Security Flaw In Hyper-Threading !!

Tuesday 17 May 2005 @ 11:32 am

Well, I need to clarify again because this post is quite serious: I AM NOT AGAINST INTEL !!

I swear to GOD, I DID NOT purposely dig out bad news about Intel !! News happens by itself, I can’t create it.

Hyper-Threading

Ok, here is the detail:-

Colin Percival, from FreeBSD Organization, revealed that Hyper-Threading (HT) is suffering from a serious security flaw. This flaw permits local information disclosure, including allowing an unprivileged user to steal an RSA private key being used on the same machine. In other words, Intel Pentium 4, Mobile Pentium 4, Pentium Extreme Edition and Xeon processors are all victims to this flaw.

However he stated single-user systems (i.e., desktop computers) are not affected. Besides, he strongly advised administrators of multi-user systems to take action to disable Hyper-Threading immediately.

He even wrote a 12-page long article, discussing this flaw and related problems.

In fact, he discovered this flaw back in October 2004. Then tested the suspected flaw and got notified by FreeBSD Security Officer Team in December 2004. In February 2005, vendors including Intel and other security teams contacted him. Finally, he made an official public disclosure that a security flaw exists in Hyper-Threading on May 13, 2005.

Quoted:
I don’t hate Intel — in fact, I think Intel makes great CPUs, and I have an Intel processor in every computer I own. (Not that I have anything against AMD; it just happened to work out this way.) But as someone who works in the field of computer security, I don’t play political games: If I find a vulnerability, I’m going to report it and work with vendors to fix it, regardless of what the problem is or who it affects.

[Source]

Same here, I do not hate Intel, Intel helps the economy of Penang and Malaysia to prosper, and I thank them truly. I just came across this article and thought it would be an interesting topic to publish.

Anyone with a solid explanation to this issue please leave your comment(s) here. Feel free to drop an email to Colin Percival too.
I would rather think this breaking news is false at the moment until further confirmation.


Blogsphere: TechnoratiFeedsterBloglines
Bookmark: Del.icio.usSpurlFurlSimpyBlinkDigg
RSS feed for comments on this post








Comments are closed.

Powered by Disqus

Apple iPad & Maxis WiFi Modem Reviews «
Apple iPad & Maxis WiFi Modem Reviews
Nokia N8 Reviews «
Nokia N8 Reviews
Samsung Galaxy S Reviews «
Samsung Galaxy S Reviews
Nokia N900 Reviews «
Nokia N900 Reviews
Nokia N97 Reviews «
Nokia N97 Reviews



.................................

Live Stats

Recent Posts

Favorite Icon



My QR Code A List Blogger