> CPU uses an insecure hash function in the signature validation Do we know what this "insecure hash function" is/was?
$5 says CRC32
AMD: Microcode Signature Verification Vulnerability
51–60 of 107 posts
Re: AMD: Microcode Signature Verification Vulnerability
#52Privileged code can load microcode? Duh, "vulnerability".
Re: AMD: Microcode Signature Verification Vulnerability
#53Re: AMD: Microcode Signature Verification Vulnerability
#54Re: AMD: Microcode Signature Verification Vulnerability
#55"A test payload for Milan and Genoa CPUs that makes the RDRAND instruction return 4"... Turns out kernel RNG belt-and-suspenders was justified?
Life imitates art: https://imgs.xkcd.com/comics/random_number.png
https://web.archive.org/web/20011027002011/http://www.dilber...
Re: AMD: Microcode Signature Verification Vulnerability
#56Re: AMD: Microcode Signature Verification Vulnerability
#57Security implications aside, the ability to load custom microcode onto these chips could have fascinating implications for reverse engineering and understanding them better.
Eg. Throw away all spectre mitigations, find all the hacks to get each instructions timing down, etc.
Re: AMD: Microcode Signature Verification Vulnerability
#58Earlier quoted context omitted.
Intel's theory I believe was that it could become the only source. The argument in favor I think is the same one you are making now: anything that could hack the chip deeply enough to break rdrand is powerful enough to achieve the same goals in another way.
I'm sure Intel loved that idea, given that I don't think RDRAND showed up on AMD chips for 3 years after Intel launched support for it, and that would let them look much better on a number of benchmarks for that duration...
Re: AMD: Microcode Signature Verification Vulnerability
#59> we will not be sharing full details at this time in order to give users time to re-establish trust on their confidential-compute workloads. What a load of shit! Confidence is earned, it does not grow back like a weed you stepped on!
Re: AMD: Microcode Signature Verification Vulnerability
#60As an end user, I wonder how my cloud provider can prove to me that they installed AMD's fix and are not simply running a malicious version of the microcode on their CPU that claims to have the fix.
Don't microcode updates require a restart as well.