ISC StormCast for Thursday, January 4th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 January 2018
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, January 4th, 2018 edition of the Sand Center, Storm Center's Stormcast. |
| 0:07.3 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:11.6 | Lots of talk today about security vulnerability in Intel processors. |
| 0:17.2 | This vulnerability apparently affects all recently released Intel processors going back about 10 years. |
| 0:25.6 | Now the issue here is how kernel memory is isolated from regular user processes. |
| 0:33.6 | Now the problem here is that user processes do need to interact with the kernel regularly to, for example, access the network or file systems, and in order to help with that, the kernel's memory space is actually mapped into the process space of these individual user processes. |
| 0:55.4 | But the kernel of course holds a lot of confidential data like encryption keys and |
| 1:00.8 | the like. |
| 1:01.8 | So in order to prevent normal user processes from reading kernel memory, the processor is supposed |
| 1:09.3 | to keep the two apart by switching from user mode |
| 1:12.7 | and to kernel mode whenever it is needed. |
| 1:16.7 | And apparently something is going wrong with this switch in Intel processors. |
| 1:22.9 | There are not a lot of details known yet. |
| 1:24.8 | The details are still under embargo until all the patches have been released. |
| 1:30.3 | But that's sort of the big picture as it's known right now. Now patches are coming out for Windows |
| 1:38.9 | for Linux and other operating systems. The Windows patches should be released next week with Microsoft's |
| 1:46.6 | regular patch Tuesday. Now these patches aren't really patching the actual problem. The |
| 1:53.0 | actual problem in the processor apparently cannot be patched with firmware or software. Instead, |
| 2:00.8 | it would require new hardware. So what's being |
| 2:04.6 | released here is not so much a patch. It's really more a workaround. And what operating |
| 2:09.5 | systems have to do now is they have to separate kernel memory and user space memory again, |
| 2:15.1 | which removes the efficiencies that were gained by actually |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

