comscore Daniel Gruss hacked his own computer to discover 'Meltdown' security flaw
News

Daniel Gruss hacked his own computer to discover 'Meltdown' security flaw

Daniel Gruss hacked into his own computer to discover the security flaw and later verified the result with his colleagues

  • Published: January 5, 2018 5:08 PM IST
intel cpu stock image

Meltdown and Spectre, two recently disclosed security flaws, affect chipsets from leading semiconductor manufacturers including Intel, AMD and mobile chip design ARM. These security flaws put devices manufactured nearly 20 years ago at a potential risk where an attacker can gain access to low-level kernel memory that is normally protected from higher programs and user access. Also Read - MediaTek teases another premium chipset manufactured on the 6nm Process

Also Read - macOS Big Sur: How to install macOS Big Sur update on your Mac

Spectre, a security flaw that affects chips made by Intel, AMD and ARM Holdings, was discovered by Google’s Project Zero team and it still remains unknown with researchers suggesting it will be difficult to exploit. Meltdown security flaw, on the other hand, has a wider implications, with the flaw affecting devices using Intel chipsets in particular. The flaw revealed on Monday affects most Intel processors manufactured since 1995. Also Read - Apple to unveil first in-house processor for Macs in November: Report

Meltdown was discovered by 31-year-old information security researcher Daniel Gruss, who is also a post-doctoral fellow at Austria’s Graz Technical University. He says the ability to breach CPU’s kernel memory, which is protected and inaccessible to users, was only theoretically possible. However, Gruss wanted t to check whether it is practically possible and hacked his own computer to discover the critical flaw. He says he didn’t sleep much the night he exposed the security flaw in chip design.

Gruss say he discovered the flaw by unlocking his personal data that is generally secured with the help of kernel memory. “When I saw my private website addresses from Firefox being dumped by the tool I wrote, I was really shocked,” Gruss told Reuters.

Gruss and his colleagues Moritz Lipp and Michael Schwartz worked from their homes on a weekend in early December and messaged each other to verify the result. “We sat for hours in disbelief until we eliminated any possibility that this result was wrong,” said Gruss.

Gruss and his colleagues accidentally discovered a flaw that can be deemed the worst CPU bug ever. Gruss adds that it is not easy to detect whether the flaw has been exploited by any attacker since it does not leave any trace in the log files.

The discovery of Meltdown, first reported by The Register, has been known to key security researchers for nearly six months and both chip manufacturers and software makers scrambled to issue bug fixes and patch the vulnerability with software. The software developers issue a patch further came to light when Linux developers started separating kernel memory from user memory and changed the current state of kernel page-table isolation.

Intel has acknowledged the flaw and has confirmed that it is working with its peers including AMD and ARM and software makers Apple and Microsoft to patch the issue. Microsoft rolled out a security patch on Wednesday that automatically gets downloaded on Windows 10 while Apple has also issued fix with macOS 10.13.2.

Since the fix is basically a mitigating step involving software update for an hardware flaw, reports suggest it will lead to performance slowdown in some devices. Intel denies drop in CPU performance but for the time being most OEMs and software developers are relying on Gruss and his team s finding to defend any attempts to steal critical information by exploiting the Meltdown bug.

For the latest tech news across the world, latest PC and Mobile games, tips & tricks, top-notch gadget reviews of most exciting releases follow BGR India’s Facebook, Twitter, subscribe our YouTube Channel.
  • Published Date: January 5, 2018 5:08 PM IST



new arrivals in india

Vivo V20 Pro
Vivo V20 Pro

29,990

Xiaomi Mi 10T
Xiaomi Mi 10T

35,999

Xiaomi Redmi 9i
Xiaomi Redmi 9i

8,299

Xiaomi Mi 10T Pro
Xiaomi Mi 10T Pro

39,999

Infinix Hot 10
Infinix Hot 10

9,999

Vivo V20 SE
Vivo V20 SE

20,990

Vivo V20
Vivo V20

24,990

Micromax In 1b
Micromax In 1b

6,999

Micromax In Note 1
Micromax In Note 1

10,999

OnePlus 8T
OnePlus 8T

42,999

Samsung Galaxy F41
Samsung Galaxy F41

15,499

Apple iPhone 12 Pro Max
Apple iPhone 12 Pro Max

1,29,900

Apple iPhone 12 Pro
Apple iPhone 12 Pro

1,19,900

Apple iPhone 12 Mini
Apple iPhone 12 Mini

69,900

Apple iPhone 12
Apple iPhone 12

79,900

Poco X3
Poco X3

16,999

Realme Narzo 20A
Realme Narzo 20A

8,499

Realme Narzo 20
Realme Narzo 20

10,499

Realme Narzo 20 Pro
Realme Narzo 20 Pro

14,999

Oppo F17
Oppo F17

17,990

Samsung Galaxy M51
Samsung Galaxy M51

24,999

Poco M2
Poco M2

10,999

Oppo F17 Pro
Oppo F17 Pro

22,990

Realme 7 Pro
Realme 7 Pro

19,999

Realme 7
Realme 7

14,999

Xiaomi Redmi 9A
Xiaomi Redmi 9A

6,799

Vivo Y20
Vivo Y20

12,990

Xiaomi Redmi 9
Xiaomi Redmi 9

8,999

Nokia 5.3
Nokia 5.3

13,999

Motorola Moto G9
Motorola Moto G9

11,499

Realme C15
Realme C15

9,999

Realme C12
Realme C12

8,999

Samsung Galaxy Note 20
Samsung Galaxy Note 20

77,999

Xiaomi Redmi 9 Prime
Xiaomi Redmi 9 Prime

9,999

Oppo Reno4 Pro
Oppo Reno4 Pro

34,990

Samsung Galaxy M01 Core
Samsung Galaxy M01 Core

5,499

Realme 6i
Realme 6i

12,999

Asus Rog Phone 3
Asus Rog Phone 3

49,999

OnePlus Nord
OnePlus Nord

24,999

Infinix Smart 4 Plus
Infinix Smart 4 Plus

7,999

Xiaomi Redmi Note 9
Xiaomi Redmi Note 9

11,999

Samsung Galaxy M01s
Samsung Galaxy M01s

9,999

Vivo X50 Pro 5G
Vivo X50 Pro 5G

49,990

Vivo X50 5G
Vivo X50 5G

34,990

Realme C11
Realme C11

7,499

Poco M2 Pro
Poco M2 Pro

13,999

Realme X3
Realme X3

24,999

Realme X3 SuperZoom
Realme X3 SuperZoom

27,999

Tecno Spark Power 2
Tecno Spark Power 2

9,999

Oppo A12
Oppo A12

9,990

Oppo A52
Oppo A52

16,990

Samsung Galaxy A21s
Samsung Galaxy A21s

15,999

Oppo Find X2
Oppo Find X2

64,990

Motorola One Fusion Plus
Motorola One Fusion Plus

17,499

Samsung Galaxy A31
Samsung Galaxy A31

20,999

Samsung Galaxy M01
Samsung Galaxy M01

8,999

Samsung Galaxy M11
Samsung Galaxy M11

10,999

Infinix Hot 9 Pro
Infinix Hot 9 Pro

9,999

LG Velvet
LG Velvet

Price Not Available

Xiaomi Mi Note 10 Lite
Xiaomi Mi Note 10 Lite

Price Not Available

Apple iPhone SE 2020
Apple iPhone SE 2020

42,500

Honor 30 Pro
Honor 30 Pro

Price Not Available

Honor 30
Honor 30

Price Not Available

OnePlus 8
OnePlus 8

44,999

OnePlus 8 Pro
OnePlus 8 Pro

54,999

Xiaomi Redmi Note 9 Pro
Xiaomi Redmi Note 9 Pro

13,999

Motorola Moto E4
Motorola Moto E4

8,999

Samsung Galaxy On Max
Samsung Galaxy On Max

9,775

nubia N2
nubia N2

15,999

Karbonn K9 Kavach 4G
Karbonn K9 Kavach 4G

5,290

Motorola Moto C Plus
Motorola Moto C Plus

6,999

Best Sellers