Version: 2008
  • On mySimon: Bacon Soap

May 16, 2005 10:08 AM PDT

Pentium 4 loophole could let in hackers

  • 9 comments
Intel is acting to calm fears that technology in its Pentium 4 processors will enable hackers to steal passwords by reading "footprints" in the cache.

Hyperthreading, introduced in Intel's Pentium 4, could allow hackers to access secure information, according to Colin Percival, a 23-year-old Ph.D. student from Vancouver, British Columbia. The technology makes software run faster by letting two threads run on the same processor at the same time.

The attack, revealed Friday in a paper delivered at the BSDCan conference in Ottawa, relies on a spy process installed on the server and sharing the L2 cache with an OpenSSL cryptographic process. The spy process observes the time taken for certain cache operations and deduces what the other process is doing (which Percival refers to as "footprints in the cache"), gathering information that could help crack the desired password.

Intel, which was informed of the problem in March, said the risk is very low. It only works on a server that has already been compromised to allow a malicious hacker to install a spy process. If the hacker has already achieved this, there are many easier and quicker ways to steal data, Intel spokesman Howard High said.

The attack could also affect any other processor that shares resources and not just Intel chips or hyperthreading chips, Intel has pointed out. Nevertheless, the Santa Clara, Calif.-based chip giant expects future versions of the Microsoft Windows and Linux operating systems to fix the problem.

Since discovering the flaw in October 2004, Percival has been working with FreeBSD and other operating systems developers to assess the risks, and various responses are posted on his site. Operating systems that do not exploit hyperthreading and keep it disabled, such as SCO's UnixWare, are said to be immune.

Peter Judge of ZDNet UK reported from London.

See more CNET content tagged:
HyperThreading, hacker, Intel Pentium 4, Intel Pentium, Intel

Add a Comment (Log in or register) (9 Comments)
  • prev
  • 1
  • next
What nonsense
by May 17, 2005 12:20 AM PDT
This article illustrates a little knowledge is a dangerous thing! To call this a flaw is to say that every computer using a volatile memory has an inherint flaw. Was someone looking for funding?
Reply to this comment
Spent too much time in academia
by sanenazok May 17, 2005 8:12 AM PDT
In order to exploit this flaw, the hacker must already have full control of a system. If someone has full control of a computer, then why bother reading the CPU cache, if you can just read the keyboard directly?

Oh wait that would not get published, but sadly this did.
View reply
little knowledge
by John Kuzak May 31, 2007 7:08 PM PDT
http://www.analogstereo.com/tape_backup_tandberg.htm
Go and look at this guys website
by May 17, 2005 12:26 AM PDT
You might see an interesting aspect the article does not mention, this guy is developing a cryptography suite. Is this the motivation for coming out with a problem statement that affects all modern computers?
Reply to this comment
(9 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Intel (0.83%) 0.16 19.40
Dow Jones Industrials (1.29%) 132.79 10,450.95
S&P 500 (1.36%) 14.86 1,106.24
NASDAQ (1.40%) 29.97 2,176.01
CNET TECH (1.71%) 26.91 1,604.16
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right