3 ms·
"After carefully reviewing the CPU voltage setting modification, Intel is mitigating the issue in two parts, a BIOS patch to disable the overclocking mailbox in
by strstr 7y ago
"After carefully reviewing the CPU voltage setting modification, Intel is mitigating the issue in two parts, a BIOS patch to disable the overclocking mailbox interface configuration. Secondly, a microcode update will be released that reflects the mailbox enablement status as part of SGX TCB [Trusted Computing Base] attestation. The Intel Attestation Service (IAS) and the Platform Certificate Retrieval Service will be updated with new keys in due course. The IAS users will receive a ‘CONFIGURATION NEEDED’ message from platforms that do not disable the overclocking mailbox interface.”
Seems like you should be able to just avoid applying the bios patch. That said, you won't be able to keep your BIOS up to date.
- chithanh 7y agoBut then again, the researchers state: "In the paper, we show that Plundervolt may affect SGX's attestation functionality" so they are apparently able to fake at least part of the attestation. Also it will be interesting to see whether directly talking to the voltage regulation controller on the mobo will circumvent the microcode protection.
- wahern 7y agoAFAICT, they were able to randomly flip bits in the enclave. Which isn't great, but doesn't yet break remote attestation as commonly used for DRM schemes, which involves online communication with both Intel and the enclave software provider. They can simply reject attestations if they detect too many authentication attempts from the same CPU, long before you manage to flip the correct bit. IIRC, reading memory out of the enclave has already been accomplished with other side-channel attacks, so that aspect has been broken. What would be novel is if you could read the per-CPU secret key[1], but that doesn't appear to be what they've done. [1] Which only Intel knows, which is why remote attestation requires a service contract with Intel for online verification of attestation responses.
- segfaultbuserr 7y ago> whether directly talking to the voltage regulation controller on the mobo Is it even possible to do that without physical access? Can you confirm that? Do modern motherboards expose an interface that allows directly control over the voltage regulation in software without physical access?! If so, it's terrifying...
- chithanh 7y agoI am talking working around attestation for someone who operates the computer and wants to subvert SGX enclaves. Whether you need physical access or not is thus inconsequential.
- big_chungus 7y agoWait, I won't be able to undervolt my CPU? What abput on linux? Intel decided that disabling functionality is a solution? Time for another PS3-type lawsuit.