Smith v. Intel Corporation

District Court, N.D. California·Decided August 15, 2024·No. 4:23-cv-05761·Unknown

Opinion

DARQUES SMITH, et al., Case No. 23-cv-05761-HSG

Plaintiffs, ORDER GRANTING DEFENDANT’S MOTION TO DISMISS, v. TERMINATING AS MOOT DEFENDANT’S MOTION TO STAY INTEL CORPORATION, DISCOVERY, AND IMPOSING TEMPORARY DISCOVERY STAY Defendant. Re: Dkt. Nos. 30, 33

Pending before the Court are Defendant’s motions to dismiss and to stay discovery pending resolution of the motion to dismiss. Dkt. Nos. 30, 33. The Court finds these matters appropriate for disposition without oral argument and the deems them submitted. See Civil L.R. 7-1(b). For the reasons discussed below, the Court GRANTS Defendant’s motion to dismiss, TERMINATES AS MOOT Defendant’s motion to stay discovery, and temporarily STAYS DISCOVERY until Plaintiffs allege an actionable claim. On November 11, 2023, Darques Smith, Renee Waltrip, Brian Cameron, Elizabeth Cordova and Michael Worley, on behalf of themselves and all others similarly situated nationwide (“Plaintiffs”), filed a class action complaint against Intel Corporation (“Defendant”). See Dkt. No. 1 (“Compl.”). Plaintiffs – who purchased central processing units (“CPUs”) and computers incorporating CPUs made by Defendant – allege that Defendant knowingly sold CPUs with a security vulnerability. Id. ¶ 1, 5. According to Plaintiffs, Defendant was on notice of a hardware defect that created this security threat, but nevertheless continued to sell CPUs without fixing the the only way to fix a hardware issue of the sort alleged would be to deploy software “patches” that throttled the processing power of the CPUs. At a high level, the security vulnerability that Plaintiffs allege relates to a computer processing technique called “branch prediction.” According to Plaintiffs, branch prediction is a “speculative procedure” developed in the 1990s designed to overcome barriers to speedy computing caused by slow memory retrieval. Id. ¶ 75. Without branch prediction, “a CPU that sequentially executes instructions will encounter a conditional instruction – one dependent on a value stored in memory,” and “must wait until that value is fetched from memory (which is relatively slow to access) to continue execution.” Id. ¶ 76. Branch prediction gets around this time lag by “predict[ing] what a program will likely do when the processor encounters a conditional instruction (i.e., an instruction dependent on some in-memory value).” Id. ¶ 77. A specific technique for implementing branch prediction is called “speculative execution,” which Plaintiffs allege is “an inherent part of a modern CPU’s computation process” on which modern CPU performance depends. Id. ¶ 82. Plaintiffs allege that speculative execution works as follows:

[F]aced with a conditional instruction – i.e., an instruction based on a value that must be retrieved – a CPU guesses what the value will be instead of waiting for its retrieval from memory, and executes code based on that guess. If, when the memory contents are fetched, the guess is incorrect, the CPU discards the “speculative” code. If the guess was right, the CPU has already executed past the conditional instruction (e.g., conditional branch) without waiting, obviating the need to wait for memory or system input/output to continue executing. Id. ¶ 80. In short, speculative execution allows processors to “speculate on future instruction directions and proactively execute instructions along these paths before knowing if the instructions are correct,” and to deliver performance gains when the speculative instruction correctly matches the value ultimately retrieved from the CPU memory. Id. ¶ 84. But the guessed instructions – referred to as “transient instructions” – apparently must be “completely cleared” from the CPU’s short-term memory after execution. Id. ¶ 83. A CPU’s failure to flush transient instructions leaves “side effects” (i.e. lingering data) that can cause fact that the privileged data retrieved from the CPU’s memory to facilitate instruction execution can become accessible to and exploitable by other parts of the computer which should not have that access to that privileged data if retained by the CPU. Id. ¶¶ 90, 95. Plaintiffs allege that Defendant’s hardware design is defective in that “it fails to ensure that side effects of [transient] instructions do not linger in various parts of the CPU accessible to the running program.” Id. ¶ 89. Instead of properly flushing these instructions, Defendant’s CPUs allegedly “cause the CPU’s cache to store memory information previously required by speculatively executed code, meaning that even if the transient code is discarded, some data remains in the CPU’s cache.” Id. ¶ 90. Additionally, Defendant’s CPUs supposedly also use “instruction buffers, where transient code may store information associated with particular instructions. Id. ¶ 91. Plaintiffs allege that Intel’s failure to “ensure that transient code is prevented from making lingering changes to shared CPU resources” makes its CPUs vulnerable to a class of attacks called transient execution attacks. Id. ¶ 92. According to Plaintiffs, the CPUs’ susceptibility to this novel class of attacks was publicly revealed in 2018, after researchers at Google identified vulnerabilities they dubbed “Spectre” and “Meltdown.” Id. ¶ 97. Spectre and Meltdown are ‘“transient execution’ attacks, meaning that they exploit the side effects of speculative code generated during speculative execution like branch prediction.” Id. ¶ 101. Importantly, these vulnerabilities “can be exploited to steal sensitive data present in a computer system’s memory.” Id. ¶ 98. And according to Plaintiffs, Spectre and Meltdown were but two of a “larger class of vulnerabilities” arising from Defendant’s hardware design of its branch prediction and segmentation systems. Id. ¶¶ 109, 115. In response to the discovery of the Spectre and Meltdown attacks, Defendant deployed software updates (or “patches”) to address the security vulnerability supposedly endemic to the hardware. But according to Plaintiffs, Defendant’s mitigation “essentially handicapped the functionality in Intel CPUs used to predict branches, to speculatively execute code, and to execute code out of order.” Id. ¶ 120. Plaintiffs allege that Wired reported in March 2018 that “attempts to disable [the vulnerability] at the software level can have a marked performance cost” – namely, execution attacks, according to Wired, was to “physically replace all the chips, a change which will take at least a full hardware generation to propagate.” Id. ¶ 119. Plaintiffs allege that Intel said it would do just that: in a March 15, 2018 press release, Intel CEO Brian Krzanich allegedly promised “a new hardware design in future chips to finally deal with the Spectre/Meltdown class of vulnerability, including Spectre and Meltdown variants,” and indicated that design would be incorporated into 8th generation chips by late 2018. Id. ¶ 126.1 Plaintiffs allege that “Intel’s 2018 hardware redesign to overcome Spectre and Meltdown vulnerabilities would need to secure its [Advanced Vector Extension] instructions, along with other attack vectors,” and that Intel knew that. Id. ¶¶ 134. As Plaintiffs explain, “[a] vector instruction is a CPU instruction that can perform the same type of operations on multiple data samples in a particularly efficient manner,” and is “central to the performance and function of any high-end CPU.” Id. ¶¶ 131, 132. Plaintiffs allege that in mid-2018, while Defendant was undertaking its reengineering to address the Spectre and Meltdown class of attacks, Defendant became aware of its CPUs’ Advanced Vector Extension (“AVX”) instructions being vulnerable to side-channel attacks of the type exploited for Spectre/Meltdown. Id. ¶ 135. One “hardware enthusiast” developed and reported to Defendant in June 2018 an exploit he called “AVX Clock Spectre,” which, like the original Spectre attack, “exploited side effects left over from a predicted branch of execution.” Id. ¶ 138. Around that time,

Free access — add to your briefcase to read the full text and ask questions with AI

Smith v. Intel Corporation, (N.D. Cal. 2024).

Smith v. Intel Corporation (Smith v. Intel Corporation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Rutman Wine Company v. E. & J. Gallo Winery
829 F.2d 729 (Ninth Circuit, 1987)
United States v. Francisco Tello
9 F.3d 1119 (Fifth Circuit, 1993)
Manzarek v. St. Paul Fire & Marine Insurance
519 F.3d 1025 (Ninth Circuit, 2008)
Clemens v. DaimlerChrysler Corp.
534 F.3d 1017 (Ninth Circuit, 2008)
Kearns v. Ford Motor Co.
567 F.3d 1120 (Ninth Circuit, 2009)
Mendiondo v. Centinela Hospital Medical Center
521 F.3d 1097 (Ninth Circuit, 2008)
In Re Gilead Sciences Securities Litigation
536 F.3d 1049 (Ninth Circuit, 2008)
Birdsong v. Apple, Inc.
590 F.3d 955 (Ninth Circuit, 2009)
Sacramento Regional Transit District v. Grumman Flxible
158 Cal. App. 3d 289 (California Court of Appeal, 1984)
LiMandri v. Judkins
52 Cal. App. 4th 326 (California Court of Appeal, 1997)
Daugherty v. American Honda Motor Co., Inc.
51 Cal. Rptr. 3d 118 (California Court of Appeal, 2006)
Mocek v. Alfa Leisure, Inc.
7 Cal. Rptr. 3d 546 (California Court of Appeal, 2003)
American Suzuki Motor Corp. v. Superior Court
37 Cal. App. 4th 1291 (California Court of Appeal, 1995)
Merrill v. Navegar, Inc.
28 P.3d 116 (California Supreme Court, 2001)
Jimenez v. Superior Court
58 P.3d 450 (California Supreme Court, 2002)
Skye Astiana v. the Hain Celestial Group
783 F.3d 753 (Ninth Circuit, 2015)