Flaws in Intel, STMicroelectronics chips risk billions of devices
Haswell CPUs are used in the popular Core i3, i5, and i7 family of processors. The second flaw is in STMicroelectronics' TPM. Notably, the STMicroelectronics' vulnerability is in a chip that has received a strong industry-recognized security certification from "Common Criteria" -- a highly acknowledged security stamp of approval based on international specifications designed to ensure technology meets high security standards preferred in industrial and government deployments.The WPI researchers worked with Thomas Eisenbarth, a professor of IT security at the University of Lubeck in Germany, and Nadia Heninger from University of California, San Diego.Once discovered, the flaws were reported to the chipmakers by the WPI researchers, who also have described the flaws in a paper to be presented at the "29th USENIX Security Symposium" in Boston next August. "We provided our analysis tools and results to Intel and STMicroelectronics and both companies worked with us to create a patch or make sure a security patch will be provided for the next generation of these devices," said Moghimi.Moghimi explained that if hackers gained access to the Intel software, they could forge digital signatures, enabling them to alter, delete, or steal information.The research team discovered another flaw in the STMicroelectronics' TPM, which is based on the company's popular ST33 chip. The chipmaker announced earlier this year that more than 1 billion ST33 chips have been sold.
--IANS na/