Yuriy Bulygin delved into the threat that Spectre posed and found new dangers that hackers could exploit
Yuriy Bulygin knows all about computer vulnerabilities. He spent most of his career at Intel Corp. studying security flaws in chips, including several years as the company’s chief threat researcher, until last summer. So you can believe him when he says he’s found something new: His latest research, set to be published on May 17, shows hackers can exploit previously disclosed problems in microprocessors to access a computer’s firmware— microcode that’s stored permanently inside processors and other chips—to get to its most sensitive information. “The firmware has access to basically all the secrets that are on that physical machine,” he says.
The hacking technique Bulygin found exploits the Spectre vulnerabilities, initially unearthed by Google and other researchers and disclosed earlier this year. The tech giant discovered that millions of computers and smartphones could be compromised by Spectre, which takes advantage of glitches in how processors try to predict what data they believe users will need next, and fetch it in advance. Bulygin’s technique goes a step further by enabling hackers to read data from a particular type of firmware called system management mode memory. The code is linked to access rights that control key functions of the machine, including shutting down the central processing unit if the computer gets too hot or letting administrators configure the system. With access to the SMM memory, hackers can get essentially any data they want.
Esta historia es de la edición May 21, 2018 de Bloomberg Businessweek.
Comience su prueba gratuita de Magzter GOLD de 7 días para acceder a miles de historias premium seleccionadas y a más de 9,000 revistas y periódicos.
Ya eres suscriptor ? Conectar
Esta historia es de la edición May 21, 2018 de Bloomberg Businessweek.
Comience su prueba gratuita de Magzter GOLD de 7 días para acceder a miles de historias premium seleccionadas y a más de 9,000 revistas y periódicos.
Ya eres suscriptor? Conectar
Instagram's Founders Say It's Time for a New Social App
The rise of AI and the fall of Twitter could create opportunities for upstarts
Running in Circles
A subscription running shoe program aims to fight footwear waste
What I Learned Working at a Hawaiien Mega-Resort
Nine wild secrets from the staff at Turtle Bay, who have to manage everyone from haughty honeymooners to go-go-dancing golfers.
How Noma Will Blossom In Kyoto
The best restaurant in the world just began its second pop-up in Japan. Here's what's cooking
The Last-Mover Problem
A startup called Sennder is trying to bring an extremely tech-resistant industry into the age of apps
Tick Tock, TikTok
The US thinks the Chinese-owned social media app is a major national security risk. TikTok is running out of ways to avoid a ban
Cleaner Clothing Dye, Made From Bacteria
A UK company produces colors with less water than conventional methods and no toxic chemicals
Pumping Heat in Hamburg
The German port city plans to store hot water underground and bring it up to heat homes in the winter
Sustainability: Calamari's Climate Edge
Squid's ability to flourish in warmer waters makes it fitting for a diet for the changing environment
New Money, New Problems
In Naples, an influx of wealthy is displacing out-of-towners lower-income workers