Their study shows how hardware bugs (e.g. the vulnerabilities in Intel processors) and software bugs (e.g. chinks in the Linux or Windows operating system) are not separate problems. Nor can they be solved separately. If anything the opposite is true: hardware and software bugs can combine to expose a system to a whole new range of attacks.
Using a new method called BlindSide, the VU scientists illustrated how hackers can take advantage of these weaknesses. On a computer protected by fully updated security for both software and hardware bugs, they not only used this method to steal all the data but also succeeded in taking over the entire computer.
The VUsec group are no strangers to the Pwnie Awards: this is their fifth victory! Since the Pwnies were founded in 2007, five of the seven awards won by Dutch research groups have gone to the VUsec team. This is their fourth win in the Most Innovative Research category. Other Pwnie categories include Best Server-Side Bug, Best Song and Epic Achievement. This year, the Epic Achievement category was won by Russian opposition leader Alexey Navalny for his phone call to the Russian secret service during which he got an agent to admit to poisoning him.