Home | About Ferret
Australia's Manufacturing and Industrial Directory
Submit Your Listing
Newsletter Sign Up
Search
missing search term

Intel Hyper-Threading Security Flaw Found by Doctoral Student

An apparent security flaw in Hyper-Threading, as currently implemented on Intel Corp.’s Pentium Extreme Edition, Pentium 4, Mobile Pentium 4, and Xeon processors, has been discovered by Colin Percival, a former student working toward his doctor of philosophy in computing at Wadham College at Oxford University.

The flaw, explained by Percival at the BSDCan 2005 conference on Friday in Ottawa, supposedly permits local information disclosure, including allowing an unprivileged user to steal an RSA private key being used on the same machine, according to Percival’s Web site.

Percival strongly advises administrators of multi-user systems to take action to disable Hyper-Threading immediately, whereas single-user systems such as desktop computers are not affected.

To mitigate thoughts to the contrary, the Oxford graduate makes it clear that he does not have any dislike for Intel. “In fact, I think Intel makes great CPUs, and I have an Intel processor in every computer I own,” he says on his Web site.

Further, “As someone who works in the field of computer security, I don’t play political games: If I find a vulnerability, I'm going to report it and work with vendors to fix it, regardless of what the problem is or who it affects,” he added.

Percival first discovered the Hyper-Threading flaw in late October 2004 and worked to develop a proof-of-concept exploit, which was completed and tested in December 2004.

On Dec. 31, 2004, the FreeBSD Security Officer Team was notified of the upcoming security issue.

In February, Percival completed the first draft of a paper on the flaw. Between late February and early March, Percival contacted other security teams and vendors including Intel contacted.

An Intel spokesman confirmed the company had spoken with Percival and definitely takes security threats very seriously.

In its labs, Intel was able to replicate this theoretical timing exploit on all modern architectures, not just Intel-based machines, as Percival did.

As a result, Intel believes all architectures could be susceptible to an attack on Hyper-Threading and it has been working with cryptographic tool and software provider, as corrections for these types of issues are typically corrected with cryptographic software, the spokesman said.

Further, Intel said this type of flaw would not be one launched remotely -- it would have to be done by a malicious user or someone with access to the system and therefore does not rank highly as a typical, real-world vulnerability.

As to whether Intel would hire this talented recent graduate, the Intel spokesman said, “You never know. We do have some cryptographers and security team on staff.”

13/01/2006 12:00 AM
Got a question about this product
Send to a friend
Close
Close
By sending this enquiry you will also be informed of other related opportunities.
* First Name
Surname
Phone
* Your Email
State
Message

Be the first to know about new products, services and developments. Send me Ferret's newsletter.

Get new security code
* does not match
Send Enquiry

Other products like this one

Forklift Hire from Crown Equipment 
Forklift Hire from Crown Equipment
Crown Equipment offers rentals on the complete range of electric forklifts and lift trucks as well as LPG, petrol and diesel trucks.  Crown’s rental fleet exceeds 10,000 trucks and offers the most competitive ...
Enquire Now
Crown Equipment 
ERP Scheduling Software Designed For Manufacturers - M1 From Bowen And Groves 
ERP Scheduling Software Designed For Manufacturers - M1 From Bowen And Groves
Identifying shop floor capacity problems Manufacturers wanting to improve delivery performance. Backwards and Forwards scheduling of individual or multiple jobs, resulting in improved control over your shop floor. ...
Enquire Now
Bowen and Groves 
iICE Master Data Manager v5.0 Launched by Innovit 
iICE Master Data Manager v5.0 Launched by Innovit
Innovit are a leading provider of software solutions for Master Data Management (MDM) and Workflow Management.  Using Innovit solutions, users can manage and synchronise product data across the many information ...
Enquire Now
Innovit Australia 
Embedded Single Board Computers 
Embedded Single Board Computers
Arbor's range of embedded Single Board Computers provide computing platforms using Intel Core Duo®, Core 2 Duo®, Pentium® 4, Pentium® M, Celeron® M, ULV Celeron®, Pentium® III, Pentium® ...
Enquire Now
Arbor Australia 
Electronics and Software Rapid Prototyping and Prototyping Design Services from LX Innovations 
Electronics and Software Rapid Prototyping and Prototyping Design Services from LX Innovations
LX Innovations’ Rapid Electronics and Software Prototyping Design services include PCB Design, Firmware Design and Software Design. Prototyping and Rapid Prototyping Services enables fast and low cost development of your ...
Enquire Now
LX Innovations 

Sections

  • Labs
  • Desktop Computers
  • Software Provider
  • Hire
  • Cpu
Ferret Categories
  • Automation, Process and Control
  • Computers and Software
  • Electronics and Components
  • Environment and Waste Management
  • Food and Beverage Processing
  • Health and Safety
  • Heavy Machinery and Equipment
  • Industrial Consumables
  • Industry Services
  • Materials Handling and Storage
  • Metal Working
  • Mining
  • Packaging, Labelling and Barcoding
  • Test and Measurement
  • Transport & Logistics
Ferret Newsletter

Be the first to know about new products, services and developments. Sign up for Ferret's Daily Product News.

invalid email address
enter your email address
Sign up
 

Home | Add My Business | Submit Free Article | Advertise On Ferret | eNewsletter | News Archive
About Us | Contact Us | Privacy Policy | Terms Of Use | Helpful Links

Copyright © Reed Business Information (2.4.9.002). All material on this site is subject to copyright. All rights reserved.
No part of this material may be reproduced, translated, transmitted, framed or stored in a retrieval system
for public or private use without the written permission of the publisher.