Another Word For It Patrick Durusau on Topic Maps and Semantic Diversity

May 16, 2019

RIDL and Fallout: MDS attacks (Intel Chips)

Filed under: Cybersecurity,Hacking — Patrick Durusau @ 2:50 pm

RIDL and Fallout: MDS attacks

From the webpage:

The RIDL and Fallout speculative execution attacks allow attackers to leak private data across arbitrary security boundaries on a victim system, for instance compromising data held in the cloud or leaking your data to malicious websites. Our attacks leak data by exploiting the 4 newly disclosed Microarchitectural Data Sampling (or MDS) side-channel vulnerabilities in Intel CPUs. Unlike existing attacks, our attacks can leak arbitrary in-flight data from CPU-internal buffers (Line Fill Buffers, Load Ports, Store Buffers), including data never stored in CPU caches. We show that existing defenses against speculative execution attacks are inadequate, and in some cases actually make things worse. Attackers can use our attacks to leak sensitive data despite mitigations, due to vulnerabilities deep inside Intel CPUs.

In addition to being a great post, there is an interactive image of the Intel chip with known vulnerabilities in color.

The uncolored areas may have unknown vulnerabilties.

Good hunting!

No Comments

No comments yet.

RSS feed for comments on this post.

Sorry, the comment form is closed at this time.

Powered by WordPress