Home WebMail Friday, November 1, 2024, 09:24 AM | Calgary | -4.8°C | Regions Advertise Login | Our platform is in maintenance mode. Some URLs may not be available. |
Posted: 2018-01-05T14:17:43Z | Updated: 2018-01-05T14:17:43Z

FRANKFURT/BENGALURU, Jan 5 (Reuters) - Security issues with Intel Corp microchips are only slowing computers slightly, technology companies said, as researchers played down the need for mass hardware replacements to protect millions of devices from hackers.

Google and other security researchers this week disclosed two major chip flaws - one called Meltdown affecting only Intel Corp chips and one called Spectre affecting nearly all computer chips made in the last decade.

That raised the prospect of Intel being on the hook for lawsuits claiming that software patches to fix the issue would slow computers and effectively force consumers to buy new hardware, driving the companys shares down.

But Intel said in a statement after U.S. stock markets closed on Thursday that the performance impact of the recent security updates should not be significant and would be mitigated over time.

It said Apple Inc, Amazon .com Inc, Google and Microsoft Corp had all reported little to no performance impact from security patches.

Intel continues to believe that the performance impact of these updates is highly workload-dependent and, for the average computer user, should not be significant, it said.

The company confirmed that the flaws reported by the researchers could allow hackers to steal information from computers, phones and other devices, but insisted that the issue was not a design flaw.

The chipmaker said it would require users to download a patch and update their operating system to fix the issue.

Microsoft and Google have said they expect few performance problems for most of their cloud computing customers.

Apple said in a separate statement late on Thursday that its tests showed patches would not significantly affect processing speeds.

Our testing with public benchmarks has shown that the changes in the December 2017 updates resulted in no measurable reduction in the performance of macOS and iOS ... or in common Web browsing benchmarks, the California-based firm said.

WHAT EXPERTS SAY

CERT, the cyber security project at Carnegie Mellon University sponsored by the U.S. government, on Friday withdrew its recommendation for the replacement of the central processing units (CPUs) of affected systems.

In the updated guidance, CERT said operating system and some application updates mitigate these attacks.

Daniel Gruss, the 31-year-old information security researcher and post-doctoral fellow at Austrias Graz Technical University who discovered the Meltdown flaw, welcomed Intels white paper on the issue.

This looks much more professional now, Gruss said in comments emailed to Reuters.

On the change in recommendation from CERT, Gruss said, however, that there were no replacements yet that could address the flaws in processors that he and other researchers have found.

All CPUs are affected, also very recent ones, Gruss said. Furthermore, software updates can fix most of the problems, leaving only a small remaining attack surface.

Browser makers Google, Microsoft Corp and Mozilla Corps Firefox confirmed to Reuters on Thursday that the patches they currently have in place do not protect iOS users.

With Safari and virtually all other popular browsers not patched, hundreds of millions of iPhone and iPad users may not have secure means of web browsing until Apple issues its patch.

Your Support Has Never Been More Critical

Other news outlets have retreated behind paywalls. At HuffPost, we believe journalism should be free for everyone.

Would you help us provide essential information to our readers during this critical time? We can't do it without you.

You've supported HuffPost before, and we'll be honest we could use your help again . We view our mission to provide free, fair news as critically important in this crucial moment, and we can't do it without you.

Whether you give once or many more times, we appreciate your contribution to keeping our journalism free for all.

You've supported HuffPost before, and we'll be honest we could use your help again . We view our mission to provide free, fair news as critically important in this crucial moment, and we can't do it without you.

Whether you give just one more time or sign up again to contribute regularly, we appreciate you playing a part in keeping our journalism free for all.

Support HuffPost

Apple said it would release a patch for the Safari web browser on its devices within days. It said that there were no known instances of hackers taking advantage of the flaw to date.

(Writing by Abinaya Vijayaraghavan; Editing by Amrutha Gayathri and Patrick Graham)