does this mean the embargo is lifted?
Reading privileged memory with a side-channel
71–80 of 639 posts
Re: Reading privileged memory with a side-channel
#72Is this saying that AMD is affected? Is this the same as the Intel bug reported earlier?
Google security blog says it is. > These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running them. https://security.googleblog.com/2018/01/todays-cpu-vulnerabi...
Treating them as a group, ignores the very real differences in effect.
https://googleprojectzero.blogspot.com/2018/01/reading-privi...
Re: Reading privileged memory with a side-channel
#73Can someone with a little more experience this low-level let me know if this is as bad as I think it is? Because this looks real bad: > Reading host memory from a KVM guest
Yeah, it's pretty bad.
Re: Reading privileged memory with a side-channel
#74> We have some ideas on possible mitigations and provided some of those ideas to the processor vendors; however, we believe that the processor vendors are in a much better position than we are to design and evaluate mitigations, and we expect them to be the source of authoritative guidance. Intel: "Recent reports that these exploits are caused by a “bug” or a “flaw” [..] are incorrect." So much for "authoritative gui…
> Arm recognises that the speculation functionality of many modern high-performance processors, despite working as intended, can be used in conjunction with the timing of cache operations to leak some information as described in this blog.
I personally don't agree, but I guess they're trying to avoid needing to issue a recall for over ten years worth of CPUs?
Re: Reading privileged memory with a side-channel
#75"AMD chips are affected by some but not all of the vulnerabilities. AMD said that there is a "near zero risk to AMD processors at this time." British chipmaker ARM told news site Axios prior to this report that some of its processors, including its Cortex-A chips, are affected." - http://www.zdnet.com/article/security-flaws-affect-every-int... * Edit: From https://meltdownattack.com/ Which systems are affected by Mel…
Another good article: https://www.theregister.co.uk/2018/01/02/intel_cpu_design_fl... "AMD processors are not subject to the types of attacks that the kernel page table isolation feature protects against. The AMD microarchitecture does not allow memory references, including speculative references, that access higher privileged data when running in a lesser privileged mode when that access would result in a page fault…
Re: Reading privileged memory with a side-channel
#76Re: Reading privileged memory with a side-channel
#77Has Google the best security team in the world? It seems like Google security is in a complete different league. I cannot imagine how this impacts companies handling fiat money or cryptocurrencies in the cloud like Coinbase in AWS.
Re: Reading privileged memory with a side-channel
#78"Testing also showed that an attack running on one virtual machine was able to access the physical memory of the host machine, and through that, gain read-access to the memory of a different virtual machine on the same host." Holy shit.
Doesn't Google say that they are protected...?
Re: Reading privileged memory with a side-channel
#79Earlier quoted context omitted.
"We reported this issue to Intel, AMD and ARM on 2017-06-01" What!
How much in advance do the intel managers have to register a stock sell?
Re: Reading privileged memory with a side-channel
#80"Testing also showed that an attack running on one virtual machine was able to access the physical memory of the host machine, and through that, gain read-access to the memory of a different virtual machine on the same host." Holy shit.
Main/Big impacts are on the cloud computer. For home computer, standard office use, there is no impact at this point, right?