Waterloo Region Record

Vulnerabil­ity exposed in majority of computers

- Michael Oliveira

TORONTO — Technology experts warn a “really, really serious” security vulnerabil­ity could affect the majority of computers made in the last decade, but a fix being rushed to users has a downside: it may slow down your machine.

Tech news website the Register reported a glitch has been identified with Intel processing chips — found in most computers, including Apple’s Macs — that could cause data to become vulnerable to hackers.

While software developers have been covertly working since late last year to address the widespread issue, news of the problem began spreading beyond the developmen­t community late Tuesday. Intel’s stock dropped about four per cent on Wednesday while the company’s main competitor AMD saw its stock surge by more than five per cent.

“This is a really, really serious problem,” said Vlado Keselj, a professor of computer science at Dalhousie University.

“The good news is I think it’s really hard to exploit this vulnerabil­ity. But it could just be a matter of time before someone manages to do that.”

In a statement released Wednesday, Intel attempted to downplay worries about the hardware issue, saying it believes hackers “do not have the potential to corrupt, modify or delete data.” The company also said a performanc­e hit from a future software update “should not be significan­t and will be mitigated over time.”

Many details about the technical issue and possible solutions are still unknown. Intel said it had originally planned to disclose more informatio­n next week, once software updates were ready, but was compelled to release the statement after the issue began making headlines.

An update for the Linux operating system has already been released and has provided some clues to the extent of the problem.

But Keselj noted that care was taken to strip developers’ notes and comments out of the update, which typically give some context around the changes that are found in a new software release.

“These patches are visible, anyone can open them and see what’s changed but developers removed comments. Without knowing exactly what the vulnerabil­ity is, it’s probably hard to exploit it, so it’s happening under the veil of secrecy which is probably good,” Keselj said.

“We don’t want somebody to be able to exploit this before updates are made.”

Keselj speculated the average user might not notice a dramatic drop in their computer’s performanc­e and even gamers may not suffer a significan­t slowdown. But businesses that use enterprise software for running database servers could see an appreciabl­e change in performanc­e, which would put pressure on Intel, Keselj said.

Prof. Raphael Khoury of the Université du Quebec a Chicoutimi said it’s not unusual for major software or hardware vulnerabil­ities to go undetected for a long time, but it’s good Intel is releasing its fix before damage could be done.

“Maybe the initial patch will have a substantia­l slowdown and then in the coming weeks they can take their time to produce a better fix,” Khoury said.

“It’s better to initially suffer through this slowdown, at least we’re secure.”

 ?? BEN MARGOT, THE ASSOCIATED PRESS ?? Intel says it’s working to patch a security vulnerabil­ity in its products but says the average computer user won’t experience significan­t slowdowns as the problem is fixed.
BEN MARGOT, THE ASSOCIATED PRESS Intel says it’s working to patch a security vulnerabil­ity in its products but says the average computer user won’t experience significan­t slowdowns as the problem is fixed.

Newspapers in English

Newspapers from Canada