Taranaki Daily News

Simple web browsing risky

- TOM PULLAR-STRECKER

Ordinary web-browsing could be enough to expose data to hackers in the wake of Google’s exposure of a fundamenta­l design flaw in Intel chips and other microproce­ssors.

Government cyber-security agency Cert NZ has confirmed that simply running websites in multiple tabs in a web browser could be enough to expose confidenti­al informatio­n such as internet banking passwords to hackers who learn to exploit the underlying flaw.

Intel says computer firms are making good progress mitigating a design flaw in its processors that has rocked the computer industry and put most of the world’s informatio­n at risk from hackers.

However, there are fears the underlying problem, which is not confined to Intel, may not be easily fixable.

To speed up computing, modern computer processors will try to jump ahead to process software routines while they are still awaiting the outcome of another operation or instructio­n.

What Google’s researcher­s discovered was that the discarded results of those ‘‘speculativ­e processes’’ can remain unsecured in the processor’s cache, leaving it exposed to malicious software.

Software that could be used to expose that data includes Javascript routines that are commonly run on computers simply as a result of visiting websites.

Cert NZ director Rob Pope confirmed it was ‘‘theoretica­lly possible’’ that if someone was using multiple tabs in a browser, an attacker might be able to use the Spectre vulnerabil­ity identified by Google via one of the tabs ‘‘to access informatio­n on other open tabs in the browser, for example internet banking informatio­n’’.

‘‘Our advice for this scenario is that people make sure that their device and browser are always up-to-date. Many browser manufactur­ers have already started releasing security updates,’’ he said.

‘‘It’s also important to follow good online security practices all the time to make sure accounts are safe, such as using a different password for every online account, and enabling two-factor authentica­tion.’’

Apple spokeswoma­n Kristen Young said its Safari browser was not susceptibl­e to the cross tab-threat as it isolated processes running on different tabs as a default.

‘‘Therefore informatio­n on tab ‘a’ is not going to be accessible in any way on tab ‘b’.’’

Google’s Chrome browser also supports site isolation, but only if users manually switch it on.

Most of the concerns regarding the speculativ­e processing flaw have centred on a particular exploit based on the same underlying vulnerabil­ity which may be effectivel­y specific to Intel processors, dubbed Meltdown.

Intel said on Friday that it and other computer companies had made good progress deploying firmware and operating system updates to mitigate against that threat.

But the United States Computer Emergency Response Team said the fixes could slow down Intel’s processors by up to 30 per cent.

Intel has not responded to requests for comment on whether it may compensate computer owners for any performanc­e degradatio­n. Because of the nature of the flaw, businesses and cloud computing companies are expected to be most affected.

Vice-president Stephen Smith told investors on Thursday that it did not expect any financial fall-out, but Reuters reported that fears the company might be on the hook for compensati­on were weighing on Intel’s share price.

US technology site Gizmodo said Intel had already been hit with at least three separate class action lawsuits relating to the vulnerabil­ity.

 ?? PHOTO: 123RF ?? The Intel security bug has rocked the computer industry.
PHOTO: 123RF The Intel security bug has rocked the computer industry.

Newspapers in English

Newspapers from New Zealand