Intel CPUs Impacted by New PortSmash Side-Channel Vulnerability (zdnet.com)
Intel processors are impacted by a new vulnerability that can allow attackers to leak encrypted data from the CPU's internal processes. From a report: The new vulnerability, which has received the codename of PortSmash, has been discovered by a team of five academics from the Tampere University of Technology in Finland and Technical University of Havana, Cuba. Researchers have classified PortSmash as a side-channel attack. In computer security terms, a side-channel attack describes a technique used for leaking encrypted data from a computer's memory or CPU, which works by recording and analyzing discrepancies in operation times, power consumption, electromagnetic leaks, or even sound to gain additional info that may help break encryption algorithms and recovering the CPU's processed data. Researchers say PortSmash impacts all CPUs that use a Simultaneous Multithreading (SMT) architecture, a technology that allows multiple computing threads to be executed simultaneously on a CPU core. [...] Researchers say they've already confirmed that PortSmash impacts Intel CPUs which support the company's Hyper-Threading (HT) technology, Intel's proprietary implementation of SMT.
Never liked Hyper-Threading. It always seemed like a fishy hack — and now my irrational fears have been "substantiated" by Finnish and Cuban academics...
In Soviet Washington the swamp drains you.
Spectre, Meltdown, a few others I forgot, and now this one. Okay security fearmongering douches, I just have one fucking question. If all this shit is so bad, where are the exploits for SSH? The phrases "tempest in a teapot" and "much ado about bullshit" come to mind. Why aren't there worms ravaging the internet and pwning every intel-based router and host machine on the net? Perhaps because all these TLB exploits and crypto hand wringing make for much better copy on some wired article than they make research material for real exploits. Send all the fucking links to "whitepapers' you want, but nobody has a fucking leg to stand on until there is some real fallout here, and it's just not materializing.
Do not buy the new 2018 top-of-the-line i7 Mac mini, the i3 and i5 options without hyper-threading are safer. Got it.
#DeleteFacebook
Is all it takes to be free! Free! FREE! Say NO! to the iNtel tyranny.
This is what happens when the CEO doesn't have the balls to say no to the NSA.
And, before some autistic manchild says I should have used "==" understand that I am assigning the value Trash to Intel, now fuck off.
If a hyperthread can spy on the other hyperthread that runs on the same core, it is possible to disable hyperthreading.
However, the next exploit will be that one core can spy on another core. This is possible because all cores use the memory subsystem including the L3 cache that is shared between all cores.
But HT does NOT execute simultaneously!?!?
wait for the 2020 mac pro with amd!
The aliens in Independence Day never stood a chance.
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
APK probably thinks that hosts can prevent this vulnerability, just like he thinks hosts protect from Spectre and Meltdown. I'm waiting for that retard to show up in this story.
They are the only company I know that evaluates change requests, both for possible legal liabilities and opportunities, as part of their agile process.
How does this exploit work in practice? Do you have one legitimate process doing encryption/decryption while another process tries to get itself hyperthreaded with the first in order to spy on it?
Why not have HT available only for threads of a single process? That would stop two unrelated programs from sharing the same core simultaneously.
From TFA: "Researchers suspect AMD processors are also impacted."
In lay terms, the attack works by running a malicious process next to legitimate ones using SMT's parallel thread running capabilities.
Once again, we are presented with an 'exploit' that requires one to have compromised the target already, rendering this as a "Why bother? You're already inside."
This feels more like bashing Intel than anything else at this point.
I want to buy a cheaper and relatively faster personal computer that has the following features.
1. Only 1 core.
2. No Hyper-Threading.
3. No GPU.
4. Largest L1, L2 and L3 caches.
5. Lowest TDP.
6. 10nm or 7nm process.
7. Accelerated fabrication due to small die.
8. Less than $100 the CPU.
9. For running this OS Linux or *BSD.
My ancient desktop has a Core2 Extreme with 4 cores and 4 thread - no HT - and a real BIOS. So it should be immune? Same for my 4-core, 4-thread Atom tablet, with 32-bit Windows and UEFI.
My laptop has an i5 with 2 cores and 4 threads - with HT. So I should disable HT in the BIOS (if it's possible - early UEFI running in legacy BIOS mode) and live with slower performance? Probably, if I'm paranoid. How likely is it that this will be widely distributed and able to operate remotely?
They will game it.
Every time I hear about a new vulnerability I laugh.
We are at the cusp of finding out how insecure all of our electronics really are.
People are just beginning to scratch the attack vector surface.
As more and more non CS people are brought into the world of computing we will see an every increasing number of new methods to "break the system".
As soon as you lose physical control of a reactionary device all security goes out the window.
What I am saying is that it is impossible to stop it, impossible to predict it and impossible to know when it will happen. The only truth is that it will happen. It's the it we just wont know until it happens.
I don't say hosts cure Spectre/Meltdown (or PortSmash): You do IMPERSONATING me https://idle.slashdot.org/comm... & you also LIE that I have a MacOS X version of my hosts program - I don't (yet).
* Give up already loser!
APK
P.S.=> FACT - you're already losing for a LONG TIME resorting to lying & IMPERSONATING me... apk
I hate semantic arguments too, but bootloader is a generic term that should cover EFI, UEFI, and BIOS
See subject + quote: "You basically have to already be able to run your own evil code on a machine in order to PortSmash it." from https://www.theregister.co.uk/...
* So when hosts blocks REMOTE SOURCES of such malware? Yes, hosts CAN stop "portsmash" attacks!
APK
P.S.=> For once? The IMPERSONATORS of me MAY be right... apk
P.S.=> FACT - you're already losing for a LONG TIME resorting to lying & IMPERSONATING me... apk
Dude, make a fucking account.
See subject: You "F'd up" BAD saying what you did vs. this that BLEW YOU AWAY you dumb bastard https://it.slashdot.org/commen... & now you "eat your words" for it, hahahaha!
* Eating your words != GOOD nutrition - you'll STARVE & die of malnutrition STUPID!
(Tell us, won't you, how EATING YOUR WORDS tasted? A bit like your FOOT IN YOUR MOUTH ramming them down your CHICKEN NECK unidentifiable anonymous "WEEZIL" throat?? Washed down w/ the BITTER taste of SELF-defeat - hohohoho!)
APK
P.S.=> I blew your DUMB ass away, again, like always you STUPID fuck... apk