Another example: would you say that MD5 is buggy/flawed?
I guess overall I think this is fair to call a "flaw" but not a "bug."
Another example: would you say that MD5 is buggy/flawed?
I guess overall I think this is fair to call a "flaw" but not a "bug."
However, looking at the reference manual for the 80386 [1], and a modern version of their x64 manual [2], they don't actually say it's for security:
Original: "6.1 Why Protection? The purpose of the protection features of the 80386 is to help detect and identify bugs. The 80386 supports sophisticated applications that may consist of hundreds or thousands of program modules..."
Modern: "The IA-32 architecture’s protection mechanism recognizes four privilege levels, numbered from 0 to 3, where a greater number mean less privilege. The reason to use privilege levels is to improve the reliability of operating systems."
So it's more like someone sells you a box with a lock on the front that looks a lot like a safe and all of the individual hinges and pins and whatnot are guaranteed to some degree, but they never actually say it's OK to lock your stuff inside.
[1]https://css.csail.mit.edu/6.858/2013/readings/i386.pdf
[2]https://www.intel.com/content/www/us/en/architecture-and-tec...
Yes I agree, it's not a bug in the sense of a silly mistake that slipped through development and testing. It's a flaw / attack-vector that no-one thought of... until now.