Intel reported a combined 39% year-over-year reduction in hardware and firmware vulnerabilities in 2023. The company touts its leadership in product security assurance in the silicon industry, claiming 67% fewer reported platform firmware vulnerabilities than its rival AMD.
The company addressed 353 vulnerabilities in its products last year. Its firmware vulnerabilities decreased by 38%, and hardware vulnerabilities down by 47%, but its software bugs increased by 208% compared to 2022, according to Intel's 2023 Product Security Report.
Intel claims 94% of its vulnerability disclosures are attributed to its product security assurance efforts in 2023 thanks to its growing bug bounty program. It “means that we either found those issues internally, or we incentivize external researchers to submit those to us through our [bug] bounty program,” Jerry Bryant, senior director of security communications and incident response at Intel Corporation, told SDxCentral.
The report showed the company has a record 256 researchers working on its bug bounty program, up from 181 in 2022. Intel also launched Project Circuit Breaker, which aims to build a community of ethical hackers around Intel technologies and train those who may have traditionally focused on software to hunt for bugs on hardware.
Intel reports fewer firmware vulnerabilities than AMD in 2023Intel’s Product Security Report included a part about Intel-AMD competitive vulnerability analysis. It claims AMD reported three times more platform firmware vulnerabilities than Intel last year.
The company defines platform firmware as firmware that maps to silicon and generally ships as part of a CPU/processor platform.
The report also found AMD reported more than 3.5 times as many vulnerabilities in its Chain of Trust/Secure Boot firmware components and features than Intel, and about 2.5 times more vulnerabilities in their confidential computing firmware components and features than Intel. Intel internally found 79% of confidential computing firmware vulnerabilities in 2023, while AMD found 69%.
Bryant said more vulnerabilities don’t necessarily mean the product was less secure, but it’s an indicator of product security assurance practice. For example, Intel began investing in this area in 2006, but AMD did not start publicly disclosing internally found vulnerabilities until May 2022.
“The key takeaway is for Intel, we have a long history of investing in product security assurance ... and we've had more years of maturity and that's basically the bottom line,” he said.
“When it comes to [customer] trust, it's like you don't necessarily want to be dealing with somebody who just getting into the assurance game, so to speak, or playing catch up,” Bryant added.
The importance of transparency in securityIntel commissioned a study by ABI Research1 to evaluate the product assurance practices of leading technology vendors, including AMD, Nvidia, Qualcomm, Intel, and Arm, which named Intel the silicon leader in this area.
“The silicon industry and the respective supply chain for firmware, we all have to raise the bar. This is an area where Intel tries to not just point fingers but lead,” Bryant said.
“Transparency means that we're disclosing vulnerabilities that we found or that were reported to us, and so that [customers] can make an accurate risk assessment when they're planning for their deployments of security mitigations,” he added.
Comments