NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Huge security flaws revealed — and tech companies can barely keep up

By Craig Timberg, Elizabeth Dwoskin and Hamza Shaban
news.com.au·
6 Jan, 2018 04:40 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Security experts say attacks would be relatively easy to develop and could allow the theft of private information such as passwords, credit card numbers, private corporate data and other information stored in computers or smartphones. Photo / 123RF

Security experts say attacks would be relatively easy to develop and could allow the theft of private information such as passwords, credit card numbers, private corporate data and other information stored in computers or smartphones. Photo / 123RF

Security experts scrambled on Friday to try to reassure computer users worldwide that a newly discovered type of security flaw can be managed — though not eliminated — through the simple act of updating software with patches that technology companies have been frantically developing for months.

But this relatively soothing message comes against a backdrop of alarm within the technology industry, which has been stunned to discover that the microchips powering nearly every computer and smartphone have for years carried fundamental flaws that can be exploited by hackers and yet cannot be entirely fixed.

The flaws, announced this week and dubbed Meltdown and Spectre, flow from designs that allowed computers to operate more quickly and efficiently. Though it's not clear whether hackers have exploited these flaws, security experts say attacks would be relatively easy to develop and could allow the theft of private information such as passwords, credit card numbers, private corporate data and other information stored in computers or smartphones. Such attacks, the experts add, would likely not leave any trace that could be detected.

"This is the most significant security news we've had in the last 10 years," said Avi Rubin, a computer science professor at Johns Hopkins University specializing in health-care security. "Some of the mitigations are going to be extremely expensive. I think this is the real deal."

Though the patches issued in recent days and weeks should largely protect users against Meltdown — which exploits a flaw mainly in Intel microchips — companies have long struggled to successfully distribute such fixes to all of their users. The patches, meanwhile, are likely to cause computers, smartphones and other devices from Apple, Dell and other PC makers to operate more slowly, though it's not clear whether the difference will be noticeable to users.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Experts consider Spectre — which affects AMD, Arm and Intel chips — more difficult for hackers to exploit but also harder to fix through software ­patches.

For both flaws, a total fix will require the redesign, production and distribution of new computer chips — a process that experts say is likely to take many years to complete.

Security experts said it was impossible to know whether hackers had used the two software flaws to steal data, though it's possible given that rumors of the flaws had been circulating for several months within the security community.

Advertisement
Advertise with NZME.

"It gave lots of people time to do things with it," said Jake Williams, president of Rendition InfoSec and a former National Security Agency employee. "I'm not worried about NSA. I'm worried about everybody else."

Current and former U.S. officials also said the NSA did not know about or use Meltdown or Spectre to enable electronic surveillance on targets overseas. The agency often uses computer flaws to break into targeted machines, but it also has a mandate to warn companies about particularly dangerous or widespread flaws so that they can be fixed.

Rob Joyce, White House cybersecurity coordinator, said, "NSA did not know about the flaw, has not exploited it and certainly the U.S. government would never put a major company like Intel in a position of risk like this to try to hold open a vulnerability."

Joyce, who used to run the NSA's elite hacking division, recently made public the rules by which the government decides to disclose or keep secret software and hardware flaws that can be exploited by hackers, including NSA personnel. He said the vulnerabilities equities process, known as VEP, "is very responsible."

Discover more

Business

Global microchip flaw could affect billions of devices

05 Jan 02:50 AM
Business

Apple reveals all iPhones, iPads, Macs at risk of hacking

05 Jan 04:35 PM
Business

Hackers may be already cashing in on tech flaws

07 Jan 03:49 AM
Business

Kiwis warned to update computer software

08 Jan 05:15 AM

The bigger risk may be criminal hackers. Cybersecurity researcher Matt Tait said he first learned about Meltdown last week. With about a day of work, he was able to develop a functioning example of how the vulnerability could work. He said it's impossible to know whether malicious hackers have deployed Meltdown because the flaw creates no record of the intrusion.

"The reality is we don't know," said Tait, a senior cybersecurity fellow at the Robert S. Strauss Center at the University of Texas at Austin. "Now that the vulnerability has been made public, we should expect this being exploited in the wild in the next few days."

It's common for researchers to withhold public disclosure of a security flaw until companies can create patches to protect users. But the delay for Meltdown and Spectre was unusually long because of the difficulty of trying to remedy hardware problems and the complexity of working across affected companies.

"It's been annoying because the kinds of changes that this all causes for system software are really nasty to write and test . . . So there's a lot of reasons why it's not the 'fun' kind of challenge," said Linus Torvalds, creator of the Linux operating system, in an email reply to questions from The Washington Post.

He added, "For most people, get your system updates and not doing stupid things ('don't run random software from people you don't trust') and you're fine."

Of particular concern, how­ever, are the risks to cloud servers, which often carry the information of multiple customers on a single machine, making them potentially vulnerable to attacks such as Meltdown.

Advertisement
Advertise with NZME.

Dozens of large companies have moved volumes of data from company-owned data centers into remote computers that are owned and managed by Amazon.com, Microsoft, Google and other technology companies. Amazon is the largest player in the cloud computing industry. (Amazon's owner, Jeffrey P. Bezos, owns The Washington Post.)

In the last year alone, Costco, Hulu, General Electric, Kohl's and PayPal are among the companies that have signed on with major cloud providers. Google chief executive Sundar Pichai has said growing his company's cloud computing service is among his top priorities.

While companies, particularly banks and health-care institutions, have long expressed concern about letting other companies house their most sensitive data, many have warmed to the idea. Some have said that technology companies are actually better equipped to make major investments in security and in enhancing the performance of data-processing software, but news of major security flaws threatens to make companies reconsider.

Experts say that for ordinary computer and smartphone users, the main priority should be keeping their software updated.

Buying new computers without the hardware flaw is impractical and expensive, even for deep-pocketed­ companies and government agencies.

"The costs alone are insane," said Tony Cole, vice president and global government chief technology officer at FireEye. He estimated that a global overhaul would amount to trillions of dollars in new expenses. "It would be mind-boggling if everyone tried."

Advertisement
Advertise with NZME.

Ellen Nakashima contributed to this report.

Save

    Share this article

Latest from Business

Premium
Tourism

'Nothing was going to stop me': Pioneer who built ski resort from scratch sells up

09 May 07:00 AM
Premium
Shares

Market close: NZ sharemarket rises as gentailers make gains

09 May 06:03 AM
Premium
Media Insider

Noise ban, off-limit interviews: TVNZ's rules as RNZ moves in; Ad agencies take aim at global merger

09 May 05:43 AM

“Not an invisible footprint”: Why technology supply chains need optimising

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
'Nothing was going to stop me': Pioneer who built ski resort from scratch sells up

'Nothing was going to stop me': Pioneer who built ski resort from scratch sells up

09 May 07:00 AM

Peter Foote started building Mt Dobson Ski Area with a $2000 bulldozer.

Premium
Market close: NZ sharemarket rises as gentailers make gains

Market close: NZ sharemarket rises as gentailers make gains

09 May 06:03 AM
Premium
Noise ban, off-limit interviews: TVNZ's rules as RNZ moves in; Ad agencies take aim at global merger

Noise ban, off-limit interviews: TVNZ's rules as RNZ moves in; Ad agencies take aim at global merger

09 May 05:43 AM
Premium
'Very happy': Jim Grenon to join NZME board with Steven Joyce in peace deal that ends bitter battle

'Very happy': Jim Grenon to join NZME board with Steven Joyce in peace deal that ends bitter battle

09 May 05:42 AM
Deposit scheme reduces risk, boosts trust – General Finance
sponsored

Deposit scheme reduces risk, boosts trust – General Finance

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP