Congress wants answers on embargo of Spectre and Meltdown information
Full article670 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Top Republicans on the House Committee on Energy and Commerce want to know why top tech companies sat on the chip flaws for more than six months.
Lawmakers on the House Committee on Energy and Commerce have sent letters to various CEOs at top tech companies asking why information about massive computer chip vulnerabilities was held under embargo for months.
The letters focus on the Spectre and Meltdown bugs, deep-rooted flaws in chips produced by leading computer hardware companies that could allow hackers to access steal sensitive data from machines created as far back as 1995.
Co-authored by panel Chairman Greg Walden, R-Ore., and members Marsha Blackburn, R-Tenn., Bob Latta, R-Ohio, and Gregg Harper, R-Miss., the letters request answers about why the bugs weren’t disclosed when the companies learned about them in June 2017. The committee has jurisdiction over technology issues.
Information about the flaws was supposed to go public in late January, but security researchers tweeted proof-of-concept code before the companies were ready to make announcements. That tweet lead to wider public scrutiny, forcing the companies involved to quickly go public with their work.
“As more products and services become connected, no one company, or even one sector, working in isolation can provide sufficient protection for their products and users,” the letter reads. “Today, effective responses require extensive collaboration not only between individual companies, but also across sectors traditionally siloed from one another. This reality raises serious questions about not just the embargo imposed on information regarding the Meltdown and Spectre vulnerabilities, but on embargos regarding cybersecurity vulnerabilities in general.”
The letters were sent to the following CEOs:
- Tim Cook, Apple
- Jeff Bezos, Amazon
- Lisa Su, AMD
- Simon Segars, ARM Holdings
- Sundar Pichai, Google
- Brian Krzanich, Intel
- Satya Nadella, Microsoft
Lawmakers want the executives to provide more information on why an embargo was needed, if the government’s U.S. Computer Emergency Readiness Team was looped in, and if impacts to critical infrastructure, such as health care or energy companies, were considered prior to the embargo.
“As demonstrated by numerous incidents over the past several years, cybersecurity is a collective responsibility. Further, it is a responsibility that is no longer limited solely to the information technology sector; connected products exist in electric grids, hospitals, manufacturing equipment, and in innumerable other sectors,” the letter reads.
The letters are not the only instance of a lawmaker asking the companies for more information on the flaws. Rep. Jerry McNerney, D-Calif., has requested a briefing with the CEOs of AMD, Arm Holdings and Intel to learn what the companies have done to mitigate the problems caused by the bugs.
You can read the letters below.
[documentcloud url=”http://www.documentcloud.org/documents/4358960-Meltdown-Spectre-Letters.html” width=675 height=500]
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/spectre-meltdown-embargo-house-energy-and-commerce-letters/