Live data from Hacker News

Reading privileged memory with a side-channel

googleprojectzero.blogspot.com

71–80 of 639 posts

Re: Reading privileged memory with a side-channel

#71
post #40

does this mean the embargo is lifted?

> We are posting before an originally coordinated disclosure date of January 9, 2018 because of existing public reports and growing speculation in the press and security research community about the issue, which raises the risk of exploitation.

Re: Reading privileged memory with a side-channel

#72
post #53

Is this saying that AMD is affected? Is this the same as the Intel bug reported earlier?

Google security blog says it is. > These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running them. https://security.googleblog.com/2018/01/todays-cpu-vulnerabi...

That's unclear, to the point of being factually wrong. Variant 2 and Variant 3 POCs only affect Intel, and those are the ones people are most talking about, and at least to me, the most concerning.

Treating them as a group, ignores the very real differences in effect.

https://googleprojectzero.blogspot.com/2018/01/reading-privi...

Re: Reading privileged memory with a side-channel

#73

Can someone with a little more experience this low-level let me know if this is as bad as I think it is? Because this looks real bad: > Reading host memory from a KVM guest

"We wrote a JavaScript program that successfully reads data from the address space of the browser process running it."

Yeah, it's pretty bad.

Re: Reading privileged memory with a side-channel

#74

> We have some ideas on possible mitigations and provided some of those ideas to the processor vendors; however, we believe that the processor vendors are in a much better position than we are to design and evaluate mitigations, and we expect them to be the source of authoritative guidance. Intel: "Recent reports that these exploits are caused by a “bug” or a “flaw” [..] are incorrect." So much for "authoritative gui…

Arm also claims it is working as intended:

> Arm recognises that the speculation functionality of many modern high-performance processors, despite working as intended, can be used in conjunction with the timing of cache operations to leak some information as described in this blog.

I personally don't agree, but I guess they're trying to avoid needing to issue a recall for over ten years worth of CPUs?

Re: Reading privileged memory with a side-channel

#75
post #43
post #13

"AMD chips are affected by some but not all of the vulnerabilities. AMD said that there is a "near zero risk to AMD processors at this time." British chipmaker ARM told news site Axios prior to this report that some of its processors, including its Cortex-A chips, are affected." - http://www.zdnet.com/article/security-flaws-affect-every-int... * Edit: From https://meltdownattack.com/ Which systems are affected by Mel…

Another good article: https://www.theregister.co.uk/2018/01/02/intel_cpu_design_fl... "AMD processors are not subject to the types of attacks that the kernel page table isolation feature protects against. The AMD microarchitecture does not allow memory references, including speculative references, that access higher privileged data when running in a lesser privileged mode when that access would result in a page fault…

Google's post is newer and has more insights, the registry article is now outdated.

Re: Reading privileged memory with a side-channel

#77
post #64

Has Google the best security team in the world? It seems like Google security is in a complete different league. I cannot imagine how this impacts companies handling fiat money or cryptocurrencies in the cloud like Coinbase in AWS.

I don't know how you would evaluate such a thing as "best security team," but Project Zero certainly attracts a high calibre of security expert. If you're into breaking things, why wouldn't you want to break things with other bright people and the support of a massive corporation?

Re: Reading privileged memory with a side-channel

#78

"Testing also showed that an attack running on one virtual machine was able to access the physical memory of the host machine, and through that, gain read-access to the memory of a different virtual machine on the same host." Holy shit.

> The infrastructure that runs Compute Engine and isolates customer workloads from each other is protected against known attacks. This also means that customer VMs are protected against known, infrastructure-based attacks from other malicious VMs.

Doesn't Google say that they are protected...?

Re: Reading privileged memory with a side-channel

#79

Earlier quoted context omitted.

"We reported this issue to Intel, AMD and ARM on 2017-06-01" What!

How much in advance do the intel managers have to register a stock sell?

You mean without getting whomped for insider trading? I don't think they're allowed to do it in advance at all.

Re: Reading privileged memory with a side-channel

#80
post #70

"Testing also showed that an attack running on one virtual machine was able to access the physical memory of the host machine, and through that, gain read-access to the memory of a different virtual machine on the same host." Holy shit.

Main/Big impacts are on the cloud computer. For home computer, standard office use, there is no impact at this point, right?

Chrome is listed as impacted. People use chrome password managers.
Post reply on HN