# Intel chips have security design flaw

**URL:** <https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [January 3, 2018, 8:34pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815 "2018-01-03T20:34:22Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Intergalactic\_Gladiator](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/intergalactic_gladiator/32/112_2.png) [@Intergalactic\_Gladiator](https://boards.straightdope.com/u/Intergalactic_Gladiator)\
**Post date:** [January 3, 2018, 8:34pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/1 "2018-01-03T20:34:22Z")

</div>

There is a massive design flaw found in Intel processors that affects operating systems using Windows, Mac, and Linux. It is also believed that this will affect cell phones as well.

> **[Critical flaws revealed to affect most Intel chips since 1995](https://www.zdnet.com/article/security-flaws-affect-every-intel-chip-since-1995-arm-processors-vulnerable/)**
>
> Most Intel processors and some ARM chips are confirmed to be vulnerable, putting billions of devices at risk of attacks. One of the security researchers said the bugs are "going to haunt us for years."

> **[Massive chip flaw not limited to Intel](https://www.axios.com/2018/01/05/massive-chip-flaw-not-limited-to-intel-1515111022)**
>
> The issue, to be disclosed later today, could affect nearly all types of computing devices.

Evidently, Mac already pushed patches for this and Microsoft will push its patch on Tuesday’s update schedule.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [January 4, 2018, 2:11pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/2 "2018-01-04T14:11:45Z")

</div>

Intel and some others claim it affects many other companies such as AMD. AMD says it doesn’t. Here’s an [article](https://www.theverge.com/2018/1/3/16846840/intel-arm-processor-flaw-chipocalypse-windows-macos-linux) with info about the flaw in AMD and ARM processors. (Deducting two points for using the term “Chipocalypse now”.)

The problem is predictive computing: The chip “guesses” what instructions will be executed next and goes ahead and does them. If the “if” branch turns out to be not taken, then the operation is dumped without effect (in theory).

Note that if the “if” branch not taken involved peeking into an area of memory you’re not supposed to be looking at (hence why that branch wasn’t supposed to be done), then you can squeeze out some info in certain circumstances due to the flaw.

Note that “fixing” the flaw in software (it can’t be fixed with a microcode update), hurts this predictive computing which means it slows down regular processes.

Not good.

Updating the OS for Intel and AMD chips will be needed but people running older OSes (for a loose definition of “older”) will be left out, as usual.

The ARM situation is scarier. A lot of phone/tablet makers don’t provide updates of this type for anything a year or two old, if at all.

Note that this peeking into protected memory doesn’t sound like a full root exploit. But it certainly sounds like something that can be exploited to gain full control now that the details are out in the open.

---

<div class="post-metadata">

**Author:** ![John\_Mace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/john_mace/32/185_2.png) [@John\_Mace](https://boards.straightdope.com/u/John_Mace)\
**Post date:** [January 4, 2018, 2:55pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/3 "2018-01-04T14:55:22Z")

</div>

I watched the stock tank yesterday, and it continues today. Down 4% at this time.

---

<div class="post-metadata">

**Author:** ![rbroome](https://avatars.discourse-cdn.com/v4/letter/r/838e76/32.png) [@rbroome](https://boards.straightdope.com/u/rbroome)\
**Post date:** [January 4, 2018, 3:13pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/4 "2018-01-04T15:13:49Z")

</div>

As I understand it, there are actually two flaws. Both have to do with predictive computing (I think). The initial press conference wasn’t clear on the details.  
One problem can be solved with a software patch-though it comes at a significant performance cost. It causes a security hole for cloud computers as well.

The second flaw simply can’t be fixed according to the people at the press conference. The only way to fix this is buy a new computer with a new CPU-which hasn’t been designed yet. Apparently there was a memory management design decision 20+ years ago that turns out to be a bad idea. Unfortunately all CPU designs in the world chose to this idea to implement in their CPUs.  
As the speaker said-this problem will be with us for decades as all imbedded computers, cell phones, computers, etc that use any CPU designed in the last 20 years will have this vulnerability until replaced.

---

<div class="post-metadata">

**Author:** ![Darren\_Garrison](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/darren_garrison/32/92_2.png) [@Darren\_Garrison](https://boards.straightdope.com/u/Darren_Garrison)\
**Post date:** [January 4, 2018, 3:33pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/5 "2018-01-04T15:33:20Z")

</div>

[Here](https://www.networkworld.com/article/3245766/virtualization/intels-processor-flaw-is-a-virtualization-nightmare.html) is an article saying that AMD isn’t subject to the exploit.

---

<div class="post-metadata">

**Author:** ![Darren\_Garrison](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/darren_garrison/32/92_2.png) [@Darren\_Garrison](https://boards.straightdope.com/u/Darren_Garrison)\
**Post date:** [January 4, 2018, 3:37pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/6 "2018-01-04T15:37:52Z")

</div>

And I see that it is [two exploits](https://www.extremetech.com/computing/261439-spectre-meltdown-new-critical-security-flaws-explored-explained)–one that is Intel specific, one that isn’t.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 4, 2018, 4:19pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/7 "2018-01-04T16:19:51Z")

</div>

Apparently Microsoft decided yesterday to push these patches to its Azure host servers without very much warning - the place where I work has all of its servers hosted in Azure and they went suddenly offline for an hour each today while their VM host went through patching (we’re too cheap for any sort of availability management - if we had that, I guess we’d have been migrated around and would not have noticed.

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [January 4, 2018, 5:10pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/8 "2018-01-04T17:10:39Z")

</div>

The one that affects almost all processors, Spectre, is a _very_ big deal.

---

<div class="post-metadata">

**Author:** ![Darren\_Garrison](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/darren_garrison/32/92_2.png) [@Darren\_Garrison](https://boards.straightdope.com/u/Darren_Garrison)\
**Post date:** [January 4, 2018, 5:43pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/9 "2018-01-04T17:43:41Z")

</div>

> [@iamthewalrus\_3](#):
>
> The one that affects almost all processors, Spectre, is a _very_ big deal.

At least it has [a cute icon](https://www.anandtech.com/show/12214/understanding-meltdown-and-spectre). (How long do spectres live?)

---

<div class="post-metadata">

**Author:** ![Barkis\_is\_Willin](https://avatars.discourse-cdn.com/v4/letter/b/a183cd/32.png) [@Barkis\_is\_Willin](https://boards.straightdope.com/u/Barkis_is_Willin)\
**Post date:** [January 4, 2018, 5:50pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/10 "2018-01-04T17:50:50Z")

</div>

> [@John\_Mace](#):
>
> I watched the stock tank yesterday, and it continues today. Down 4% at this time.

Meanwhile, AMD stock, which I just happened to buy on Tuesday before this news, has climbed over 10%.

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [January 4, 2018, 6:30pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/11 "2018-01-04T18:30:54Z")

</div>

> [@Darren\_Garrison](#):
>
> At least it has [a cute icon](https://www.anandtech.com/show/12214/understanding-meltdown-and-spectre). (How long do spectres live?)

Ouch.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [January 4, 2018, 6:39pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/12 "2018-01-04T18:39:49Z")

</div>

By an amazing coincidence, the CEO of Intel [sold off](https://www.cnbc.com/2018/01/04/intel-ceo-reportedly-sold-shares-after-the-company-already-knew-about-massive-security-flaws.html) a large part of his shares in ~November, keeping just the minimum he as required to hold. Thereby avoiding the hit Intel stock has taken now that the bug is public.

Note that Google people had informed Intel and other affected companies well before that.

Nothing to see here, move along.

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [January 4, 2018, 6:58pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/13 "2018-01-04T18:58:17Z")

</div>

I thought people did time for that sort of thing.

---

<div class="post-metadata">

**Author:** ![Darren\_Garrison](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/darren_garrison/32/92_2.png) [@Darren\_Garrison](https://boards.straightdope.com/u/Darren_Garrison)\
**Post date:** [January 4, 2018, 7:06pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/14 "2018-01-04T19:06:18Z")

</div>

Intel–the computer _Insid_er Trading.

---

<div class="post-metadata">

**Author:** ![TroutMan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troutman/32/6721_2.png) [@TroutMan](https://boards.straightdope.com/u/TroutMan)\
**Post date:** [January 4, 2018, 7:18pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/15 "2018-01-04T19:18:36Z")

</div>

> [@Barkis\_is\_Willin](#):
>
> Meanwhile, AMD stock, which I just happened to buy on Tuesday before this news, has climbed over 10%.

You might want to take the gain. Once it becomes clear that Spectre is the bigger deal and patches won’t work, AMD is likely to suffer too.

Or maybe this is a buying opportunity for both stocks. People are going to need to buy a lot of new processors.

---

<div class="post-metadata">

**Author:** ![TroutMan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troutman/32/6721_2.png) [@TroutMan](https://boards.straightdope.com/u/TroutMan)\
**Post date:** [January 4, 2018, 7:26pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/16 "2018-01-04T19:26:02Z")

</div>

> [@Mangetout](#):
>
> Apparently Microsoft decided yesterday to push these patches to its Azure host servers without very much warning - the place where I work has all of its servers hosted in Azure and they went suddenly offline for an hour each today while their VM host went through patching (we’re too cheap for any sort of availability management - if we had that, I guess we’d have been migrated around and would not have noticed.

They (and the other providers) had a better mitigation plan that didn’t include unannounced updates. But news of the exploit leaked out before the planned announcement next Tuesday, so there was a lot of scrambling yesterday to rush things out.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 4, 2018, 8:08pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/17 "2018-01-04T20:08:47Z")

</div>

> [@TroutMan](#):
>
> They (and the other providers) had a better mitigation plan that didn’t include unannounced updates. But news of the exploit leaked out before the planned announcement next Tuesday, so there was a lot of scrambling yesterday to rush things out.

Yeah - I spent most of the morning explaining to users that what was happening was rather extraordinary, and that yes, some proper notice would have been right and proper, but that we should assume this emergency action was done in order to prevent a greater pain.

I guess it’s especially pertinent for people running server farms and renting virtual machines, because (as I understand it) the exploit leaks data locally to the CPU (so one program can steal data from another, but in a shared virtual server farm, one CPU may be running the virtual machines (or components of them) for more than one organisation.

---

<div class="post-metadata">

**Author:** ![Voyager](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/voyager/32/133_2.png) [@Voyager](https://boards.straightdope.com/u/Voyager)\
**Post date:** [January 4, 2018, 8:55pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/18 "2018-01-04T20:55:58Z")

</div>

[Here is an article from the Register](https://www.theregister.co.uk/2018/01/04/intel_amd_arm_cpu_vulnerability/) which broke the story. It has others on the site.

The fix is not to change the prediction - it is to put the kernel into a separate address space. That does slow down programs which do lots of kernel calls, but shouldn’t affect much of the usual computing like gaming and word processing very much.  
The exploit is most dangerous in the Cloud, since machines are shared. If you manage not to download any code with the exploit on your personal machine you should be okay - and if you do load untrusted code you will be in trouble in a lot of other ways.  
This is for Meltdown - it appears that Spectre, though harder to fix, is also harder to exploit.  
This all started in 1995 when Andy Grove was CEO of Intel, so he clearly wasn’t paranoid enough. When I was there I worked on Itanic (Itanium) which does not have the problem - not that anyone uses it much any more.  
Prediction is done in hardware, not in microcode, so the root cause fix will require a redesign.  
SPARC processors also do not have the bug.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [January 4, 2018, 9:47pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/19 "2018-01-04T21:47:21Z")

</div>

It seems weird to me that they patched Linux out in the open if they wanted to keep a lid on this until next Tuesday. Security issues like that should be patched on a private branch.

---

<div class="post-metadata">

**Author:** ![Rysto](https://avatars.discourse-cdn.com/v4/letter/r/ecccb3/32.png) [@Rysto](https://boards.straightdope.com/u/Rysto)\
**Post date:** [January 4, 2018, 9:58pm UTC](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815/20 "2018-01-04T21:58:45Z")

</div>

> [@BigT](#):
>
> It seems weird to me that they patched Linux out in the open if they wanted to keep a lid on this until next Tuesday. Security issues like that should be patched on a private branch.

It was an enormous fuck-up. I’m not privy to any details but I suspect that the developers involved will not be trusted with future embargoed security flaws. Leaking the issue on the day after Christmas is utterly inexcusable and has apparently caused an awful lot of problems for poor developers on other projects who have suddenly had to work on mitigating the issue over their holiday.

[Next page](https://boards.straightdope.com/t/intel-chips-have-security-design-flaw/805815.md?page=2)
