Author Topic: Another Intel Flaw!  (Read 211 times)

0 Members and 1 Guest are viewing this topic.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 19557
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Another Intel Flaw!
« on: May 14, 2019, 09:47:42 PM »
From New RIDL and Fallout Attacks Impact All Modern Intel CPUs:

Quote
Multiple security researchers have released details about a new class of speculative execution attacks against most modern Intel processors. Called data-sampling attacks, they are different from and more dangerous than Meltdown, Spectre and their variations because they can leak data from CPU buffers, which is not necessarily present in caches.

Speculative execution is a method for optimizing the performance of a CPU by running tasks in advance, without knowing whether they will be needed or not.

As indicated in the Wired article at Intel Flaw Lets Hackers Siphon Secrets from Millions of PCs | WIRED, it is four distinct attacks using a similar technique, and all capable of siphoning a stream of potentially sensitive data from a computer's CPU to an attacker.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline satrow

  • LzD Friends
  • Full Member
  • *****
  • Posts: 212
    • View Profile
Re: Another Intel Flaw!
« Reply #1 on: May 16, 2019, 12:54:37 PM »
Moonchild has a down to earth summary of Zombieload attacks and mitigations.

Quote
TL;DR: If you switch off HT for this on your desktop, you're being dumb.

===
Honestly, it's something you cannot really exploit in the wild for anything useful.

Please read the entirety of the article which highlights some important points.

...