. 24/7 Space News .
CHIP TECH
Tech firms rush out patches for 'pervasive' computer flaw
By Rob Lever
Washington (AFP) Jan 5, 2018


Amid a frantic rush to patch a computer security flaw, experts struggled Thursday to determine the impact of a newly discovered vulnerability which could affect billions of devices worldwide.

Cybersecurity researchers called for computer systems to urgently install updates a day after the release of details of the so-called Spectre and Meltdown vulnerabilities affecting the chips powering most modern PCs and many mobile devices.

Researchers on Wednesday published details of the flaw, which unlike many other vulnerabilities stems from the chip itself and how it safeguards private data stored on computers and networks.

The researchers at Google showed how a hacker could exploit the flaw to get passwords, encryption codes and more, even though there have been no reports of any attacks using the vulnerability.

"The full extent of this class of attack is still under investigation and we are working with security researchers and other browser vendors to fully understand the threat and fixes," said Mozilla researcher Luke Wagner in a blog post.

The revelations "attack the foundational modern computer building block capability that enforces protection of the (operating system)," said Steve Grobman, chief technology officer at security firm McAfee.

"Businesses and consumers should update operating systems and apply patches as soon as they become available."

- Intel updates -

Computer chipmaking giant Intel -- the focus of the first reports on the flaw -- said the company and its partners "have made significant progress in deploying updates" to mitigate any threats.

"Intel expects to have issued updates for more than 90 percent of processor products introduced within the past five years," an Intel statement said.

"In addition, many operating system vendors, public cloud service providers, device manufacturers and others have indicated that they have already updated their products and services."

But John Bambenek, a Fidelis security researcher who works with the SANS Internet Storm Center, warned that it may be too soon to know the extent of the problem.

"This bug is probably worth its name and logo considering the pervasive nature of the vulnerability," Bambenek said in a blog post.

"Contrary to some initial reporting, this is NOT just an Intel bug, it affects AMD and ARM processors as well. These could even be used in cloud... environments to leak memory outside the running virtual machine."

In a web page dedicated to the vulnerability, security researchers said Meltdown and Spectre may "get hold of secrets stored in the memory of other running programs. This might include your passwords stored in a password manager or browser, your personal photos, emails, instant messages and even business-critical documents."

The two flaws "work on personal computers, mobile devices, and in the cloud," the researchers said.

"All Mac systems and iOS devices are affected, but there are no known exploits impacting customers at this time," Apple said in a post at an online support page

It advised only getting apps from its online App Store which vets programs for safety, and said it has already released some "mitigations" to protect against the exploit and planned to release a defensive update for Safari on macOS and iOS in the coming days.

Some experts pointed out that the only real "fix" in some cases would be replacing the chip itself, which would be a massive issue for the computing industry.

"The good news is patches are out for almost everything," Bambenek said.

"The bad news is, Spectre, in particular can't be completely mitigated by patching as it seems it will require a hardware fix. The good news is that Spectre is harder to exploit."

The US government's Computer Emergency Response Team initially indicated in a bulletin that only a hardware fix would solve the problem, but then removed that from an update.

"Fully removing the vulnerability requires replacing vulnerable CPU (central processing unit) hardware," said the first bulletin.

rl-gc/ia

INTEL

AMD - ADVANCED MICRO DEVICES

GOOGLE

CHIP TECH
New study visualizes motion of water molecules, promises new wave of electronic devices
Oak Ridge TN (SPX) Jan 03, 2018
A novel approach to studying the viscosity of water has revealed new insights about the behavior of water molecules and may open pathways for liquid-based electronics. A team of researchers led by the Department of Energy's Oak Ridge National Laboratory used a high-resolution inelastic X-ray scattering technique to measure the strong bond involving a hydrogen atom sandwiched between two ox ... read more

Related Links
Computer Chip Architecture, Technology and Manufacture
Nano Technology News From SpaceMart.com


Thanks for being there;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Monthly Supporter
$5+ Billed Monthly


paypal only
SpaceDaily Contributor
$5 Billed Once


credit card or paypal


Comment using your Disqus, Facebook, Google or Twitter login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CHIP TECH
Race for 'smart' hits fever pitch at electronics show

JPL sketches out a trip to the Alpha Centauri system in 2069

The Russian Progress MS-06 cargo freighter undocks and takes a final Pacific dive

NASA picks finalists to explore comet, Saturn's moon

CHIP TECH
China tests new ballistic missiles with hypersonic glide vehicles

One Small Step: Massive Stratolaunch Aircraft Conducts First Taxi Tests

Space Launch System solid rocket booster avionics complete key testing

Japan launches H-IIA carrier rocket with 2 satellites

CHIP TECH
Opportunity takes extensive imagery to decide where to go next

Mars: Not as dry as it seems

Mars' surface water - the truth is out there

Thirsty rocks may contain the missing water of Mars

CHIP TECH
Nation 'leads world' in remote sensing technology

China plans for nuclear-powered interplanetary capacity by 2040

China plans first sea based launch by 2018

China's reusable spacecraft to be launched in 2020

CHIP TECH
Russia restores contact with Angolan satellite

Fourth set of Iridium NEXT satellites arrive in orbit and provide telemetry

SpaceX launches 10 more satellites for Iridium

Green Light for Continued Operations of ESA Science Missions

CHIP TECH
Nature's smallest rainbows, created by peacock spiders, may inspire new optical technology

New lensless camera creates detailed 3-D images without scanning

Accelerated analysis of the stability of complex alloys

Russian scientists suggested a new technology for creating magnet micro-structures

CHIP TECH
NASA Invests in Concept Development for Missions to Comet and Titan

Genes in Space-3 successfully identifies unknown microbes in space

Powerful new tool for looking for life beyond Earth

Ancient fossil microorganisms indicate that life in the universe is common

CHIP TECH
Study explains why Jupiter's jet stream reverses course on a predictable schedule

New Horizons Corrects Its Course in the Kuiper Belt

Does New Horizons' Next Target Have a Moon?

Juno probes the depths of Jupiter's Great Red Spot









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.