Announcement

Collapse
No announcement yet.

AMD Secure Processor & Ryzen Chipsets Reportedly Vulnerable To Exploit

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #11
    Exploiting MASTERKEY requires an attacker to be able to re-flash the BIOS with a specially crafted BIOS update. This update would contain Secure Processor metadata that exploits one of the vulnerabilities, as well as malware code compiled for ARM Cortex A5 – the processor inside the AMD Secure Processor.

    Ryzenfall exploitation requires that an attacker be able to run a program with local-machine elevated administrator privileges. Accessing the Secure Processor is done through a vendor supplied driver that is digitally signed.

    FALLOUT exploitation requires that an attacker be able to run a program with local-machine elevated administrator privileges. Accessing the Secure Processor is done through a vendor supplied driver that is digitally signed.

    CHIMERA Prerequisites for Exploitation: A program running with local-machine elevated administrator privileges. Access to the device is provided by a driver that is digitally signed by the vendor.
    quote from a slashdot user

    Comment


    • #12
      Originally posted by shmerl View Post
      Is there a way to completely disable PSP with Ryzen?
      Sadly not that I have found. The closest thing to it was a motherboard option to "disable" it that was found in some mobos. However, everything I read about that mobo option suggested it was likely just disabling the features related to the PSP in the mobo and not disabling the PSP itself.

      In short, we are sh!t out of luck.

      What I'm expecting is that at some point there will be a huge mass malware, theft or extortion event where either the Intel or AMD onboard "security" processor is compromised by some bad people on millions of devices. When this occurs it will create a huge demand for chips without these horrible onboard-chips and Intel and AMD will start offering chips without them.

      Ideally the event I described above would not need to happen to create enough demand for these chips for Intel and AMD to start producing them now. It seems though that most people lack the knowledge or foresight to demand these chips. They need to burn their hand in the fire just once before they opt to avoid touching the hot flame again.

      In the mean time there are quite a few options for people who want a CPU without this problem. They are all imperfect in some way, but it's better than nothing. There are old slow CPUs which don't have this horrible ME/PSP tech (slow option). Their are modern Intel CPUs which can be fed cut-down firmware which hopefully disables the ME (fast, but potentially flawed). There are alternative instruction set CPUs like the POWER series which I think can be bought without any ME/PSP style tech inside them (expensive and less compatible).

      Comment


      • #13
        Originally posted by ConvexEd View Post
        The very name is shady as fuck.
        https://whois.domaintools.com/amdflaws.com
        Link is some kind of 4chan redirect. Please don't - I sometimes browse Phoronix from work.

        Comment


        • #14
          Here's a quote from Viceroy Research:

          Viceroy analyze CTS Labs’ report exposing fatal security vulnerabilities across AMD products

          ...

          We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries.
          What a load of bollocks.

          Comment


          • #15
            Already changed it, my apologies for the redirect.

            Comment


            • #16
              Intel paid fake news, they are indeed desperate it seems.

              Comment


              • #17
                Whether they're real or not, I heard from another site that they can only be exploited via root/admin access. So basically it's a non-issue (where if someone/something has access to root, you have greater problems to worry about than these exploits).

                Comment


                • #18
                  Might be Intel pulling the strings. It might just as well just be an attempt to mess with the stock price. Discredit them, stock falls, buy lots, wait for everyone to realize this was FUD, stock recovers, sell stock..

                  Comment


                  • #19
                    I don't think it's Intel. It could be anyone who wants cheap stocks.

                    Comment


                    • #20
                      I'm wondering if this isn't someone trying to see if they can't manipulate automated trading bots with negative headlines.

                      Comment

                      Working...
                      X