Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    [mc4wp_form id=3515]
    What's Hot

    Name That Toon: Last Line of Defense

    April 16, 2024

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Facebook Twitter Instagram
    • Privacy Policy
    • Contact Us
    Facebook Twitter Instagram Pinterest Vimeo
    AI Home SecurityAI Home Security
    • Home
    • Home Security
    • Cyber Security
    • Biometric Technology
    Contact
    AI Home SecurityAI Home Security
    Home»Cyber Security»Intel Faces ‘Downfall’ Bug Lawsuit, Seeking $10K per Plaintiff
    Cyber Security

    Intel Faces ‘Downfall’ Bug Lawsuit, Seeking $10K per Plaintiff

    justmattgBy justmattgNovember 11, 2023No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    [ad_1]

    A class-action complaint was filed against Intel this week over its handling of data-leaking bugs in its CPUs.

    In a 112-page filing with the San Jose Division of the United States District Court’s Northern District of California, five representative plaintiffs are alleging that the chip giant knew about faulty instructions which enabled such issues as the recent “Downfall” bug, half a decade before it actually released any kind of fix.

    Determining whether Intel’s negligence constitutes a legal offense may be complicated, though, and it could have broad-reaching ramifications for the technology industry.

    “Never having a flaw is an unrealistic demand,” says John Gallagher, vice president of Viakoo Labs at Viakoo, but “if my data is stolen because a vendor did not apply a patch in a timely manner, I should be able to sue them because of negligence.”

    How Intel Has Handled its Chip Woes

    Downfall was the name given to CVE-2022-40982, a 6.5 medium-rated CVSS-rated information disclosure vulnerability in Intel’s sixth to eleventh-generation CPUs. As a Google researcher revealed at last August’s Black Hat, an attacker could take advantage of a vulnerable instruction the processors use for speculative execution in order to gain access to privileged information from other users in a shared computing environment.

    Though it exists in untold millions, even billions, of computers worldwide (Intel enjoys a majority of the global x86 CPU market), “at an individual level this will not impact most people; it is a relatively complex exploit and is based on a user sharing a computer or cloud environment,” Gallagher notes.

    While the Google researcher first brought Downfall into the limelight in August, the new lawsuit points back far further than that.

    In 2018, a hardware enthusiast published findings demonstrating Downfall-style transient execution vulnerability in Intel CPUs. It was similar to other, more infamous chip bugs — Spectre and Meltdown — and yet another, similar case — NetSpectre — arose around the very same time.

    “However, despite multiple (publicly-known) vulnerability disclosures made to Intel on the subject, Intel did not carefully analyze[sic] possible side-effects in the AVX ISA and engineering hardware solutions to fix them in 2018. Or in 2019, or 2020, or 2021, or 2022. Instead, Intel put profits first, selling defective CPUs for years after it clearly knew them to be defective,” the complaint states.

    In concurrence with the Black Hat revelation this year, Intel released a patch for Downfall. But that patch, the complaint points out, reduces processing speeds to such a degree that “plaintiffs are left with defective CPUs that are either egregiously vulnerable to attacks or must be slowed down beyond recognition to ‘fix’ them.”

    For this, the prosecution is seeking “monetary relief against Intel measured as the greater of (a) actual damages in an amount to be determined at trial or (b) statutory damages in the amount of $10,000 for each plaintiff.”

    Should Intel Be Held Legally Liable?

    The threshold at which poor vulnerability remediation becomes outright negligence is as yet not clearly defined by law.

    “Next year will be 30 years since the Intel ‘floating point error’ hit the headlines and caused Intel to do a recall of its chips (potentially to avoid being found legally liable). Since then the legal liability is not much clearer, as there will always be corner cases and minor flaws which would not rise to the level of legal liability,” Gallagher reflects.

    And whether or not Intel was in the wrong, a complex side-channel bug with limited consequences for most computer owners doesn’t make for the clearest-cut case to reverse this trend. “If this were a widely exploited flaw that could have reasonably been prevented, it might give rise to legal liability, but without that it is just another example of how even with the most rigorous testing and product design, flaws will happen,” he says.

    “If every side-channel attack exploiting a chip-level architectural flaw was brought as a legal case,” he concludes, “the dockets would be overflowing.”

    Bathaee Dunne LLP, representing the prosecution, declined to comment for this story. Dark Reading also reached out to Intel, which has not yet responded as of this publication.

    [ad_2]

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleRussian Hackers Sandworm Cause Power Outage in Ukraine Amidst Missile Strikes
    Next Article Customize Where it Matters, Automate the Rest
    justmattg
    • Website

    Related Posts

    Cyber Security

    Name That Toon: Last Line of Defense

    April 16, 2024
    Cyber Security

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024
    Cyber Security

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Add A Comment

    Leave A Reply Cancel Reply

    Demo
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Cyber Security

    Name That Toon: Last Line of Defense

    justmattgApril 16, 2024

    [ad_1] The enemies are always getting closer, using the same advanced technologies as security pros…

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024

    Muddled Libra Shifts Focus to SaaS and Cloud for Extortion and Data Theft Attacks

    April 16, 2024

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    [mc4wp_form id=3515]
    Demo
    Top Posts

    Name That Toon: Last Line of Defense

    April 16, 2024

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Latest Reviews
    Cyber Security

    Name That Toon: Last Line of Defense

    justmattgApril 16, 2024

    [ad_1] The enemies are always getting closer, using the same advanced technologies as security pros…

    Cyber Security

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    justmattgApril 16, 2024

    [ad_1] Apr 16, 2024NewsroomSupply Chain / Software Security Security researchers have uncovered a “credible” takeover…

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    [mc4wp_form id=3515]
    Demo
    MOST POPULAR

    Name That Toon: Last Line of Defense

    April 16, 2024

    California mountain lion P-22 left mark on wildlife conservation

    January 1, 2023

    Congress Again Writes To Home Minister Amit Shah Over Rahul Gandhi’s Security

    January 1, 2023
    OUR PICKS

    Name That Toon: Last Line of Defense

    April 16, 2024

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    [mc4wp_form id=3515]
    Facebook Twitter Instagram Pinterest
    • Privacy Policy
    • Contact Us
    AI Home Security © 2025 All rights reserved | Designed By ESmartsSolution

    Type above and press Enter to search. Press Esc to cancel.

    ↑