Progress Continues on Firmware Updates
newsroom.intel.com
newsroom.intel.com
Turns out the 85% number is quoted from the "Top 30 Targeted High Risk Vulnerabilities" published in 2015[1], which came from Public Safety Canada's "Top 4 Strategies to Mitigate Targeted Cyber Intrusions" also from 2015[2], which came from the Australian Signals Directorate's report "Top four mitigation strategies to protect your ICT system" from 2012[3], which says (emphasis mine):
"At least 85% of the intrusions that ASD responded to in 2011 involved adversaries using unsophisticated techniques that would have been mitigated by implementing the Top 4 mitigation strategies as a package."
A far cry from "as many as 85 percent of all targeted attacks" quoted from Intel in 2018.
[1] - https://www.us-cert.gov/ncas/alerts/TA15-119A
[2] - https://www.publicsafety.gc.ca/cnt/ntnl-scrt/cbr-scrt/tp-str...
[3] - https://www.asd.gov.au/publications/protect/top_4_mitigation...
The microcode updates are also made available to only very few channels and vendors. In turn, vendors are not making the updates available to customers. As an example, SuperMicro didn't release publically an updated BIOS.
So, one month after the end of the embargo, Intel is working very hard to ensure people cannot get properly protected.
I mean Intel is definitely not handling this well, just playing devils advocate here, they are not completely evil or insane actors.
Linus Torvalds says, "They do literally insane things. They do things that do not make sense ... The patches do things that are not sane. WHAT THE F*CK IS GOING ON?"
(not native English-speaker though, so happy to be corrected)
(edit: spelling)
(1. come up with brand name. 2. patent the product. 3. develop the product.)