Live data from Hacker News

MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

techcrunch.com

11–20 of 204 posts

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#11
post #3

Sounds like it requires physical access to a device, is that right? At least less of a concern than software only, though still not good.

As the article puts it, it's a breach in “last line” security defences. Specifically, it's a mitigation that applies when you already have code execution. It's nothing for most people to worry about. PACs are a new mitigation that Intel Macs didn't have, so it's not like it puts the M1 in a worse position than what it replaced.

This is a new security feature, which few computers have, so the fact that it does not work obviously has little practical importance. At worst it makes the new computers with this feature only as secure as any old computer.

Nevertheless, the article is very important, because it shows that this supposedly security-improving feature has been implemented in a way that makes it useless (like it has also happened with some Intel security features, e.g. Software Guard Extensions).

Everybody must become aware that this "pointer authentication" feature is currently unreliable, so it must not be used, and the designers of future CPUs must take care to not repeat these mistakes.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#14
post #9

OT, but is anyone here also redirected to " " rel="nofollow">https://guce.advertising.com/collectIdentifiers?sessionId=3_... ", which gets blocked by µBlock Origin? It's a HTTP redirect. This only happens with my IPv6 landline internet connection (german carrier Telekom), via IPv4 mobile internet (T-Mobile) it loads fine. Happens with two different devices, so it shouldn't be a compromised device, Techcrunch TLS cert…

Not on my side, but it wouldn't be the first time some third party advertising server would be serving malware. Malvertising will restrict itself to only some visitors to make sure it's not detected and blocked too quickly. The massive cookie wall I'm met with when opening this site makes it clear that it's probably impossible to determine which third party is responsible this time. You can read the article safely he…

A domain "advertising.com" is basically the definition of malware.

It's Yahoo/Oauth's spyware domain and as the URL suggests it "collects identifiers" presumably takes a browser fingerprint and sets tracking cookies.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#16

OT, but is anyone here also redirected to " " rel="nofollow">https://guce.advertising.com/collectIdentifiers?sessionId=3_... ", which gets blocked by µBlock Origin? It's a HTTP redirect. This only happens with my IPv6 landline internet connection (german carrier Telekom), via IPv4 mobile internet (T-Mobile) it loads fine. Happens with two different devices, so it shouldn't be a compromised device, Techcrunch TLS cert…

This is Techcrunch first-party native. If it can't set a third party tracking and fingerprint cookie, instead it will forcefully HTTP redirect you through that to drop a "first party" cookie.

NB: techcrunch is basically advertising.com (via aol/yahoo/oath/verizon media/whatever else)

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#17
post #3

Sounds like it requires physical access to a device, is that right? At least less of a concern than software only, though still not good.

As the article puts it, it's a breach in “last line” security defences. Specifically, it's a mitigation that applies when you already have code execution. It's nothing for most people to worry about. PACs are a new mitigation that Intel Macs didn't have, so it's not like it puts the M1 in a worse position than what it replaced.

> it's a mitigation that applies when you already have code execution

Sounds like a huge deal if you want to run untrusted code inside a sandbox.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#18
post #12

Hi! Joseph (one of the authors) here. You can read more about our attack here: https://pacmanattack.com

(Will read the paper later) How lawyer-y do you think Bandai Namco will be?

If they are - Joseph and MIT, please stand up to them. The standard for infringement is confusing similarity. Researchers aren't marketing goods and there's no risk of confusion.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#19

OT, but is anyone here also redirected to " " rel="nofollow">https://guce.advertising.com/collectIdentifiers?sessionId=3_... ", which gets blocked by µBlock Origin? It's a HTTP redirect. This only happens with my IPv6 landline internet connection (german carrier Telekom), via IPv4 mobile internet (T-Mobile) it loads fine. Happens with two different devices, so it shouldn't be a compromised device, Techcrunch TLS cert…

I have this errors on techcrunch for years. I don't remember the last time I read something on this site.

Re: MIT researchers uncover ‘unpatchable’ flaw in Apple M1 chips

#20

Earlier quoted context omitted.

As the article puts it, it's a breach in “last line” security defences. Specifically, it's a mitigation that applies when you already have code execution. It's nothing for most people to worry about. PACs are a new mitigation that Intel Macs didn't have, so it's not like it puts the M1 in a worse position than what it replaced.

This is a new security feature, which few computers have, so the fact that it does not work obviously has little practical importance. At worst it makes the new computers with this feature only as secure as any old computer. Nevertheless, the article is very important, because it shows that this supposedly security-improving feature has been implemented in a way that makes it useless (like it has also happened with s…

What are you basing “so it must not be used” on?

I would think it can’t harm, ever.

Post reply on HN