: 49° Lo: 28°
Feels Like: 37°
Terre Haute
Cloudy
43° wxIcon
Hi: 49° Lo: 27°
Feels Like: 37°
Scattered Showers
WTHI Planner
WTHI Temps
WTHI Radar

Latest Video

Image

MARSHALL RED HILL

Image

BARR REEVE BLOOMFIELD

Image

WASH CATH VIN RIV

Image

NORTH DAVIESS SULLIVAN

Image

MT VERNON POSEY WASHINGTON

Image

DUGGER RIVERTON PARKE

Image

LINTON GBB STATE FINALS

Image

THN LAF JEFF

Image

Overnight: Scattered showers possible. Low: 40°

Image

A Farmer's Perspective

WTHI Events

 

Illinois Coronavirus Cases

(Widget updates once daily at 7 p.m. CT)

Cases: 1181144

Reported Deaths: 22607
CountyCasesDeaths
Cook4722069317
DuPage763981190
Will64655885
Lake59119918
Kane50439711
Winnebago28263436
Madison27835453
St. Clair25283463
McHenry24190263
Champaign18020123
Peoria16848260
Sangamon16072216
McLean14538156
Tazewell13458239
Rock Island13030286
Kankakee12438189
Kendall1098684
LaSalle10746218
Macon9417185
Vermilion8528114
DeKalb8226112
Adams7994114
Williamson6778119
Boone591271
Whiteside5907147
Clinton556389
Coles517090
Grundy508462
Knox5013131
Ogle498773
Jackson459460
Effingham448569
Macoupin434079
Henry431956
Marion4255111
Livingston416475
Franklin413965
Stephenson407875
Monroe405183
Jefferson3969115
Randolph395778
Woodford365260
Morgan357976
Montgomery347367
Lee334243
Logan330453
Christian329466
Bureau329173
Fayette306552
Perry303357
Fulton284044
Iroquois276660
Jersey248946
Douglas242632
McDonough231440
Lawrence228824
Saline228447
Union218436
Shelby213034
Crawford200321
Bond190224
Cass187822
Pike168750
Clark168029
Hancock166729
Wayne166748
Warren166443
Richland163438
Jo Daviess160522
White160125
Washington157823
Ford157045
Carroll156934
Edgar154037
Moultrie148722
Clay142641
Greene137631
Johnson134712
Piatt131814
Wabash129812
De Witt127722
Mercer127632
Mason127541
Massac125832
Cumberland118618
Jasper110517
Menard10348
Marshall83414
Hamilton78315
Schuyler6755
Pulaski6705
Brown6606
Stark53722
Edwards52310
Henderson49814
Calhoun4782
Scott4481
Alexander4478
Gallatin4364
Putnam4133
Hardin34412
Pope2823
Out of IL00
Unassigned02201

Indiana Coronavirus Cases

(Widget updates once daily at 8 p.m. ET)

Cases: 659127

Reported Deaths: 12494
CountyCasesDeaths
Marion903271628
Lake48239872
Allen35663632
Hamilton31929395
St. Joseph29721510
Elkhart25306412
Vanderburgh21173377
Tippecanoe19873199
Johnson16290355
Porter15896268
Hendricks15765300
Clark11885179
Madison11704315
Vigo11538229
Monroe10285159
Delaware9815178
LaPorte9732195
Howard9030195
Kosciusko8529108
Bartholomew7412147
Hancock7392128
Warrick7389147
Floyd7172165
Wayne6616189
Grant6411157
Morgan6054124
Boone605388
Dubois5885111
Dearborn542366
Henry540792
Marshall5406104
Cass539699
Noble508176
Jackson463664
Shelby459390
Lawrence4165111
Gibson401081
Harrison397061
Clinton393753
Montgomery384283
DeKalb384078
Knox355784
Miami355663
Whitley347835
Huntington341276
Steuben337155
Wabash329776
Putnam327359
Ripley325661
Adams321549
Jasper314243
White296151
Jefferson293370
Daviess284696
Fayette270856
Decatur269788
Greene260679
Posey260131
Wells256574
Scott249649
LaGrange240570
Clay239744
Randolph225276
Spencer216630
Jennings214144
Washington209327
Sullivan202639
Fountain200942
Starke186950
Owen181853
Fulton177737
Jay177328
Carroll176118
Perry173035
Orange170750
Rush164322
Vermillion159541
Franklin158835
Tipton145841
Parke138415
Pike127432
Blackford120327
Pulaski106444
Newton96431
Brown94839
Benton91613
Crawford90413
Martin80014
Switzerland7527
Warren75212
Union66910
Ohio52911
Unassigned0429