Pentium 4 loophole could let in hackers

Intel is acting to calm fears that technology in its Pentium 4 processors will allow hackers to steal passwords by reading 'footprints' in the cache.

Hyperthreading, introduced in Intel's Pentium 4, could allow hackers to access secure information, according to Colin Percival, a 23 year old Ph.D student from Vancouver. The technology makes software run faster by letting two threads run on the same processor at the same time. Percival has developed a sophisticated attack based on timing, which exploits the fact that both processes can access the same cache memory.

The attack, revealed on Friday in a paper delivered at the BSDCan conference in Ottawa, relies on a spy process installed on the server, and sharing the L2 cache with an OpenSSL cryptographic process. The spy process observes the time taken for certain cache operations, and deduces what the other process is doing (which Percival refers to as "footprints in the cache"), gathering information that could help crack the desired password.

Intel was informed of the problem in March, and says the risk is very low. It only works on a server that has already been compromised to allow a malicious hacker to install a spy process. If the hacker has already achieved this, there are many easier and quicker ways to steal data, according to Intel spokesman Howard High.

The attack could also affect any other processor that shares resources, and not just Intel chips or hyperthreading chips, the company has pointed out. Nevertheless, the company expects future versions of Windows and Linux to fix the problem.

Since discovering the flaw in October 2004, Percival has been working with FreeBSD and other operating systems developers to judge the dangers, and various responses are posted on his site. Operating systems that do not exploit hyperthreading and keep it disabled, such as SCO's UnixWare, are immune.

ZDNet UK's Peter Judge reported from London. For more coverage from ZDNet UK, click here.

Advertisement

Talkback 1 comments

    This was announced at BSDCan, ...Anonymous -- 19/05/05

    This was announced at BSDCan, not BDSCan...

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured