The Elite Intel Team Still Fighting Meltdown and Spectre
Source: Wired
LILY HAY NEWMAN SECURITY 01.03.19 12:33 PM
THE ELITE INTEL TEAM STILL FIGHTING MELTDOWN AND SPECTRE
A YEAR AGO today, Intel coordinated with a web of academic and independent researchers to disclose a pair of security vulnerabilities with unprecedented impact. Since then, a core Intel hacking team has worked to help clean up the messby creating attacks of their own.
Known as Spectre and Meltdown, the two original flawsboth related to weaknesses in how processors manage data to maximize efficiencynot only affected generations of products that use chips from leading manufacturers like Intel, AMD, and ARM, but offered no ready fix. The software stopgaps Intel and others did roll out caused a slew of performance issues.
On top of all of this, Meltdown and particularly Spectre revealed fundamental security weaknesses in how chips have been designed for over two decades. Throughout 2018, researchers inside and outside Intel continued to find exploitable weaknesses related to this class of "speculative execution" vulnerabilities. Fixing many of them takes not just software patches, but conceptually rethinking how processors are made.
At the center of these efforts for Intel is STORM, the company's strategic offensive research and mitigation group, a team of hackers from around the world tasked with heading off next-generation security threats. Reacting to speculative execution vulnerabilities in particular has taken extensive collaboration among product development teams, legacy architecture groups, outreach and communications departments to coordinate response, and security-focused research groups at Intel. STORM has been at the heart of the technical side.
-snip-
Read more:
https://www.wired.com/story/intel-meltdown-spectre-storm/