Intel and AMD chips have another serious security flaw to worry about

Intel Core HX
(Image credit: Intel)

Chips from Intel and AMD, as well as processors from other manufacturers, may be susceptible to a new type of attack which could allow threat actors to steal cryptographic keys and other data directly from the endpoint's hardware.

A team of security researchers, including Riccardo Paccagnella of the University of Illinois Urbana-Champaign, set out to investigate the idea of extracting cryptographic data from a chip by measuring the power consumed during data processing. It’s a relatively old theory that’s been proven inviable in practice, due to the inability to measure power consumption remotely. 

But the researchers managed to give the idea a new twist, by turning the attack into a different type of side-channel exploit, and this one is a lot more viable. 

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Intel plays down the flaw

As it turns out, through dynamic voltage and frequency scaling (DVFS), attackers can track the time the server takes to respond to specific queries, effectively allowing them to spot changes in power consumption. It’s a relatively simple thing, researchers said. They’ve dubbed the vulnerability Hertzbleed, and it’s since being tracked as CVE-2022-24436 for Intel devices, and CVE-2022-23823 for AMD. 

While they managed to successfully reproduce the attack on Intel chips from 8th to 11th generation, they’re also saying it works on Xeon, as well as Ryzen chips.

But Intel is having none of it. Responding to the findings, the company’s Senior Director of Security Communications and Incident Response Jerry Bryant, wrote that the idea is not practical outside the lab.

"While this issue is interesting from a research perspective, we do not believe this attack to be practical outside of a lab environment. Also note that cryptographic implementations that are hardened against power side-channel attacks are not vulnerable to this issue.”

The chip manufacturers won’t be updating their chips, Ars Technica found, and will instead endorse changes Microsoft and Cloudflare made to their PQCrypto-SIDH and CIRCL cryptographic code libraries.

Via: Ars Technica

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
AMD logo
AMD patches high severity security flaw affecting Zen chips
Security
Intel slams Nvidia and AMD, claims chip giants have huge numbers of security flaws
AMD Ryzen 5 7600X processor
AMD confirms processor security flaws after Asus patch slips out early
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in Security
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Latest in News
an image of the Samsung Galaxy S24 Ultra
Finally! One UI 7 has a release date - here are the Samsung phones that’ll get it first
Google Cloud logo
Google to acquire cloud security platform Wiz in $32 billion deal
GIMP 3.0 interface from the website
Our favorite free photo editor finally got the update it deserves - and these are the top 5 features designers should know about
A still from a promo image for the second season of Severance showing the character Mark holding blue balloons in a hallway
Macrodata Refiners rejoice, Google has rewarded us with a virtual balloon party ahead of the Severance season 2 finale
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
FCC filing for the Nothing CMF Buds 2 Plus
Nothing’s next-gen CMF cheap earbuds slated to arrive within the month, but don’t expect hi-res audio support