Followers | 679 |
Posts | 140823 |
Boards Moderated | 36 |
Alias Born | 03/10/2004 |
Sunday, March 08, 2020 10:26:35 AM
By: Engadget | March 8, 2020
• AMD reportedly heard about the Take A Way flaws several months ago.
It's not just Intel chips that are vulnerable to hard-to-fix security flaws. Researchers at the Graz University of Technology have detailed a pair of side channel attacks under the "Take A Way" name that can leak data from AMD processors dating back to 2011, whether it's an old Athlon 64 X2, a Ryzen 7 or a Threadripper. Both exploit the "way predictor" for the Level 1 cache (meant to boost the efficiency of cache access) to leak memory content. The Collide+Probe attack lets an intruder monitor memory access without having to know physical addresses or shared memory, while Load+Reload is a more secretive method that uses shared memory without invalidating the cache line.
Unlike some side channel attacks, it hasn't taken long to show how these exploits would work in the real world. The team took advantage of the flaws using JavaScript in common browsers like Chrome and Firefox, not to mention virtual machines in the cloud. While Take A Way only dribbles out a small amount of information compared to Meltdown or Spectre, that was enough for the investigators to access AES encryption keys.
It's possible to address the flaw through a mix of hardware and software, the researchers said, although it's not certain how much this would affect performance. Software and firmware fixes for Meltdown and Spectre have typically involved speed penalties, although the exact hit depends on the task.
We've asked AMD for comment. However, the authors suggest that AMD has been slow to respond. They said they submitted the flaws to AMD in late August 2019, but haven't heard back despite keeping quiet about the flaw for the past several months.
The findings haven't been without controversy, although it doesn't appear to be as questionable as some thought at first. While Hardware Unboxed found disclosures that Intel funded the research, raising concerns about the objectivity of the study, the authors have also received backing from Intel (and other sources) for finding flaws in the company's own chips as well as other products. It appears to just be a general effort to spur security research, then. As it stands, the funding source doesn't change the practical reality -- AMD may have to tweak its CPU designs to safeguard against Take A Way attacks going forward.
Read Full Story »»»
DiscoverGold
Information posted to this board is not meant to suggest any specific action, but to point out the technical signs that can help our readers make their own specific decisions. Caveat emptor!
• DiscoverGold
Recent AMD News
- United Shares Surge 5.3% in Q1 2024 Earnings Beat; Take-Two Cuts 5% of Workforce, and More News • IH Market News • 04/17/2024 10:57:39 AM
- AMD to Report Fiscal First Quarter 2024 Financial Results • GlobeNewswire Inc. • 04/16/2024 08:15:00 PM
- AMD launches AI chips for business laptops and desktops • IH Market News • 04/16/2024 02:43:08 PM
- AMD Expands Commercial AI PC Portfolio to Deliver Leadership Performance Across Professional Mobile and Desktop Systems • GlobeNewswire Inc. • 04/16/2024 01:00:00 PM
- Paramount Global Board Shrinks, Morgan Stanley Faces Regulatory Probe, and More News • IH Market News • 04/12/2024 11:05:29 AM
- Delta Generates US$37 Million Profit in Q1, Google and Intel Unveil Cutting-Edge AI Chips, and More News • IH Market News • 04/10/2024 11:13:48 AM
- AMD Extends Leadership Adaptive SoC Portfolio with New Versal Series Gen 2 Devices Delivering End-to-End Acceleration for AI-Driven Embedded Systems • GlobeNewswire Inc. • 04/09/2024 08:15:00 AM
- AMD Recommends Rejection of “Mini-Tender” Offer from Tutanota LLC • GlobeNewswire Inc. • 04/01/2024 08:15:00 PM
- U.S. Stocks May Move Back To The Upside In Early Trading • IH Market News • 03/26/2024 01:09:44 PM
- U.S. Index Futures on the Rise, Oil Prices Show Stability • IH Market News • 03/26/2024 11:21:42 AM
- U.S. Stocks Show Modest Move To The Downside • IH Market News • 03/25/2024 08:44:00 PM
- Tech Sector Weakness May Weigh On Wall Street • IH Market News • 03/25/2024 01:26:54 PM
- AMD Adaptive Computing Technology Powers Sony Semiconductor Solutions LiDAR Automotive Reference Design • GlobeNewswire Inc. • 03/19/2024 01:00:00 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 03/11/2024 08:22:08 PM
- Form 144 - Report of proposed sale of securities • Edgar (US Regulatory) • 03/08/2024 10:23:51 PM
- Form 144 - Report of proposed sale of securities • Edgar (US Regulatory) • 03/07/2024 10:59:11 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 03/07/2024 09:14:43 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 03/07/2024 09:09:41 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 03/06/2024 09:09:18 PM
- AMD Extends Market-Leading FPGA Portfolio with AMD Spartan UltraScale+ Family Built for Cost-Sensitive Edge Applications • GlobeNewswire Inc. • 03/05/2024 02:00:00 PM
- AMD Hits Regulatory Roadblock, GitLab’s Stock Tumbles on Disappointing Earnings, and Latest News • IH Market News • 03/05/2024 11:05:08 AM
- Form 144 - Report of proposed sale of securities • Edgar (US Regulatory) • 03/04/2024 11:25:41 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 03/04/2024 10:48:32 PM
- AMD Hires Thomas Zacharia to Expand Strategic AI Relationships • GlobeNewswire Inc. • 03/04/2024 10:00:00 PM
- AMD to Present at the Morgan Stanley Technology, Media and Telecom Conference • GlobeNewswire Inc. • 02/27/2024 09:15:00 PM
Axis Technologies Group and Carbonis Forge Ahead with New Digital Carbon Credit Technology • AXTG • Apr 24, 2024 3:00 AM
North Bay Resources Announces Successful Equipment Test at Bishop Gold Mill, Inyo County, California • NBRI • Apr 23, 2024 9:41 AM
Epazz, Inc.: CryObo, Inc. solar Bitcoin operations will issue tokens • EPAZ • Apr 23, 2024 9:20 AM
Avant Technologies Launches Advanced AI Supercomputing Network and Expansive Data Solutions • AVAI • Apr 23, 2024 8:00 AM
BestGrowthStocks.com Issues Comprehensive Analysis of Triller Merger with AGBA Group Holding Limited • AGBA • Apr 22, 2024 1:00 PM
Cannabix Technologies to Present Marijuana Breathalyzer Technology at International Association for Chemical Testing (IACT) Conference in California • BLO • Apr 22, 2024 8:49 AM