The Atlanta Journal-Constitution

Intel CEO: Fixes on way for chip security flaws

- By Matt O’Brien

LAS VEGAS — Intel has big plans to steer toward new business in self-driving cars, virtual reality and other cutting-edge technologi­es. But first it has to pull out of a skid caused by a serious security flaw in its processor chips, which undergird many of the world’s smartphone­s and personal computers.

Intel CEO Brian Krzanich opened his keynote talk Monday night at the annual CES gadget show in Las Vegas by addressing the hard-to-fix flaws disclosed by security researcher­s last week. At an event known for its technologi­cal optimism, it was an unusually sober and high-profile reminder of the informatio­n security and privacy dangers lurking beneath many of the tech industry’s geewhiz wonders.

Some researcher­s have argued that the flaws reflect a fundamenta­l hardware defect that can’t be fixed short of a recall. But Intel has pushed back against that idea, arguing that the problems can be “mitigated” by software or firmware upgrades. Companies from Microsoft to Apple have announced efforts to patch the vulnerabil­ities.

And Krzanich promised fixes in the coming week to 90 percent of the processors Intel has made in the past five years, consistent with an earlier statement from the company. He added that updates for the remainder of those recent processors should follow by the end of January. Krzanich did not address the company’s plans for older chips.

To date, he said, Intel has seen no sign that anyone has stolen

data by exploiting the two vulnerabil­ities, known as Meltdown and Spectre.

The problems were disclosed last week by Google’s Project Zero security team and other researcher­s. Krzanich commended the “remarkable” collaborat­ion among tech companies to address what he called an “industrywi­de” problem.

While Meltdown is believed to primarily affect processors built by Intel, Spectre also affects many of the company’s rivals. Flaws affecting the processor chips also endanger the PCs, internet browsers, cloud computing services and other technology that rely on them.

Both bugs could be exploited through what’s known as a side-channel attack that could extract passwords and other sensitive data from the chip’s memory.

Krzanich himself has been in the spotlight over the security issue after it was revealed that he had sold about $39 million in his own Intel stocks and options in late November, before the vulnerabil­ity was publicly known. Intel says it was notified about the bugs in June.

The company didn’t respond to inquiries about the timing of Krzanich’s divestment­s, but a spokeswoma­n said it was unrelated to the security flaws.

During his presentati­on Monday, Krzanich also launched into a flashy and wide-ranging celebratio­n of the way Intel and its partners are harnessing data for futuristic innovation­s, from 3D entertainm­ent partnershi­ps with Paramount Pictures to virtual-reality collaborat­ions with the 2018 Winter Olympics and a new breakthrou­gh in so-called quantum computing.

 ?? ETHAN MILLER / GETTY IMAGES ?? Intel CEO Brian Krzanich opens his keynote talk Monday night at the annual CES gadget show in Las Vegas by addressing hard-to-fix flaws disclosed by security researcher­s last week.
ETHAN MILLER / GETTY IMAGES Intel CEO Brian Krzanich opens his keynote talk Monday night at the annual CES gadget show in Las Vegas by addressing hard-to-fix flaws disclosed by security researcher­s last week.

Newspapers in English

Newspapers from United States