Published: Sat, January 13, 2018
Sci-tech | By Carrie Guzman

Intel warns patches for chip flaws are buggy

Intel warns patches for chip flaws are buggy

For one of the variants of Spectre, which Google says proved to be a lot more problematic, its engineers came up with a technique called "Reptoline", which modifies programs to ensure that execution can not be influenced by an attacker. He concludes the update by remarking that AMD will continue to work with the rest of the technology industry to mitigate Meltdown and Spectre. The company previously said that its chips are only susceptible to the first Spectre variant, but in its latest announcement, it admitted that both Spectre variations are "applicable to AMD processors".

As a bonus, here is a graph from Intel showing the performance hit that its security updates for Meltdown and Spectre will bring to various Intel processors.

It was able to do this "without any performance degradation" or slowdown in services like Gmail, it adds.

Things are a little different when it comes to the GPZ Variant 2 vulnerability (Spectre, Branch Target Injection).

To its credit, the company has shared all of its research and solutions publicly, even going so far as open sourcing the Retpoline solution.

Roger Federer begins Australian Open title defence against Aljaz Bedene
On Saturday, she'll face American Irina Falconi in the hope of returning to one of the biggest biggest stages in tennis. Australia's charge will be led by Nick Kyrgios and Ashleigh Barty in the men's and women's tournaments respectively.

The first approach Google's engineers took was to switch off CPU features that rendered chips vulnerable to intrusion.

Both Microsoft and AMD have confirmed that they will be making the Meltdown and Spectre security updates available for Windows devices with AMD chips once again starting next week. However, in testing, Google found that made its services slow and inconsistent.

Eventually, Google took a "moonshot" approach to solving the problem and turned up with Retpoline, a solution that "modifies programs to ensure that execution can not be influenced by an attacker". As Google explained it, there are three variants here. Google says Spectre and Meltdown "represent a new class of attack" and that "they're just a few among the many different types of threats our infrastructure is created to defend against every day". Needless to say, other tech giants will definitely pick up this Retpoline technique and look into it.

Intel notes that performance for "web applications that involve complex JavaScript operations may see a somewhat higher impact (up to 10 percent based on our initial measurements)" while "graphics-intensive [workloads] like gaming or compute-intensive like financial analysis see minimal impact".

Like this: