What does this allow the attacker to do? Steal data? The post isnt very clear.
Huh. The very first line seems pretty clear: > If you remove the first word from the string "hello world", what should > the result be? This is the story of how we discovered that the answer > could be your root password! Can you please expand on your question?
Zenbleed
31–40 of 378 posts
Re: Zenbleed
#32What does this allow the attacker to do? Steal data? The post isnt very clear.
>We now know that basic operations like strlen, memcpy and strcmp will use the vector registers - so we can effectively spy on those operations happening anywhere on the system! It doesn’t matter if they’re happening in other virtual machines, sandboxes, containers, processes, whatever!
>This works because the register file is shared by everything on the same physical core. In fact, two hyperthreads even share the same physical register file.
>It turns out that mispredicting on purpose is difficult to optimize! It took a bit of work, but I found a variant that can leak about 30 kb per core, per second.
>This is fast enough to monitor encryption keys and passwords as users login!
Re: Zenbleed
#33What does this allow the attacker to do? Steal data? The post isnt very clear.
Huh. The very first line seems pretty clear: > If you remove the first word from the string "hello world", what should > the result be? This is the story of how we discovered that the answer > could be your root password! Can you please expand on your question?
Re: Zenbleed
#34Re: Zenbleed
#35AMD Ryzen 5000 Series Processors with Radeon Graphics Does this mean Ryzen CPUs without integrated graphics are fine?
No, it's all Zen 2 CPUs, which include both desktop CPUs (with or without integrated graphics, laptop CPUs, and server CPUs. The reason why the product list is so confusing is that AMD reuses architectures across generations. You'd think that all ryzen 5000 series CPUs have the same microarchitecture, but they don't). It's much easier to consult this list instead: https://en.wikipedia.org/wiki/Zen_2#Products
https://en.wikichip.org/wiki/amd/microarchitectures/zen_2#Al...
Both of them are missing the newer 7000-family products with Zen2 like 7520U etc.
https://www.amd.com/en/products/apu/amd-ryzen-5-7520u
Re: Zenbleed
#36> AMD have released an microcode update for affected processors. Your BIOS or Operating System vendor may already have an update available that includes it. Yes, I love flashing BIOS... edit nvm, Microcode can get updated via system updates.
To be fair, flashing the bios isn't nearly as bad on most modern systems. Put the file on a USB drive, plug it in, restart and go into the bios, look for the flashing utility, select the file, done. As long as the machine is on a UPS in case of disaster, everything's accounted for.
Re: Zenbleed
#37Earlier quoted context omitted.
Huh. The very first line seems pretty clear: > If you remove the first word from the string "hello world", what should > the result be? This is the story of how we discovered that the answer > could be your root password! Can you please expand on your question?
does it require physical access to the machine?
Re: Zenbleed
#38Earlier quoted context omitted.
Huh. The very first line seems pretty clear: > If you remove the first word from the string "hello world", what should > the result be? This is the story of how we discovered that the answer > could be your root password! Can you please expand on your question?
does it require physical access to the machine?
Re: Zenbleed
#39Earlier quoted context omitted.
Huh. The very first line seems pretty clear: > If you remove the first word from the string "hello world", what should > the result be? This is the story of how we discovered that the answer > could be your root password! Can you please expand on your question?
does it require physical access to the machine?
Re: Zenbleed
#40The site is getting hugged to death. https://web.archive.org/web/20230724143835/https://lock.cmpx...