![]() |
|
Zen CPUs Might Be Hit By 4 New Flaws UPDATED - Printable Version +- AlienBabelTech Forums (http://alienbabeltech.com/forum) +-- Forum: Technology (http://alienbabeltech.com/forum/forumdisplay.php?fid=6) +--- Forum: General Hardware (http://alienbabeltech.com/forum/forumdisplay.php?fid=10) +--- Thread: Zen CPUs Might Be Hit By 4 New Flaws UPDATED (/showthread.php?tid=1873) |
Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-13-2018 https://www.techpowerup.com/242328/13-major-vulnerabilities-discovered-in-amd-zen-architecture-including-backdoors Quote:Security researchers with Israel-based CTS-Labs, have discovered a staggering thirteen critical security vulnerabilities affecting AMD "Zen" CPU microarchitecture, which are as damning the three recent "Meltdown" and "Spectre" vulnerabilities that affect various CPU manufacturers at varying degrees (Intel, AMD, and ARM). The thirteen new CVEs are broadly classified into four groups based on the similarity in function of the processor that they exploit: "Ryzenfall," "Masterkey," "Fallout," and "Chimera." RE: Zen CPUs Hit By 4 New Flaws - SteelCrysis - 03-14-2018 http://www.tomshardware.com/news/amd-flaws-ryzenfall-masterkey-fallout-chimera,36656.html Quote:We're digging deeper to find out more information about the vulnerabilities, but given the lack of information, it is best to be cautious. Much like the initial few days of the Spectre/Meltdown vulnerabilities, there is likely to be quite a bit of misinformation circulating in regards to potential performance impacts. Currently the information that CTS-Labs has posted is unverified and is presented without evidence, and the company has several strong disclaimers regarding its "disclosures." We've pasted a partial outtake of the disclaimers from the whitepaper (PDF) below. RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-14-2018 https://www.extremetech.com/computing/265582-everything-surrounding-new-amd-security-allegations-reeks-hit-job Quote:If these security flaws are real, AMD has a lot of work to do to fix them. It absolutely deserves criticism for failing to catch them in the first place, and there is at least one security researcher who has seen the code and believes the matter to be serious. But even if CTS-Labs findings are genuine, it has communicated them in a manner completely at odds with best practices in the security community. Its manner and method of communicating its findings have much more in common with a PR firm hired to do a hit job on a competitor or a company looking to make a financial killing by shorting stock than a reputable security firm interested in establishing a name for itself. Finding 13 major security flaws in a major microprocessor was guaranteed to make the news all on its own. RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-14-2018 Torvalds is unhappy: https://www.techpowerup.com/242340/linus-torvalds-slams-security-researchers-without-taking-names And it looks like the vulnerabilities are real, even if AMD was given only 24 hours before the issue was disclosed: https://www.techpowerup.com/242346/cts-labs-sent-amd-and-other-companies-a-research-package-with-proof-of-concept-code RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-15-2018 http://www.tomshardware.com/news/cts-labs-amd-ryzenfall-ryzen-epyc,36660.html Quote:CTS Labs' CTO, Ilia Luk-Zilberman, has now posted a letter on the AMDflaws site that says much of what he told us. It's a somewhat curious screed in which he expounds on his distaste for the 90-day response window and his views on why it's not helpful. Partly, he said that he thinks alerting everyone at once (that is, consumers, media, and companies) puts public pressure on the companies to fix the vulnerabilities (it certainly does), and that by doing so without disclosing the actual technical details, no one is actually at risk. But that creates obvious problems, such as causing widespread FUD, and it invites backlash upon the security researchers, all of which he alluded to in the letter. The salient passage reads in part:Quote:This model has a huge problem; how can you convince the public you are telling the truth without the technical details. And we have been paying that price of disbelief in the past 24h. The solution we came up with is a third party validation, like the one we did with Dan from trailofbits. In retrospect, we would have done this with 5 third party validators to remove any doubts. A lesson for next time.Altogether, it seems that AMD customers may be justified in worrying about these vulnerabilities. If CTS Labs' description of them is accurate, they are remotely exploitable flaws that could allow attackers to install persistent malware in the deepest recesses of a system. That puts consumers at risk, and it could also undermine businesses' secure networks simply because they rely on Ryzen or EPYC processors. RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-15-2018 https://www.extremetech.com/computing/265695-cts-labs-responds-allegations-bad-faith-amd-security-disclosures-digs-deeper-hole Quote:By its own statements, CTS Labs tested and developed a proof of concept exploit for Asmedia controllers before it was aware these controllers were incorporated into Ryzen chipsets. Where, then, is the website AsmediaFlaws.com? Where’s the notification to tell Intel motherboard customers that the chips on their motherboards can be similarly backdoored and abused? This isn’t a theoretical; I’m writing this article from an Ivy Bridge-E system powered by an Asus X79-Deluxe motherboard with an Asmedia 1042 controller. In its white paper, CTS Labs describes the offending Asmedia controllers as follows: RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-16-2018 CTS Labs does a Q&A: https://www.techpowerup.com/242386/cts-labs-responds-to-a-techpowerup-technical-questionnaire RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-17-2018 Tom's analysis raises further questions: http://www.tomshardware.com/news/cts-labs-responds-amd-vulnerability-disclosure,36680.html RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-20-2018 First proof-of-concept video released: https://www.techpowerup.com/242521/cts-labs-releases-masterkey-exploit-proof-of-concept-video RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 03-21-2018 http://www.tomshardware.com/news/amd-response-cts-labs-ryzenfall-masterkey-chimera-fallout,36707.html Quote:AMD has finally issued a full response to CTS Labs’ report that Ryzen and EPYC processors contain a total of 13 security flaws. Here’s the short version of the chipmakers’ response: RE: Zen CPUs Might Be Hit By 4 New Flaws UPDATED - SteelCrysis - 05-03-2018 AMD confirms that it has sent out patches: https://www.tomshardware.com/news/amd-vulnerability-patches-ecosystem-partners,36993.html |