Security News

A decade's worth of AMD chips offer data takeaway via a side channel but AMD yawns and says 'meh, not an issue'
2020-03-09 21:10

AMD processors sold between 2011 and 2019 are vulnerable to two side-channel attacks that can extract kernel data and secrets, according to a new research paper. In a paper [PDF] titled, "Take A Way: Exploring the Security Implications of AMD's Cache Way Predictors," six boffins - Moritz Lipp, Vedad Hadžić, Michael Schwarz, and Daniel Gruss, Clémentine Maurice, and Arthur Perais - explain how they reverse-engineered AMD's L1D cache way predictor to expose sensitive data in memory.

9 Years of AMD Processors Vulnerable to 2 New Side-Channel Attacks
2020-03-09 07:20

AMD processors from as early as 2011 to 2019 carry previously undisclosed vulnerabilities that open them to two new different side-channel attacks, according to a freshly published research. Known as "Take A Way," the new potential attack vectors leverage the L1 data cache way predictor in AMD's Bulldozer microarchitecture to leak sensitive data from the processors and compromise the security by recovering the secret key used during encryption.

9 Years of AMD Processors Vulnerable to 2 New Side-Channel Attacks
2020-03-09 07:20

AMD processors from as early as 2011 to 2019 carry previously undisclosed vulnerabilities that open them to two new different side-channel attacks, according to a freshly published research. Known as "Take A Way," the new potential attack vectors leverage the L1 data cache way predictor in AMD's Bulldozer microarchitecture to leak sensitive data from the processors and compromise the security by recovering the secret key used during encryption.

Mixed-signal circuits can stop side-channel attacks against IoT devices
2020-02-26 05:00

Purdue University innovators have unveiled technology that is 100 times more resilient to electromagnetic and power attacks, to stop side-channel attacks against IoT devices. Recent attacks have shown that such side-channel attacks can happen in just a few minutes from a short distance away.

Microsoft movie tried to Azure Ignite attendees about CPU side-channel flaws, but biz wouldn't be drawn on details
2019-12-12 10:00

'Sir, they're about to disclose the vulns!' 'Damn it. Accelerate the rollout!' How does Microsoft mitigate the risk of speculative-execution bugs on its Azure platform? The US goliath is unwilling...

Linux maintainer: Patching side-channel flaws is killing performance
2019-10-31 13:15

Mirror, mirror on the wall, which is the worst side-channel vulnerability of them all?

Another Side Channel in Intel Chips
2019-09-16 11:39

Not that serious, but interesting: In late 2011, Intel introduced a performance enhancement to its line of server processors that allowed network cards and other peripherals to connect directly to...

Side-Channel Attack against Electronic Locks
2019-08-14 17:36

Several high-security electronic locks are vulnerable to side-channel attacks involving power monitoring....

New SWAPGS Side-Channel Attack Bypasses Spectre and Meltdown Defenses
2019-08-07 13:55

Researchers demonstrate a new side-channel attack that bypass mitigations against Spectre and Meltdown.

Protection Against Side-Channel Attacks Added to OpenSSH
2019-06-24 14:45

Protection against Spectre, Meltdown, Rowhammer, read more