News

Researchers Accuse Intel of Attempted Bribery over MDS Flaw

Intel Security Flaws

Earlier this week it was revealed that a whole new slew of security flaws existing with Intel processors was revealed. Now, to date, at least 4 names have cropped up for seeming the same or different flaws. We’ve seen ‘Zombieland’, ‘Fallout’ and even Microsoft’s preferred own branding to it, ‘MDS’ mentioned.

When cybersecurity research firm VU Amsterdam discovered RIDL, however, in a report via TechPowerUp, they are claiming that Intel attempted to ‘bribe’ them into keeping it quiet or, more accurately, not making their findings quite so public.

Was it a Bribe?

Ok, so that is rather a harsh word. It is, after all, well established that various companies will happily pay ‘bounties’ for people who discover security flaws in their hardware or software. We’ve seen in on multiple occasions where ‘white hat’ hackers get rewarded for finding faults and reporting them.

The security team, however, has chosen to disclose that they were essentially offered a $40,000 ” reward. This was on the proviso, however, that they would significantly downplay the importance of the flaw. This was backed up by a further promise of $80,000. The team did not disclose the terms of this 2nd payment. One can, however, presume that it would be upon successful ‘delivery’ of their initial deal.

VU Amsterdam did, however, decide to decline both offers and make the flaw known to the world. A factor that is clearly more than a little uncomfortable for Intel.

What is the Flaw?

After many attempts to try and understand the details, I have largely come to the conclusion that this is a very technical problem. Well beyond the understanding (or wish of) by the normal PC enthusiast. Put simply, however, RiDL (rouge in-flight data load) is an essential security back-door found deep in the processor design. This isn’t just an older-CPU issue either. It is believed to lie in most (even 9th-gen) designs.

Utilising a design flaw in the CPU buffer, it can effectively allow attackers to infiltrate your system. From there, certain commands can be executed to make your system vulnerable. In other words, putting your security, system and data at risk. This, in combination with the other flaws discovered, is a concern though. Particularly since many of them can effectively ‘work’ together for greater potential damage. This is, however, part of the reason why the details and specifics of the flaws are a little scarce at present. Intel wants to try and fix this before making it too well known.

The flaw is confirmed to have only affected Intel processors with AMD (once again) largely escaping exploit clutches. Intel is, however, working on fixing the issue. Albeit the issue of the fix potentially restricting performance is, again, on the agenda. Let’s see what Intel can do to fix this!

What do you think? Are you concerned about this security flaw? – Let us know in the comments!

Mike Sanders

Disqus Comments Loading...

Recent Posts

Electronic Arts Titles Played for Over 11 Billion Hours in 2024

Electronic Arts (EA) announced today that its games were played for over 11 billion hours…

2 days ago

Just 15% of Steam Gaming Time in 2024 Was Spent on New Releases

Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…

2 days ago

STALKER 2 Gets Massive 110GB Patch With 1800+ Fixes

GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…

2 days ago

Intel Unveils Core 200H Processors Based on the Previous Raptor Lake Refresh

Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…

3 days ago

Ubisoft Reportedly Developing a New Quadruple A Game

Ubisoft is not having the best of times, but despite recent flops, the company still…

3 days ago

STALKER 2: Heart of Chornobyl Update 1.1 Fixes 1,800 Issues and Revamps A-Life 2.0

If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…

3 days ago